<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
ナビゲーションへスキップメインコンテンツへスキップ
0D51Y0000ALoiMBSQZOkta Classic EngineUniversal DirectoryAnswered2024-04-30T09:36:12.000Z2021-01-25T23:38:51.000Z2021-06-08T18:24:14.000Z

JohnO.45837 (XIX.AI) さんが質問をしました。

Can user matching with an IdP be made case insensitive?

We're developing an external MFA solution by configuring a SAML IdP as 'Factor Only' and then enabling it as an MFA factor.

 

Everything works great, except that usernames passed to us in the subject of the SAML assertion (saml2:NameID) are case sensitive and our solution stores them as case insensitive.

 

So, when we return the SAML assertion to Okta, it fails because the names are not identical, case-sensitive matches.

 

Is there a way to configure profile mappings (or anything, really) to not require this to match exactly on case, or to downcase and then accept a downcase match on the return SAML?

 

Otherwise, we'll just have to do the work to change our user store to support case sensitivity as well as perform some additional work to prevent collisions on our end.

 

 

 

 

 


  • ea0rr (ea0rr)

    Hello @JohnO.45837 (XIX.AI)​!

     

    I'm Jonatan from the T2 support team.

    Thanks for using our Help Center community.

     

    Unfortunately, after doing some research it doesn't look like there is a way to change case sensitive from the Okta side for your particular use case where the problem is the username value used in the SAML assertion.

     

    I suggest you create an Okta Idea with the details of the problem so that the community can vote on it. If it gets enough votes, the developers team will have more visibility and there will be more chances for the feature to be introduced in the future.

     

    I hope this clarifies your doubts. Please don't hesitate to contact us if you have any other questions or problems with your Okta products.

    投稿を展開
  • DariuszM.10078 (Customer)

    What is the solution of this topic?

    I have similar problem.

この質問は閉じられました。
読み込み中
Can user matching with an IdP be made case insensitive?