<div dir="ltr"><div>Hi everyone,</div><div><br></div><div>Lothar is correct. The attribute or claim selected in nameOfUsernameAttribute must match the name attribute of the user in midPoint.</div><div><br></div><div>In our case, even though we receive the email within the claims, the user has a different identifier configured as the name in midPoint, which prevents the authentication from working correctly under this configuration.</div><div><br></div><div>We would like to know if it is possible to use a different midPoint attribute for OIDC authentication instead of the default name field.</div><div><br></div><div>Best regards,</div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div><div dir="ltr"><div dir="ltr"><font><div style="color:rgb(80,0,80)"><b><font face="tahoma, sans-serif" color="#666666">Gianluca Bisi</font></b></div><div style="color:rgb(80,0,80)"><font color="#999999" face="tahoma, sans-serif">Developer | Rakkau</font></div><div style="color:rgb(80,0,80)"><font color="#999999" face="tahoma, sans-serif"><a href="mailto:gbisi@rakkau.com" target="_blank">gbisi@rakkau.com</a></font></div><div style="color:rgb(80,0,80)"><font color="#999999" face="tahoma, sans-serif"><a href="http://www.rakkau.com" target="_blank">www.rakkau.com</a></font></div></font></div></div></div><div style="margin:2px 0px 0px;color:rgb(80,0,80)"></div></div></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">El jue, 25 jun 2026 a la(s) 7:40 a.m., Lothar Haeger via midPoint (<a href="mailto:midpoint@lists.evolveum.com" target="_blank">midpoint@lists.evolveum.com</a>) escribió:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div><br><div><blockquote type="cite"><div>Am 25.06.2026 um 10:55 schrieb Markus Calmius via midPoint <<a href="mailto:midpoint@lists.evolveum.com" target="_blank">midpoint@lists.evolveum.com</a>>:</div><div><div style="font-family:Arial,sans-serif;font-size:14px"><br></div><div style="font-family:Arial,sans-serif;font-size:14px">our keycloak config contains this:</div><div style="font-family:Arial,sans-serif;font-size:14px"><code><span><span><</span><span>nameOfUsernameAttribute</span><span>></span></span><span><code>email</code></span><span><span></</span><span>nameOfUsernameAttribute</span><span>></span></span></code></div></div></blockquote><br></div><div>I ran into the same question as Gianluca and my understanding is that <font face="Consolas"><nameOfUsernameAttribute>email</nameOfUsernameAttribute></font> means: "read the email claim from Keycloak, then look up the midPoint user whose name equals that email." If name isn't the email, it matches nobody. It does not search against an "email" property in midPoint.</div></div>_______________________________________________<br>
midPoint mailing list<br>
<a href="mailto:midPoint@lists.evolveum.com" target="_blank">midPoint@lists.evolveum.com</a><br>
<a href="https://lists.evolveum.com/mailman/listinfo/midpoint" rel="noreferrer" target="_blank">https://lists.evolveum.com/mailman/listinfo/midpoint</a><br>
</blockquote></div>