Configure SAML token encryption to use a different encryption algorithm

Nicholas 20 Reputation points
2023-07-06T13:43:19.5366667+00:00

Is it possible to configure SAML token encryption to use a different encryption algorithm? I know Azure AD uses AES-256 in CBC mode by default, but I would like to configure an enterprise application to use other algorithms supported by the xmlenc spec https://www.w3.org/TR/xmlenc-core1/#sec-Algorithms like AES-128/AES-256 in GCM mode.

Microsoft Security Microsoft Entra Microsoft Entra ID
{count} votes

Accepted answer
  1. Alfredo Revilla - Upwork Top Talent | IAM SWE SWA 27,526 Reputation points Moderator
    2023-07-07T20:01:20.5233333+00:00

    Hello @Nicholas , currently Azure AD only supports AES-256 for token encryption. You can let the Azure AD product team know about your interest posting and idea in the Azure Feedback forums.

    Let us know if you need additional assistance. If the answer was helpful, please accept it and rate it so that others facing a similar issue can easily find a solution.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.