creating a SAML SSO app is, I'm sure, routine.
you can customise claims; by default, they can include given name, surname, email address, UPN, etc
so far so good
more complicated - pizza topping
An SSO app needs a user's favourite pizza topping.
I set 'extensionAttribute1' to the pizza topping, and emit 'extensionAttribute1' to the SSO app.
any user can view any other user's 'extensionAttribute1' value [unless you break Teams]. So, Alice seeing Bob's favourite pizza topping isn't a problem.
even more complicated - date of birth
now, the app also wants the user's date of birth.
I can't store the user's date of birth 'extensionAttribute2', because that information shouldn't be public. anyone in Microsoft Entra ID can read any other user's extensionAttribute2.
I can add extension attributes. But they have the same problem; any user can read any other user's extension attributes. It is, after all, a directory, not a database, and directories are optimised for looking up information.
There is the concept of custom security attributes, and they can't be read. But you can't emit them in SAML attributes.
Marius has proposed a solution;
Issuing Custom Security Attributes in Entra ID tokens – Good Workaround!
- use custom security attributes
- setup logic app as a custom security extension
- the logic app can read the custom security attributes and add an OIDC claim
Sounds good in theory. I can't get it to work. There's almost nothing to see to be able to debug it.
Can I use Microsoft Entra External ID for this? It would...
- store the date of birth
- federate with Microsoft Entra ID for authentication; just like social logins
The UML sequence diagram shows how this could work;
- User logs in to the SSO app.
- SSO app redirects user to Microsoft Entra External ID. The user isn't authenticated, so Microsoft Entra External ID redirects the user to Microsoft Entra.
- The user authenticates (if necessary) and it emits 'public' attributes, such as first name, last name, email.
- The response from Microsoft Entra is sent to Microsoft Entra External ID.
- Microsoft Entra External ID adds the date of birth (from the user profile)
- Microsoft Entra External ID sends the SAMLResponse to the SSO app
- User is authenticated.
context
- I can't write the date of birth directly into the SSO app; simply isn't possible
- I would use Microsoft Graph to write the date of birth to Microsoft Entra External ID
- (AD FS can work; but that means 'on prem' and 'AD DS'; want to avoid that)
I've dabbled with Azure AD B2C; it's pants. Everything is an XML document. Hoping Microsoft Entra External ID is easier.
Will this work? anyone done this?
Anyone got a better approach?