Azure SSO SAML Response encoding issue

Dima Dima 0 Reputation points
2023-05-30T14:41:06.1266667+00:00

Hello!
When I get user info from azure i got response liked this Screenshot 2023-05-29 at 23.23.32

This user has no firstName and Surname but if I add if I get encrypted response

Screenshot 2023-05-29 at 23.25.33

How can I decrypt it ?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. Akshay-MSFT 18,011 Reputation points Microsoft Employee Moderator
    2023-05-31T06:53:27.4866667+00:00

    @Dima Dima

    Thank your for posting your query on Microsoft Q&A. From above query I could understand that you are looking for a way to decrypt the encrypted SAML response token.

    Please do let me know if this is not correct by responding in the comments section.

    • When enabling token encryption in the Azure AD portal, you would have to provide the public key of the cert. on the application side.

    import-certificate-small

    • Once the certificate is imported, and the private key is configured for use on the application side, activate encryption by selecting the ... next to the thumbprint status, and then select Activate token encryption from the options in the dropdown menu.
    • You would be needing the Private key of the same certificate to decrypt the SAML response.

    Thanks,

    Akshay Kaushik

    Please "Accept the answer" (Yes), and share your feedback if the suggestion answers you’re your query. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.