Microsoft Graph Certificate Based Authorization Configuration
Microsoft Graph’s certificate-based authentication configuration is a tenant-level setting in Microsoft Entra ID that you manage via the Graph API to enable and govern sign-in using X.509 client certificates. It lets administrators specify which certificate authorities are trusted, how certificate chains and revocation are validated, and how fields in a presented certificate (such as Subject or Subject Alternative Name/UPN) are mapped to a specific user account.