Skip to main content
Identity verification

Issuance campaigns

How to send a client's users their credential instructions, announcements, reminders and expiry warnings, and issue their credentials in bulk, for clients that use Microsoft Entra Verified ID.

Written By Chris Scaminaci

Last updated About 1 hour ago

Microsoft Entra Verified ID works only for callers who already hold a credential, and enrolling them one at a time during calls does not scale. An issuance campaign is the bulk route: it e-mails the users you list instructions to add their credential to Microsoft Authenticator, can remind the ones who have not, can warn the ones whose credentials are about to expire, and can issue the credentials as it sends.

Campaigns apply to Verified ID only. Authenticator step-up needs nothing rolled out to users in advance, so a client that uses it needs no campaign.

Before you start: you need the Administrator or Identity Verification Admin role, Verified ID set up, and a client that is enabled and uses Verified ID. To use Include Credential Issuance, the credential contract must exist. To send by e-mail you also need an SMTP profile, on the Configuration tab or for this campaign.

Open the screen with Campaigns on the management screen, or go to /settings/identity-verification/campaigns.

Issuance Campaigns with the list of campaigns on the left and the campaign editor on the right
Issuance Campaigns with an empty campaign list and a new campaign open in the editor

Read the campaign list

The screen has the campaign list, Existing Campaigns, on the left and the editor on the right. The header has Help, Refresh and Back.

Each campaign is a card with its name, its status, its scheduled time or "Not scheduled", a count such as "12 / 40 sent", and a count of failures when there are any. The status is Draft, Scheduled, Running, Completed or Failed. The icons on a card edit, run and delete the campaign. Use Refresh to see the latest counts.

Campaign types

TypeWhat it is for
Issuance InstructionsHow to add the credential. The main enrolment message.
Pre-Rollout AnnouncementTells users it is coming, before anything changes for them.
Enrollment ReminderA reminder for users who have not added their credential yet. You choose who receives it.
Expiration WarningA warning for users whose credentials are about to lapse. You choose who receives it.
Bulk IssuanceTells users their credential has been created for them and is ready to add.

Placeholders

Placeholders in the subject and body are replaced for each recipient. The editor lists them under Available Placeholders, and clicking one copies it.

PlaceholderBecomes
{{FirstName}}, {{LastName}}The recipient's name from the client's directory, or empty when the address is not found there.
{{DisplayName}}The name shown for the recipient. For an address you pasted in the list, this is the address.
{{Email}}The recipient's address.
{{CompanyName}}The client's name.
{{IssueUrl}}The recipient's personal link to add their credential.
{{QrCode}}A QR code image of that link.

{{IssueUrl}} and {{QrCode}} are filled only when Include Credential Issuance is on. Otherwise the placeholder text itself is sent, so remove both from a message that does not issue a credential. The default Issuance Instructions, Enrollment Reminder, Expiration Warning and Bulk Issuance templates contain them.

Create a campaign

  1. Choose the Client and enter a Campaign Name. Both are required. The client decides whose users the campaign is for and which sender name recipients see.
  2. Choose the Campaign Type.
  3. Choose the Delivery Method. SMTP Email sends from your mail server and is the method to use for a list of addresses. Halo Email Action and Halo Ticket Note deliver through an existing HaloPSA ticket, so each recipient has to be attached to a ticket. A plain list of addresses has no ticket, so those messages are not delivered.
  4. Check the sender line. Once you pick a client, the editor shows "Recipients see this campaign as coming from" followed by a name. When no white-label brand applies to the client, the name is the neutral "IT Support", and the screen notes that this is the intended result, not a fault. For a client that belongs to a white-label partner, the name is the partner's display name from their Identity Verification policy profile.
  5. Write the message in Email Subject and Email Body, which accepts HTML, and add placeholders where you want each person's details. Choose Load Default Template for a ready-made subject and body for the type you chose. The button appears when a type is selected and the subject is empty, and choosing a type while the subject and body are empty fills them in for you.
  6. Enter the Recipients: e-mail addresses separated by commas, semicolons or new lines. Duplicates are removed, and entries without an @ are ignored.
  7. Set the options.
    • Include Credential Issuance creates a credential issuance request for each recipient as the message is sent, which is what fills {{IssueUrl}} and {{QrCode}}. When the client's directory has a photo for the user, the credential includes it, so that Face Check can match. A recipient whose issuance fails is not sent the message, and counts as failed.
    • Test Mode sends everything to the Test Recipient Email you enter instead of the real recipients. Use it first on any campaign whose text you have edited, and to confirm that your mail profile delivers. It still creates an issuance request for the test address when Include Credential Issuance is on.
  8. Optionally set Scheduled Date/Time in your local time. A campaign with a time is saved as Scheduled and starts by itself. QuantumOps checks for due campaigns about every five minutes, so it can start a few minutes after the time. A campaign without a time is saved as Draft, and you start it with Run.
  9. Choose the mail profile under SMTP Settings. Leave Use Global SMTP Settings ticked, as it is by default, to send through the profile on the Configuration tab (see Set the mail profile for campaigns), or untick it and enter a profile for this campaign: SMTP Host, Port, Use SSL/TLS, Username, Password, From Address and From Display Name. The profile on the Configuration tab is sent without a password, so a mail server that needs a username and password must be entered for each campaign. If you leave the From name empty, the sender name from step 4 is used.
  10. Choose Save Campaign. Clear empties the editor.

Saving a campaign in Test Mode keeps only the test address as its recipient list. To send to the real recipients, untick Test Mode and enter the recipients again before you save.

Run, edit and delete a campaign

  • Run starts a draft, scheduled or failed campaign now. It is disabled while the campaign is Running. When it finishes, the campaign is Completed if at least one message was sent, and Failed if none was. Run does nothing to a Completed campaign. Editing one and choosing Save Campaign returns it to Draft (or Scheduled if it has a time) with its old counts, and Run then sends it to its recipients again, so create a new campaign to write to more people.
  • The edit icon loads a campaign into the editor under Edit Campaign. Change it and choose Save Campaign.
  • The bin icon deletes a campaign straight away, without asking you to confirm.

What your clients' users receive

Each recipient gets the message you wrote, from the sender name shown in the editor. With Include Credential Issuance on, it carries their own link and QR code. The default templates tell them to open Microsoft Authenticator on their phone, open the link or scan the QR code, and follow the prompts to add the credential. Once it is added, they can use it to verify themselves when they contact your helpdesk.

A sensible order

  1. Confirm the client is enabled and uses Verified ID (Clients and per-client policy).
  2. Send a Pre-Rollout Announcement, so the enrolment message is not the first they hear of it.
  3. Send Issuance Instructions with Include Credential Issuance on, in Test Mode first, then to the real list.
  4. Send an Enrollment Reminder to the users who still have no credential; the Credentials tab shows who has one (Credentials and the verification log).
  5. Send an Expiration Warning before credentials lapse. Credentials are marked Expired automatically once their expiry date passes.