Interviews
Ankur Patel: Microsoft’s Decentralized Identity Product—Entra Verified ID

Zack Jones
·
·
3 min read

Today’s guest is Ankur Patel, Head of Product at Entra Verified ID which is Microsoft’s decentralized identity product. We begin the conversation by reviewing Microsoft’s storied history of identity initiatives, and why one of the world’s most valuable companies made decentralized identity one of their major focus areas.
We dive into the recent announcement about verifiable credentials on LinkedIn, which allows companies to issue employment credentials, so LinkedIn members can truly prove they actually work at the organization listed on their LinkedIn profile.
Ankur is one of the pioneers in decentralized identity and his perspective on why enterprises are adopting decentralized identity is fascinating.
Reach out to Ankur on Twitter (@_AnkurPatel) or LinkedIn (https://www.linkedin.com/in/4ankurpatel/). To learn more about Microsoft Entra Verified ID visit the following two links:
Reach out to Riley (@rileyphughes) and Trinsic (@trinsic_id) on Twitter. We’d love to hear from you.
Full Transcript
Transcript lightly edited for clarity.
Riley Hughes: Welcome to the Future of Identity podcast, where we talk to the people building the ID tech products of tomorrow. I’m Riley Hughes, co-founder and CEO of Trinsic, and we build infrastructure for launching awesome identity products. Today’s guest is Ankur Patel, head of product at Entra Verified ID, which is Microsoft’s decentralized identity product. We begin the conversation by reviewing Microsoft’s storied history of identity initiatives and why one of the world’s most valuable companies made decentralized identity one of their major focus areas. We dive into the recent announcement about verifiable credentials on LinkedIn, which allows companies to issue employment credentials so that LinkedIn members can finally prove they actually work at the organization listed on their LinkedIn profile. Ankur is one of the pioneers in decentralized identity, and his perspective on why enterprises are adopting decentralized identity is fascinating. I think you’re going to love this episode. And now to my conversation with Ankur. Welcome.
Ankur Patel: Hey Riley, nice to see you. How are you?
Riley Hughes: I’m doing great. I’m really glad that you could come. I remember seeing an announcement from Microsoft that LinkedIn would be verifying users and would be enabling organizations to issue verifiable credentials to their employees to prove their employment status at those organizations. And I wanted to have a chat and see if we could explore that.
Ankur Patel: Great. Yeah, I’d love to talk about it.
Riley Hughes: I think it might be helpful to just kind of walk through the history of identity at Microsoft. What are some of the initiatives that have happened at Microsoft so far and Microsoft Entra?
Ankur Patel: Sure. Well, history of identity at Microsoft is a very long history, being Microsoft has a long history now. It’s hard to believe this company has been around for 50 years. And it started with machines and signing into Windows for having a session, and that was your local account. And then there were network PCs, and then you had accounts that roamed the network. That was for a household previously. That turned into, for enterprise, as Active Directory systems, which had been the dominant force for a long time until we arrived at the internet, and those account systems then moved to the cloud. At Microsoft, that cloud account became Microsoft account, and it was used for services like Live, once upon a time, for your online storage, or Xbox for gaming. So billions of users around the world use accounts from our team.
Ankur Patel: Now, in addition, that Active Directory system for the enterprise then graduated to going to the cloud as Azure Active Directory system, and that’s used for everything on Azure and Office and millions of third-party applications, whether it’s calling into Google or into Dropbox or other enterprise services like Workday and SuccessFactors or SAP and ServiceNow, all of these things with Workday run or powered by Azure Active Directory. Today, in fact, most businesses on the planet are powered by Azure Active Directory, in addition to governments around the world, including the United Nations. So that’s been the continuum of all the account systems. The latest thing that added, and it’s a good segue to verified ID work, was LinkedIn. So we acquired LinkedIn in 2016 or right around then, and that was professional accounts. So you have at-home accounts with Microsoft accounts, professional for your life, and then enterprise at work. But all three of them were islands of accounts, and we have no real way of connecting those things.
