SAML Unique Identifier Value

adminER 1 Reputation point
2021-08-30T22:54:37.583+00:00

Is there a way to change the value of the SSO Unique User Identifier for a specific application?

It is using the user.userprincipalname and I need to use the email address. I don't seem to have any options and clicking the ... does nothing.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,381 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 33,706 Reputation points Microsoft Employee
    2021-08-31T19:59:42.243+00:00

    Yes, you can change the Unique User Identifier to from user.userprincipalname to user.mail. Make sure you have met the prerequisites by signing in with an account that is either a Global Administrator, Cloud Application Administrator, Application Administrator, or owner of the service principal.

    Under Single Sign-On > SAML > User attributes and claims > Edit, you have to select "user.mail" from the dropdown and hit "save."

    128026-image.png

    I was able to test from my side and get it to work so it seems like it could be either a permissions error or browser latency issue. You can also try logging in from a different browser and see if that resolves it.

    https://learn.microsoft.com/en-us/azure/active-directory/develop/active-directory-saml-claims-cusomization

    https://www.concurtraining.com/customers/tech_pubs/Docs/_Current/SG_Shr/Shr_SG_SSO_Mgmt.pdf

    0 comments No comments