0D54z00009WnMlCCAVOkta Classic EngineSingle Sign-OnAnswered2023-08-16T18:45:53.000Z2023-08-15T17:56:53.000Z2023-08-16T18:45:53.000Z

SamuelP.19985 (Customer) asked a question.

Azure IdP sending hidden claims in SAML Assertion starting with http://schemas.microsoft.com/

I have a customer trying to integrate with our app via Azure SSO SAML 2.0. the SAML handshake is working fine but when the user is trying to enter the application they get a 400 error. The logs show "Unknown Profile Attribute" and debug lists the following attribute names:

 

AttributeNames

[http://schemas.microsoft.com/identity/claims/tenantid, http://schemas.microsoft.com/identity/claims/identityprovider, http://schemas.microsoft.com/identity/claims/objectidentifier, http://schemas.microsoft.com/claims/authnmethodsreferences]

 

I'm lost because I've done hundreds of these integrations and I've never seen this issue before.

 

I don't know of a location in the Azure config where we can stop these attributes from being passed. Has anyone seen this or been able to fix this issue?


This question is closed.

Recommended content

No recommended content found...