Ankur Patel: And since our mission statement is to empower and support every business and person, hard to do that if you don’t know who you are dealing with and you just have a bunch of accounts. So that’s why we started investing in verified ID, and we realized that it needs to be based on open standards. And verified ID is a managed implementation of said open standards. The idea being we empower the user or organization to have their own identity where you connect all these accounts, which is what becomes a proper digital identity rather than accounts. And that can roam with you across these islands. So now we know for sure that that same person who works at, I don’t know, Contoso is also this professional on LinkedIn who claims to work for Contoso. And you can share as much or as little of it as you like, including on things like your social network then, like an Xbox gaming service.
Riley Hughes: Awesome. That’s a great intro. Could you maybe explain what is Microsoft Entra?
Ankur Patel: Sure. As I just mentioned here, identity systems at Microsoft is a portfolio of different capabilities, ranging from consumer services and accounts to enterprise-grade. And in between, there is things like cross-cloud identity management. You can imagine some of these enterprises run on Azure, but also Google Cloud, AWS, and on-premises. And you’re not going to have four different orchestration services. We also provide things like permissions management across clouds. And then there is Azure Active Directory, and then there is Verified ID thing. So the overarching offer that we provide the marketplace is managing the entrance to your work or personal life or the internet, and hence the brand Entra. And inside of it is this offer which focuses specifically on verifiability, which is Verified ID, which is the managed implementation for verifiable credentials and decentralized identifiers.
Riley Hughes: That’s pretty amazing that within Microsoft, the verifiable credentials, decentralized identifier stuff appear almost under that umbrella to something as prevalent as Active Directory.
Ankur Patel: It took us some time to go think through what that would be and why that is the case. One of those key learnings we had along the way was A key problem that we have a lot of friction on is cross-domain verification. So all these companies, millions of businesses are on Azure Active Directory today, but there is still a lot of friction on establishing trust between two companies. We can establish security through traditional federation of two companies can exchange keys and all of that. However, how do you do it at scale, and how do you do it for granular attributes of arbitrary things? So, like, if you and I want to work on, I don’t know, a top secret project, how do we get to go set up for Microsoft with Trinsic and create a special claim that says it’s for this top secret project, and that’s what our two line-of-business apps want to accept? Very complicated and expensive to pull off, and it doesn’t scale. We think the standards-based approach is a better way to go do that.
Riley Hughes: I think my first contact with Microsoft as it relates to decentralized identity was early in my time at the Sovrin Foundation. So this has been in the works now for some time. What was it about decentralized identity or verifiable credentials that convinced Microsoft and the leadership at Microsoft and the product teams there that, you know, now is the time to invest in an offering like this?
Ankur Patel: It goes back to we have all these account systems that we’ve acquired. I had worked on the LinkedIn acquisition, and we realized that we have all these accounts, but we really don’t know who they belong to. And even setting up these federations across for companies we were doing mergers and acquisitions with was cumbersome and difficult to do. And so we started with a first principle approach, asking that question to ourselves, and it took us, call us slow, a couple of years to write two sentences. And this became our incubation hypothesis for this work, which was we believe each of us, and us at the time was meant to be not only a user, but an organization, an application, a device, needs a digital identity that we own and control. One which is securely and privately stores all of our data associated with it.
Ankur Patel: And, oh, by the way, make it such that it seamlessly integrates into our existing lives, not tell people to reach, start the internet, or redo everything that we’ve done with Azure Active Directory and Microsoft accounts, and yet give us complete control over our identity data and how it’s used. And we felt that if we could do that, this would be the next step in the zero trust quest that the enterprises were working on. So we were coming at this from a very different audience, if you will. It was less about the individual per se, but we realized that individuals live in an enterprise-first world. Like as much as we want choice, we have to do what the bank says, or what the car rental company says, or the airline or the hotel or the restaurant says to say, Here’s the proof I need you to provide in order for you to get service. And it turns out all of those enterprises I just described to you run on Azure Active Directory today. So we were like, Well, what is the missing piece? And the missing piece was this idea that the user who has agency over this credential could be trusted.
Ankur Patel: How do we do that with that same enterprise-grade security, traceability, verifiability, performance, scale, et cetera, in order for it to be a trusted operator? So that’s why we felt this was the time, because we were also having colleagues who were starting to work on things like artificial intelligence and things like quantum computing, and in all of those worlds, one of those things that our extended leadership would worry about is verifiability. Anything can generate anything. How do we know who did something? And we operated at massive scale. And it’s very difficult, therefore, to keep track of all of these signals that would come in to know that’s good and these are not good things. And therefore, we had to go think about, oh, this means it can’t be proprietary to Microsoft. It therefore must be based on open standards. It must be done in a way that the user is truly the controller of these choices.
