Digital identity is moving to the centre of how Western Australian government agencies design citizen services and manage workforce access. As service delivery becomes increasingly online, the ability to verify who a person is, and what qualifications or entitlements they hold, without repeatedly collecting and storing sensitive documents is becoming a core design requirement. Verifiable credentials offer a model that reduces reliance on copied identity documents while giving citizens and staff more control over the information they share.
Microsoft Entra Verified ID provides one route for agencies to explore this model within a familiar, Microsoft-native identity environment. It aligns with open standards for decentralised identity, which matters for interoperability across the many systems that government, aged care, and enterprise organisations operate. This article explains how the technology works, where it may support emerging WA digital identity directions, and what to consider before adopting it.
A verifiable credential is a tamper-evident digital statement issued by a trusted party, held by the individual it concerns, and presented to a third party that needs to check it. The model relies on three roles: an issuer who signs the credential, a holder who stores it in a digital wallet, and a verifier who confirms its authenticity. Because the verifier can validate the cryptographic signature without contacting the issuer directly, the individual controls when and to whom their information is disclosed.
This approach fits the broader national direction set by the Digital ID Act 2024 and the accompanying accreditation arrangements, which emphasise privacy, consent, and reduced data collection. Within Western Australia, initiatives such as the ServiceWA application and the state's wider digital government agenda point towards service and access design where citizens prove attributes rather than surrender documents. Verifiable credentials support that intent by allowing an agency to confirm a claim, such as residency, age, or a professional registration, without retaining the underlying evidence.
Microsoft Entra Verified ID is built on open standards, including the W3C Verifiable Credentials data model and Decentralised Identifiers, so credentials issued through it are not locked to a single proprietary format. An organisation configures an issuer service, defines the credential type and its attributes, and links the issuance process to an existing identity source such as Microsoft Entra ID. Individuals receive credentials into the Microsoft Authenticator wallet on their device, where the credentials remain under their control.
When a citizen or staff member needs to prove something, a verifier presents a request, and the holder consents to share the specific credential. The verifier checks the digital signature and the issuer's decentralised identifier to confirm the credential is genuine and unaltered. Because the exchange is cryptographically verifiable and consent-based, agencies can reduce the manual handling of identity documents while maintaining a clear, auditable trail of what was presented and accepted.
For citizen-facing services, verifiable credentials can streamline onboarding to concessions, permits, and entitlements where an attribute must be confirmed once and reused. A citizen could receive a credential attesting to a verified attribute after an initial proofing process, then present it to multiple agencies without repeating the full check. This reduces friction for the individual and lowers the volume of sensitive data that each agency must collect, store, and protect.
For workforce scenarios, credentials can represent employment status, security clearances, mandatory training, or professional registrations that determine access to systems and facilities. In sectors such as aged care, where worker screening and qualification checks are central to compliance, a verifiable credential model can make those checks faster and more reliable. Verified ID can also strengthen access decisions when combined with Conditional Access, allowing an organisation to require a valid credential before granting entry to sensitive applications or during high-assurance onboarding.
Adopting verifiable credentials is as much a governance exercise as a technical one. Agencies need to decide which attributes warrant a credential, who is authorised to issue them, how long they remain valid, and how revocation is handled when circumstances change. These decisions should be documented in a trust framework that aligns with the Digital ID Act 2024, relevant privacy obligations, and the Australian Cyber Security Centre's guidance on identity and access management.
On the technical side, organisations should plan for wallet availability on citizen and staff devices, accessibility for people who cannot use a smartphone, and integration with existing Microsoft Entra ID environments and directory data. It is prudent to begin with a contained pilot covering a single credential type and a well-defined user group, then measure verification success rates, support demand, and user experience before scaling. Careful attention to lifecycle management, incident response, and interoperability with other jurisdictions will determine whether a credential programme delivers lasting value rather than isolated benefit.

Level 7, 12 St Georges Tce
Perth WA 6000
[email protected]
Ph 1300 NOVATA

In the spirit of reconciliation Novata Solutions acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their Elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today. This land always was, and always will be Aboriginal Land.

Novata Solutions is committed to embracing diversity and eliminating all forms of discrimination through education. We welcomes all people and is respectful of individual identities.