[midPoint] OIDC authentication - Matching users by an attribute other than 'name'

Gianluca Bisi gbisi at rakkau.com
Wed Jun 24 22:56:52 CEST 2026


Hi everyone,

We are currently working on integrating midPoint v4.8 with Microsoft Entra
ID using the OIDC authentication module.

During our implementation, we ran into a structural constraint: it appears
that midPoint’s OIDC (and SAML2) authentication modules strictly use the
incoming claim to match against the user's *name *attribute (the core
username field) in midPoint.

We looked into alternative mechanisms such as attributeVerification or
focusIdentification modules, but according to our analysis and
documentation, these flexible authentication components seem to only apply
to password-reset or user-recovery flows.

In our specific use case, we need to map the incoming OIDC claim to a
different unique attribute within midPoint instead of the default name
field.

Has anyone encountered this specific requirement before? If so, how did you
resolve or work around it? Is there an advanced or hidden configuration
within the security policy that allows matching external IdP claims against
custom or alternative user attributes?

Any insights, workarounds, or documentation pointers would be greatly
appreciated.

Best regards,
*Gianluca Bisi*
Developer | Rakkau
gbisi at rakkau.com
www.rakkau.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20260624/67b27800/attachment.htm>


More information about the midPoint mailing list