App registration group claim is not shown in Enterprise app Single sign-on blade (Portal) in diferent directory (tenant)

Oliver Balun 51 Reputation points
2023-02-20T17:10:05.8266667+00:00

Hello,

I'd like to ask about Enterpise apps and their Single sign-on blade. I have App registration created correctly with optional groups claim Token configuration as shown below:

User's image

This App registration has its corresponding Enterprise app created in the same directory (tenant) -> this Enterprise app has shown the groups claim in Single sign-on blade (Attributes & Claims) and this groups claim can be configured via Portal as shown below:

User's image

User's image

But problem is when I use this App registration for another different directory (tenant). Enterprise app created there in the different directory has not any claims shown in Single sign-on blade (Attributes & Claims) nor any possibility to add it. The Add a group claim button doesn't work (is grey and I cannot click on it). This button also doesn't work in any other Enterprise apps nor directories (tenants). Is there anything wrong with this button for me? Because the documentation says, that button can be also used for this purpose that I am trying to accomplish. -> https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-fed-group-claims#add-group-claims-to-tokens-for-saml-applications-using-sso-configuration

User's image

User's image

I would expect that these claims would be inherited to all Enterprise apps across all tenants as it is pre-defined in App registration from which these Enterprise apps are created.

I need to use this claims definition to filter groups that would be emitted into JWT token so it wouldn't exceed the number of 200 groups (OIDC) which is a limit - as documentation says . -> https://learn.microsoft.com/en-us/azure/active-directory/develop/active-directory-optional-claims#configuring-groups-optional-claims

Please let me know what am I missing, thank you for your help.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} vote

1 answer

Sort by: Most helpful
  1. Anonymous
    2024-08-12T09:27:32.7066667+00:00

    Hi,

    Was there a solution found for this issue?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.