A field on a point-to-site gateway using Entra ID, set to the Secure Token Service URL https://sts.windows.net/{TenantID}/ including the final slash. It is neither the Graph nor the login URL.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Issuer in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- HTTP / HTTPS
The protocols of the web, with HTTPS being HTTP secured by TLS.
- Token
The unit of text an LLM works with, which may be a word, part of a word or punctuation. Billing, limits and context windows are all counted in these units.
- URL
The web address of a resource, on which URL-based routing relies.
- HTTPS
Secure HTTP, wrapped in TLS. VCF products serve their web UIs and REST APIs this way on 443.
- Login
A server-wide security principal used for connecting to SQL Server or an Azure SQL logical server; users inside each database are linked to it. EXECUTE AS LOGIN can't be used in Azure SQL Database.
Related terms
- API Management validate-jwt policy
API Management inbound policy validating a JWT's issuer, audience, signature and required claims, for instance using the Microsoft Entra OpenID configuration. By default it answers 401 when a token is absent or invalid.
- Authentication binding policy
Rules in this certificate-based authentication setting, matched on certificate issuer or policy OID, can lift a certificate from the tenant default (single-factor, low affinity) to multifactor or to high affinity binding.
- Domainless federation
Normally a SAML/WS-Fed identity provider set up for B2B is matched on the guest's email domain. With this option that check is skipped and guests are sent to the provider by its issuer URI instead, which helps when a partner's users have email addresses on domains other than the provider's.
- Issuer (workload identity federation)
The field in a federated credential that contains the URL of the external identity provider and has to match the iss claim in the token. When you need to create the federated credential manually, Azure Pipelines displays the Issuer and Subject identifier for you.
- Logic Apps authorization policy
Setting on a logic app that checks Microsoft Entra OAuth tokens sent to request-based triggers against an issuer and claims. SAS still works alongside it unless you also turn on Disable SAS authentication, which only Consumption offers.
- Microsoft Entra issuer
By default, newly created workload identity federation connections in Azure DevOps take tokens from https://login.microsoftonline.com/{tenant-id}. The previous issuer, https://vstoken.dev.azure.com, retires on 1 July 2027 for managed identities and single-tenant apps.
- OID
An object identifier naming a certificate policy. Certificate-based authentication can match on it with rules that beat issuer rules, for example to count a certificate as multifactor or to insist on high-affinity binding.
- PKI-based trust store
The recommended trust store for certificate-based authentication, holding each PKI's CAs in its own container (a maximum of 250 CAs at 8 KB apiece) and supporting issuer hints. Privileged Authentication Administrators manage it, and uploading a PKI in bulk needs P1 or P2.