<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR00001Vdlsx0ABOkta Classic EngineMulti-Factor AuthenticationAnswered2026-04-06T15:02:21.000Z2026-04-05T19:44:27.000Z2026-04-06T15:02:21.000Z

IsaacB.81593 (Customer) asked a question.

Getting a valid AMR with Entra as external IDP

Hi:

I am trying to set up an org with Entra as an external IDP. I'm successful at getting the IDP to work and to do JIT provisioning of users. I want to pull an authentication method reference AMR from Entra, indicating to Okta, and apps downstream, what, if any MFA the user did in Entra.

I followed the setup described here - https://www.youtube.com/watch?v=lnOVsY3T6bE - but did not see the AMR in the debug data in the log. A key part of the video has you setting up custom app user attributes in the SAML IDP profile.

I read somewhere that the Entra does not pass the AMR correctly to Okta in SAML.

So, I'd like to try OIDC. Setting up the IDP-SP seems straightforward and I got that working. But the part I'm unclear about is if I need to add any custom attributes to the app user profile for OIDC. Do I add the exact user profile attributes in OIDC as I do for SAML? Is this documented anywhere?

Thanks,

 


Loading
Getting a valid AMR with Entra as external IDP