[midPoint] OIDC authentication - Matching users by an attribute other than 'name'
Markus Calmius
markus.calmius at proton.ch
Thu Jun 25 10:55:55 CEST 2026
Hi Gianluca,
our keycloak config contains this:
<nameOfUsernameAttribute>email</nameOfUsernameAttribute>
Maybe that will solve this issue
Kind regards,
Markus
On Wednesday, 24 June 2026 at 22:57, Gianluca Bisi via midPoint <midpoint at lists.evolveum.com> wrote:
> Hi everyone,
>
> We are currently working on integrating midPoint v4.8 with Microsoft Entra ID using the OIDC authentication module.
>
> During our implementation, we ran into a structural constraint: it appears that midPoint’s OIDC (and SAML2) authentication modules strictly use the incoming claim to match against the user's nameattribute (the core username field) in midPoint.
>
> We looked into alternative mechanisms such as attributeVerification or focusIdentification modules, but according to our analysis and documentation, these flexible authentication components seem to only apply to password-reset or user-recovery flows.
>
> In our specific use case, we need to map the incoming OIDC claim to a different unique attribute within midPoint instead of the default name field.
>
> Has anyone encountered this specific requirement before? If so, how did you resolve or work around it? Is there an advanced or hidden configuration within the security policy that allows matching external IdP claims against custom or alternative user attributes?
>
> Any insights, workarounds, or documentation pointers would be greatly appreciated.
>
> Best regards,
>
> Gianluca Bisi
> Developer | Rakkau
> gbisi at rakkau.com
> www.rakkau.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20260625/d7232101/attachment.htm>
More information about the midPoint
mailing list