Riley Hughes: I know that this is before my time, but I’ve heard stories about the Microsoft Passport or identity cards or things that had come previously. I wonder if there were lessons or takeaways that you brought from those past experiences and rolled them into a Verified ID product.
Ankur Patel: This is one of those benefits of working at a company with a long history of working on such problems. These problems are difficult. They are not one of those that you get to just prototype and ship it to the channel and then there’s adoption, because getting it right from a first principles is critical. We had the benefit of having someone like Kim Cameron that many of your listeners might know about as a leading thinker for identity and digital identity for the world to be at Microsoft. And he’s the person who led some of those initiatives that you were just referring to. And so he was helping us very much think through how do we think about this next iteration? And we very much think about this as just next iteration. We learned a set of things from the first one, the second attempt, and the third attempt for doing that work. And there were three key lessons that we learned from it. The first one is that open standards part. It needed to be based on open standards. Like InfoCards and such was open, but there was no standard to it that the world had agreed to.
Ankur Patel: And that was another thing that when we started doing this work, standards became a thing. Previous to then, I mean, let’s just take base protocol. W3C had ratified one base protocol, HTTP. That’s it. There has been none other. The next one is DID, decentralized identifiers. That’s why it’s a pretty big deal for the community in the world. That was one of those key lessons, like this must be based on open standards from day zero and not after the fact. The second one was mobile devices. Having a cryptographic device in your pocket, that didn’t exist before. As a result, in things like InfoCard, you had to trust a centralized service to do that part for you, which was back to centralized federations. This allowed true decentralization, if you will, because now I have a set of keys which are independently stored and managed from the issuing service and from the verifier. So that was new and different.
Ankur Patel: And the third was the world started to think about it and started to champion it, and businesses like Microsoft and others started to care about, no, no, this needs to get better because what’s to come. And therefore there were a bunch of hundreds of companies, it turns out, who joined Decentralized Identity Foundation, where such ideas were then nurtured and matured rather than a company like Microsoft going on its own. So this very much became a community-developed initiative, and I felt like these were the key lessons we learned.
Riley Hughes: Sounds like you worked on the LinkedIn acquisition, you know, a few years ago, and now you’re also the head of product at Verified ID. So I’m sure this has been, in your mind, something that you’ve wanted to tackle for years now, I’m guessing.
Ankur Patel: Yeah, it came to a simple problem. How do we know who is working for Microsoft on LinkedIn? Lots of people self-attest to it. In our case, one of the things we implemented at the time was an OAuth consent, so you can go connect your work identity to your LinkedIn identity and vice versa. And therefore work can know what skills you have on the internet, and the internet community can know that you actually work at this company. But that works one OAuth consent at a time. How many such federations can LinkedIn possibly go set up? And while you can go through Azure Active Directory to help, but it still doesn’t scale for everyone on the planet, right? LinkedIn, as a member community, professional member community, really wants it to be inclusive and work for everyone on the planet. So how do we do that? And hence use of open standards. And now using those open standards, I as a professional can say my workplace can attest whether they are an Azure Active Directory or not. That I work at this company, and the government or an identity verification entity can attest that N.
Ankur Patel: Riley is a real person in the world that we have also verified and not just somebody with a work account or email address, for that matter. And that all of these things put together give greater assurance to the community that Riley is a trusted professional on LinkedIn, for example. And so with LinkedIn, the relationship is very much like it’s an application on the internet who’s choosing to accept verifiable credentials as means to get these attestations, as opposed to there’s some business relationship that we have between the two. And that’s the meta lesson in all of this, that what makes this work and work at scale is not to have these business relationships where every attribute we are going to go exchange. That’s very difficult to do. But Microsoft is issuing a verified employee credentials to us, or other companies are, so they can use them on the internet, LinkedIn and otherwise.
Riley Hughes: Yeah, so if I read the announcement correctly, it sounds like there’s three components: the verified email, the verified ID in partnership with Clear, and the verifiable credential component. How does one accept the verifiable credential from their employer? How does an employer issue that credential? How does it all work?
