
IsaacB.81593 (Customer) asked a question.
Getting a valid AMR with Entra as external IDP
Hi:
I am trying to set up an org with Entra as an external IDP. I'm successful at getting the IDP to work and to do JIT provisioning of users. I want to pull an authentication method reference AMR from Entra, indicating to Okta, and apps downstream, what, if any MFA the user did in Entra.
I followed the setup described here - https://www.youtube.com/watch?v=lnOVsY3T6bE - but did not see the AMR in the debug data in the log. A key part of the video has you setting up custom app user attributes in the SAML IDP profile.
I read somewhere that the Entra does not pass the AMR correctly to Okta in SAML.
So, I'd like to try OIDC. Setting up the IDP-SP seems straightforward and I got that working. But the part I'm unclear about is if I need to add any custom attributes to the app user profile for OIDC. Do I add the exact user profile attributes in OIDC as I do for SAML? Is this documented anywhere?
Thanks,

Updating this response for ease of access and reference:
When configuring Entra ID as an external Identity Provider (IdP) via OpenID Connect (OIDC), Okta does not map the Authentication Methods References (amr) claim by default. To pass the amr
claim to Okta and downstream applications, administrators must explicitly define the attribute in the Okta Profile Editor, use Entra ID v1.0 endpoints, and enable Authentication Claims Sharing.
Applies To
Solution
How is the attribute mapped in Okta?
Create a custom attribute in the Identity Provider profile and map it to the Okta user profile.
Entra ID endpoint compatibility requires v1.0 endpoints.
When Okta processes OIDC claims, Okta looks in the ID Token and the UserInfo endpoint. If administrators configure a UserInfo endpoint in the Okta Identity Provider setup, Okta ignores the ID token payload and only checks the UserInfo response for custom claims. A known compatibility issue exists when passing the amr claim from Entra ID via OIDC using Entra v2.0 endpoints. Entra ID v2.0 endpoints return an Access Token with an issuer claim that does not match the published OIDC configuration. If Okta attempts to validate this token to extract the amr claim, the authentication flow stops and prevents successful login.
Resolve this issue and successfully pull the amr claim by configuring the Okta Identity Provider with Microsoft Entra ID v1.0 endpoints.
NOTE: Ensure that acceptMappedClaims is set to truein the Entra ID App Manifest.
How is Okta Claims Sharing configured?
Mapping the attribute is not sufficient to indicate to Okta that multifactor authentication (MFA) was already performed in Entra. Administrators must enable Authentication Claims Sharing. When this setting is enabled, Okta actively looks for the amr
array in the token. If the token contains MFA indicators from Entra, Okta satisfies the sign-on policy MFA requirements for that session.
Enable Authentication Claims Sharing to allow Okta to satisfy sign-on policy MFA requirements.
Related References