<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR00001Vdlsx0ABOkta Classic EngineMulti-Factor AuthenticationAnswered2026-09-22T19:24:55.000Z2026-04-05T19:44:27.000Z2026-09-22T19:24:55.000Z

IsaacB.81593 (Customer) asked a question.

Getting a valid AMR with Entra as external IDP

Hi:

I am trying to set up an org with Entra as an external IDP. I'm successful at getting the IDP to work and to do JIT provisioning of users. I want to pull an authentication method reference AMR from Entra, indicating to Okta, and apps downstream, what, if any MFA the user did in Entra.

I followed the setup described here - https://www.youtube.com/watch?v=lnOVsY3T6bE - but did not see the AMR in the debug data in the log. A key part of the video has you setting up custom app user attributes in the SAML IDP profile.

I read somewhere that the Entra does not pass the AMR correctly to Okta in SAML.

So, I'd like to try OIDC. Setting up the IDP-SP seems straightforward and I got that working. But the part I'm unclear about is if I need to add any custom attributes to the app user profile for OIDC. Do I add the exact user profile attributes in OIDC as I do for SAML? Is this documented anywhere?

Thanks,

 


  • Paul S. (Okta, Inc.)

    Updating this response for ease of access and reference:

     

    When configuring Entra ID as an external Identity Provider (IdP) via OpenID Connect (OIDC), Okta does not map the Authentication Methods References (amr) claim by default. To pass the amr

    claim to Okta and downstream applications, administrators must explicitly define the attribute in the Okta Profile Editor, use Entra ID v1.0 endpoints, and enable Authentication Claims Sharing.

     

    Applies To

    • Okta Identity Engine (OIE)
    • Okta Classic Engine
    • OpenID Connect (OIDC)
    • Entra ID (External Identity Provider)

     

    Solution

    How is the attribute mapped in Okta?

    Create a custom attribute in the Identity Provider profile and map it to the Okta user profile.

    1. Go to Directory, and then select Profile Editor in the Okta Admin Console.
    2. Locate the profile for the Entra OIDC Identity Provider and select Profile.
    3. Select Add Attribute.
    4. Enter amr in the External Name field. NOTE: This must match the exact claim name coming from Entra.
    5. Enter amr or entra_amr in the Variable Name and Display Name fields.
    6. Save the attribute.
    7. Configure the Mappings to map the new Identity Provider attribute (appuser.amr) into the Okta user profile (user.entra_amr).

     

    Entra ID endpoint compatibility requires v1.0 endpoints.

    When Okta processes OIDC claims, Okta looks in the ID Token and the UserInfo endpoint. If administrators configure a UserInfo endpoint in the Okta Identity Provider setup, Okta ignores the ID token payload and only checks the UserInfo response for custom claims. A known compatibility issue exists when passing the amr claim from Entra ID via OIDC using Entra v2.0 endpoints. Entra ID v2.0 endpoints return an Access Token with an issuer claim that does not match the published OIDC configuration. If Okta attempts to validate this token to extract the amr claim, the authentication flow stops and prevents successful login.

    Resolve this issue and successfully pull the amr claim by configuring the Okta Identity Provider with Microsoft Entra ID v1.0 endpoints.

     

    NOTE: Ensure that acceptMappedClaims is set to truein the Entra ID App Manifest.

     

    How is Okta Claims Sharing configured?

    Mapping the attribute is not sufficient to indicate to Okta that multifactor authentication (MFA) was already performed in Entra. Administrators must enable Authentication Claims Sharing. When this setting is enabled, Okta actively looks for the amr

    array in the token. If the token contains MFA indicators from Entra, Okta satisfies the sign-on policy MFA requirements for that session.

     

    Enable Authentication Claims Sharing to allow Okta to satisfy sign-on policy MFA requirements.

    1. Open the Entra OIDC Identity Provider settings in the Okta Admin Console.
    2. Select the Trust claims from this identity provider checkbox.

     

    Related References

     

    Expand Post
    Selected as Best
  • Paul S. (Okta, Inc.)