Ankur Patel: LinkedIn has enabled three modalities to get yourself verified. The broadest one available to everyone is an email, but it’s also the lowest assurance one for people who are in the security world. But therefore, you can at least have something more than an automated bot came along and created an account on LinkedIn and filled out a bunch of stuff. The step up from that one is go get verified with Clear. Now that initial offer, as the blog post said, is available for North America. And therefore, CLEAR, as a brand that’s well known to people in this community, can go and get themselves verified if they choose to. It’s an opt-in. And then you can say, okay, now in addition to email verified, we know that Riley is real, at least as attested by CLEAR. And then beyond that, if you want to go and verify that you actually work at the company that you claim, because LinkedIn is a professional network, your company can issue you a verifiable credential. In our case, we have enabled it as default on service that enterprises can go configure to issue a verified employee credential.
Ankur Patel: LinkedIn has implemented the wallet library that we have open sourced into the LinkedIn app, so that they can request, using OpenID Connect, a verifiable credential. And so long as the schema is the same, they can come and say, Yeah, we can verify that you work at Contoso, or whatever that company might be. Currently, that workflow is by invitation only, because again, we are testing and trying all these things out and getting the user experience right. So one of the patterns you will see in our work, it’s taken us many years to get to this point even, is we’ve been super deliberate and methodical in going about it. On the flip side, we have not received any negative tweets or blog posts or other things about it, because we’ve been as transparent as we can be in trying to get it right from a member-first, from a company-first perspective, going back to that incubation hypothesis. And then it’s opt-in, and users get to choose to share and not share, and the company gets to choose to issue and not issue, and what attributes go in it, and so on and so forth.
Ankur Patel: Entra is just providing as one of those optional rails that companies and LinkedIn can choose to use if they want to, and they can use others that are spec compliant.
Riley Hughes: That’s really interesting. It seems like a really exciting way to kickstart an ecosystem. One of the things that we talk about a lot on this podcast, and something that I’m really interested in, is the adoption question. Because in many use cases, there’s a chicken and egg problem, as you know, where before the verifiers and relying parties will want to accept a credential, there needs to be an issuer and the people need to download a wallet. But it sounds like LinkedIn’s implemented a wallet library, and there are organizations that are willing to issue credentials into that. It sounds like a good way to kickstart an ecosystem.
Ankur Patel: Yeah, that was one of the key reasons why I stayed here at Microsoft building the Verified ID solution, because Microsoft has these services that people are willing to do work for, such as LinkedIn or GitHub or Xbox or any of these communities. And enterprises get value out of it on having such verified attestation show up on behalf of their company in those contexts, or game publishers in the case of Xbox or whoever. So each of those businesses will decide on their own time and schedule on when to activate their ecosystem, using Microsoft or otherwise. But in this current dawn of AI age, you can see everybody is in somewhat of an arms race to go figure out to bring greater verifiably and trust as humanly possible. So the timing is somewhat right for such ecosystems to now get activated, because previously we had all chosen the least common denominator of just saying, I enable sign-in with your social identity provider. And it really didn’t help anyone but the social networks get more audiences, and those applications then had zero switching cost.
Ankur Patel: Versus in this new world, we’re saying, no, no, you don’t have to outsource your users. You in fact get to build your own brand relationship with them, and that’s good for both of you.
Riley Hughes: A lot of our listeners are building products. Maybe they are interested in verifying people’s employment status for the purposes of a background check, or maybe they are interested in issuing credentials into the LinkedIn profile for purposes of attestation, things like that. What does the roadmap look like for broadening the ecosystem up? And I don’t know if you can speak to any of that.
Ankur Patel: I will do it for LinkedIn specifically. We should talk to LinkedIn in that case, right? This is why I’m being deliberate about they are making their own business choices. So they will publish their own Entra profile probably that says, here’s how you issue credentials to us, here’s how we accept credentials, and here’s how you can request from us. And they will have their own time and schedule and agenda for how they go about it. However, LinkedIn is just one app in the Entra ecosystem. As I said, there’s millions of apps and millions of enterprises who run on it. Our Entra profile is public at aka.ms/vcentra. Anybody can go implement that thing today. And there are almost eight companies who are doing it now, and some of the names will be familiar on that list. So there’s no reason to wait for it. LinkedIn is one use case. There are many use cases beyond LinkedIn.
