An object identifier naming a certificate policy. Certificate-based authentication can match on it with rules that beat issuer rules, for example to count a certificate as multifactor or to insist on high-affinity binding.
Also called object identifier.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains OID in context, with comparison tables and the common traps.
Terms in this definition
- Certificate
Key Vault object holding an X.509 certificate, whose associated key and secret are managed alongside it.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- Certificate-based authentication
Lets people authenticate to Microsoft Entra by presenting an X.509 certificate from your organisation's PKI. Scoped to a group, it becomes an extra option, can count as passwordless MFA and doesn't stop anyone using other methods.
- MATCH
Used in WHERE when querying SQL Graph, it describes how to walk from node to node through edge tables, with patterns written like p1-(f1)->p2.
- Issuer
A field on a point-to-site gateway using Entra ID, set to the Secure Token Service URL https://sts.windows.net/{TenantID}/ including the final slash. It is neither the Graph nor the login URL.
- COUNT
A DAX function returning how many non-blank numbers, dates or text values a column contains. Boolean columns need COUNTA instead, and for counting the rows of a table COUNTROWS is the better choice.
- Binding
A declarative way to bring data into a function as an input or to write results out as an output. None are required: the code is always free to talk to the target service by using an SDK client from Azure.
Related terms
- Authentication binding policy
Rules in this certificate-based authentication setting, matched on certificate issuer or policy OID, can lift a certificate from the tenant default (single-factor, low affinity) to multifactor or to high affinity binding.
- Pointer file
A tiny text file, made up of version, oid and size lines, that Git LFS commits instead of the real binary. Anyone cloning without the LFS client receives these placeholders rather than the actual files.