    Hello @IsaacB.81593 (Customer)​ Thank you for posting on our Community page!

     

    For the OIDC setup you can review our documentation below:

    https://developer.okta.com/docs/guides/social-login/microsoft/main/#

     

    Please also see our documentation for SAML and WS-Fed below:

    https://support.okta.com/help/s/article/Integrate-Microsoft-Entra-as-an-Identity-Provider-for-Okta-and-Vice-Versa?language=en_US

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
    • IsaacB.81593 (Customer)

      Thanks, Paul. The documentation describes the basic OIDC setup. I followed and got a working integration, but no AMR. The SAML documentation discusses defining and mapping attributes, but not the OIDC. So, I'm wondering if anyone in the community has insight about these steps, i.e., getting the AMR claim. Thanks all.

      • Paul S. (Okta, Inc.)

        Hi @IsaacB.81593 (Customer)​ My advice would be to reach out via devforum.okta.com to take advantage of their expertise.

         

        Thank you for reaching out to our Community and have a great day!

        --

        Help others in the community by liking or hitting Select as Best if this response helped you.

         

        Expand Post
  • Paul S. (Okta, Inc.)

    Updating this response for ease of access and reference:

     

    When configuring Entra ID as an external Identity Provider (IdP) via OpenID Connect (OIDC), Okta does not map the Authentication Methods References (amr) claim by default. To pass the amr

    claim to Okta and downstream applications, administrators must explicitly define the attribute in the Okta Profile Editor, use Entra ID v1.0 endpoints, and enable Authentication Claims Sharing.

     

    Applies To

    • Okta Identity Engine (OIE)
    • Okta Classic Engine
    • OpenID Connect (OIDC)
    • Entra ID (External Identity Provider)

     

    Solution

    How is the attribute mapped in Okta?

    Create a custom attribute in the Identity Provider profile and map it to the Okta user profile.

    1. Go to Directory, and then select Profile Editor in the Okta Admin Console.
    2. Locate the profile for the Entra OIDC Identity Provider and select Profile.
    3. Select Add Attribute.
    4. Enter amr in the External Name field. NOTE: This must match the exact claim name coming from Entra.
    5. Enter amr or entra_amr in the Variable Name and Display Name fields.
    6. Save the attribute.
    7. Configure the Mappings to map the new Identity Provider attribute (appuser.amr) into the Okta user profile (user.entra_amr).

     

    Entra ID endpoint compatibility requires v1.0 endpoints.

    When Okta processes OIDC claims, Okta looks in the ID Token and the UserInfo endpoint. If administrators configure a UserInfo endpoint in the Okta Identity Provider setup, Okta ignores the ID token payload and only checks the UserInfo response for custom claims. A known compatibility issue exists when passing the amr claim from Entra ID via OIDC using Entra v2.0 endpoints. Entra ID v2.0 endpoints return an Access Token with an issuer claim that does not match the published OIDC configuration. If Okta attempts to validate this token to extract the amr claim, the authentication flow stops and prevents successful login.

    Resolve this issue and successfully pull the amr claim by configuring the Okta Identity Provider with Microsoft Entra ID v1.0 endpoints.

     

    NOTE: Ensure that acceptMappedClaims is set to truein the Entra ID App Manifest.

     

    How is Okta Claims Sharing configured?

    Mapping the attribute is not sufficient to indicate to Okta that multifactor authentication (MFA) was already performed in Entra. Administrators must enable Authentication Claims Sharing. When this setting is enabled, Okta actively looks for the amr

    array in the token. If the token contains MFA indicators from Entra, Okta satisfies the sign-on policy MFA requirements for that session.

     

    Enable Authentication Claims Sharing to allow Okta to satisfy sign-on policy MFA requirements.

    1. Open the Entra OIDC Identity Provider settings in the Okta Admin Console.
    2. Select the Trust claims from this identity provider checkbox.

     

    Related References

     

    Expand Post
    Selected as Best

Loading
Getting a valid AMR with Entra as external IDP