Riley Hughes: Well, that’s a great segue into what I wanted to explore next, which is on your website, you have a lot of great customer stories with governments, universities, healthcare institutions, and more. When you think about use cases, after the several years of experience that you have deploying these solutions out to these customers, what are the use cases that get you most excited about adoption of verifiable credentials and user-controlled identity?
Ankur Patel: That’s a good question. One of the things that I’ve come to learn now is, of course, this utility value of having a portable identity that just works everywhere is super cool. And today we are all somewhat falling into the convenience factor of passkeys on a iOS or Android device, and then behind it are a whole bunch of usernames and passwords that it syncs to somehow and goes to different apps. But it still creates the same problem that I have all these balkanized datas living in those places. And any one of those loss of controls equals I have to deal with a privacy challenge, or somebody else did something in my name, even if it was buying a sandwich. The scenario that I get excited about is, rather than replacing, adding verifiable credentials as a step-up authentication scheme into those workflows, so that that primary key still belongs to me, and then you can have delegations into your existing apps. So this is how those existing apps don’t have to change. They can keep speaking usernames, passwords, or MFAs, or passkeys for doing it.
Ankur Patel: But that first step is with me, particularly for high assurance workflows. So, for example, if I want to look at my bank account, my bank account hopefully implements multi-factor auth or passkey-type things that make sure that somebody has the keys that are deemed secure to access this account. But if somebody’s going to move money from my account, I would like you to make sure that it is really me and perform a biometric verification in real time. And I don’t want that data bound to any centralized identity system. I want it bound to my personal identity, and therefore I should be asked to present a verifiable credential and perform a step-up verification. And so my mind is somewhat different than saying that verifiable credentials should be used everywhere. I think where they really shine is for those low-frequency, high-assurance workflows, and we should make sure those are the workplaces where they really shine and are conveniently available, and they’re reusable, and they’re under my control, and they don’t get tracked, and so on and so forth.
Riley Hughes: I’ve seen generally companies that are getting quite a bit of traction having two different approaches. One is to focus on credentials that are high-frequency, more relatively low-value credentials. Things that are used every day in people’s lives, or the things that are low frequency but really high-value interactions. Travel is an obvious one where generally most people are not flying every week, every month, but that’s a high assurance thing.
Ankur Patel: And that’s what I was thinking around this, that for our customers, we offer them external identity as a solution for those low assurance, high frequency use cases, which will cover email-based sign-up or sign-in, SMS, or multi-factor auth or passkeys, any of these. Depends on your level of assurance you want for your use case. So if you’re a sandwich shop, you’ll say, I want least friction on ordering that sandwich. Just make sure it’s the same person and Riley gets it. his sandwich. Or somebody who likes sandwich 57 gets the sandwich. You don’t even need to know it’s Riley. And then if you step up from it and you want to sell some alcohol that goes with it, then you can say, look, I want age proof and so on and so forth, right? So in business to consumer, B2C, where they call it progressive profiling, what we can add to it now is progressive verification. Instead of, you have to fill out all this stuff and give me your firstborn in order to just book a car. And it’s like, why? I’m not driving or whatever it might be.
Ankur Patel: So that when you’re doing the ticket change, for example, or booking the ticket, you can say, okay, I need to see the government-issued ID now, versus to see what the prices are available, you don’t need my government-issued ID to do that for an airline ticket, right? So that’s one of the things I love about having Verified ID be part of the Entra suite offer, because we can provide then that holistic solution that transcends that boundary, whether you’re on-premises or in cloud, mine or somebody else’s cloud, whether you’re doing that low-assurance workflows for high-frequency or low-frequency, high-assurance workflows, and having a predictable user experience rather than, oh, now you have to do this thing, and you have other time you have to do that other thing, and therefore users give up and just do the least common denominator thing. Therefore, most people still stick with sticky notes for that very reason.
Riley Hughes: Yeah. Well, I’m curious, after being on this journey for the last few years and having success with a number of customers as well as LinkedIn. I wonder if there’s anything that has really surprised you as you were going into this endeavor a few years ago, 2018 or whenever it was, that maybe has impacted how you think about verifiable credentials, decentralized identity, and how it will be adopted.
