How to use a Regex Pattern to transform multivalue group claims in JWT OIDC Token?

Suryendu Bhattacharyya 11 Reputation points
2024-03-20T10:46:49.3033333+00:00

I am trying to apply regex-replace for group display name transformations in OIDC ID Tokens.

Group Names: acl_test_group1, acl_test_group2

But the group claims transformation only gives "group1_claim" in the id token claims, That is only the first attribute of the multivalue group attributes.

Group Claim :

Customize the name of the group claim : True

Apply regex replace to groups claim content : True

Regex Pattern: acl_test_(?'group'\S+\d)$

Regex Replace Pattern: {group}_claim

Manifest :

	"optionalClaims": {
		"idToken": [
			{
				"name": "groups",
				"source": null,
				"essential": false,
				"additionalProperties": [
					"emit_as_roles",
                    "cloud_displayname"
				]
			}
		],

Group assignment to Applications :

Display NameObject TypeRole assignedAacl_test_group1GroupDefault Accessacl_test_group1GroupDefault Accessacl_test_group2GroupDefault AccessID Token Claims:

"roleclaim": "group1_claim"

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Locked Question. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.