Ankur Patel: Three things come to mind. The first one was that we’re not alone, and there are lots of people around the world who care about it, from governments to large enterprises to small businesses to individuals who are willing to pour in a lot of sweat and energy and critical thinking, and really work together. We definitely have islands of philosophy on like, no, I shall not move, and it shall all be blockchain, or it needs to have zero-knowledge proof or whatever. But putting technology aside, people are very invested in making sure we make progress on bringing greater trust, verifiable, and privacy. And these are ends. Previously they have been ors, like I’ll take one of the three and that’s good enough. And now I’ve found that there is this movement towards, no, no, no, there shall be no compromise, and we shall hold each other accountable in making sure we’re going about doing this the right way. So that has been refreshing and good. And I think that’s generally how open standards movement is maturing. It’s no longer just a handful of people; it’s a large community effort.
Ankur Patel: So that’s been super cool. Two has been how relevant this is to the enterprises. Like going back to your sovereign days, it was very much consumer movement and empowered the user. And it turns out enterprises very much care about it too, and they generally want to get it right too. They don’t want to hold personally identifiable information. They don’t want to track people all over the internet. They want to just give you a great experience. And the identity thing is like, if you ask end users or enterprises, they’ll say it needs to be transparent, needs to be magical, rather than magic, which people don’t understand today, right? So that’s been a good surprise. The final one is timing. My gosh, this is one of those things where one of our executives pointed out that for once we are going to be where the puck is headed. And we already have some tools for it. Versus a lot of times you come up to some venture like this, like AI happens or metaverse happens or Web3 or crypto or any of these things you talk of, they all have this identity problem to be solved first.
Ankur Patel: And it turns out we as a community have a bunch of things which are deeply thought about, and we have a perspective and we have some working code and it’s being used in some production context. It’s a solve world hunger. But we’re farther along than a lot of times when we have ended up in these kinds of challenges previously. So those have been some good surprises in my mind.
Riley Hughes: Yep, I agree. I always like to ask people at the end of our time together, this has been a wonderful conversation. I’m glad that you’re so generous to spend the time. Tell me what the future of identity looks like to you, and why does that matter for the world or for Microsoft’s mission?
Ankur Patel: Microsoft’s mission statement is to empower every person and business to achieve more. Increasingly, that achieve more happens in a digital space. And how might you be feeling empowered if you don’t own and control your own digital identity? And so I feel like the future is bright if we continue on this current trajectory. Each of us, me, my family, my community, my professional friends, businesses will own their own digital identity to be trustworthy, and we can partner with each other and truly know that this news article is genuine, and the person who commented actually has some qualification that their opinion is grounded in some experience and not halfway across the world just somebody saying something. So these are all very timely challenges, and I’m hoping that these incremental gains that we’re making are going to help us tackle this very important challenge for the true digital world and global community to work with each other, trust each other, respect each other’s privacy and obligations.
Ankur Patel: So I think it’s going to be super cool, and to be part of it, come on, it’s going to be amazing.
Riley Hughes: That’s right. That’s an amazing vision. Thanks a lot. Well, is there anything that you have to plug, or if people want to get in touch with you or your team, if they’re interested in exploring Microsoft Entra Verified ID or in issuing credentials to their employees on LinkedIn, what would you direct them to do?
Ankur Patel: A common place to start is aka.ms/verifyonce. That’s our landing page, and that’s the tagline, right? Verify once, use everywhere. For developers, go to aka.ms/didfordevs. And again, those links are available for any of these pages. You can navigate back and forth. And of course, you can reach me on LinkedIn, Twitter, or any other channel. We are a small community.
Riley Hughes: Great. Well, thanks again for coming, and I appreciate you spending the time with me.
Ankur Patel: Happy to. Thank you for this opportunity. It was a great chat. It made me think about a few things. You usually don’t get to sit back and just think about some of these things, so thank you for this chat.
Riley Hughes: Thanks a lot. Thanks for listening. You can find us on YouTube, Apple, Spotify, and wherever else you listen to podcasts. Feel free to reach out on Twitter at Trinsic underscore ID or to me at Riley P. Hughes, and visit Trinsic if you’re interested in building the ID tech products of the future. Subscribe to get new episodes as they drop.

Zack Jones
Director of Product Partnerships @ Trinsic
Zack Jones leads the product partnerships at Trinsic that together form the connections that make up the world’s largest identity acceptance network. Zack is a published author, expert on digital IDs, and passionate about entrepreneurship.
Newsletter
Subscribe to weekly insights and updates in the digital ID ecosystem.
