auth test lab saml oidc json setup

OIDC · before and after the IdP migration

What the move
changed.

Before: https://login.microsoftonline.com/b164ba84-e972-477c-9709-7b1d0fb7d0c1/v2.0, signed in 2026-10-04 11:27:52 UTC. After: https://trial-3394347.okta.com, signed in 2026-10-04 11:33:38 UTC. Claims are lined up by what they mean, not what they are called, so a claim the new IdP spells differently still sits opposite its old self. Values are compared case-insensitively except subject identifiers, which are compared exactly, and multi-valued claims are compared as sets.

0 unchanged
5 changed
3 dropped
7 new
The subject identifier changed Before, sub: 0-_x7MLGOCTAFoxeSvBSFQQp4ODciFjhPhlmdv6CQpM After, sub: 00u17dk517xLGPfvE698

The new issuer minted a different sub for the same person, as it always will: a sub is only unique within one issuer. Accounts keyed on the old one will not be found. Migrate on a claim below that is unchanged — usually the email address or a directory object ID.

Claim by claim 15 rows

● Before ● After —●— unchanged –◆– value changed ●— dropped or new
Before · https://login.microsoftonline.com/b164ba84-e972-477c-9709-7b1d0fb7d0c1/v2.0
concept
After · https://trial-3394347.okta.com
sub via ID token + UserInfo
0-_x7MLGOCTAFoxeSvBSFQQp4ODciFjhPhlmdv6CQpM
Subject
changed
sub via ID token + UserInfo
00u17dk517xLGPfvE698

The sub claim is only unique within one issuer, and a new IdP issues new ones for the same people. Existing accounts keyed on the old sub will not be found.

preferred_username
govvy9@gmail.com
Username
changed
preferred_username via ID token + UserInfo
gov@tenantflex.com

What the user types to sign in. Mutable at the directory — do not use it as a primary key.

email via ID token + UserInfo
govvy9@gmail.com
Email
changed
email via ID token + UserInfo
gov@tenantflex.com

Preferred address. Not guaranteed unique and not necessarily verified.

not sent
Email verified
new
email_verified via UserInfo
true
name via ID token + UserInfo
Lee Gov
Display name
changed
name via ID token + UserInfo
Lee McGovern

Full name as the directory holds it.

not sent
Given name
new
given_name via UserInfo
Lee
not sent
Family name
new
family_name via UserInfo
McGovern
oid
6f5d385a-fde9-4a88-8233-2e990af99cb7
Directory object ID
dropped
not sent

The new IdP no longer sends this. Anything in the application that reads it will now get nothing.

tid
b164ba84-e972-477c-9709-7b1d0fb7d0c1
Tenant
dropped
not sent

The new IdP no longer sends this. Anything in the application that reads it will now get nothing.

idp
https://sts.windows.net/9188040d-6c67-4c5b-b112-36a304b66dad/
Upstream IdP
changed
idp
00o17dk513jR27lTC698

Set when the sign-in was federated from somewhere else.

not sent
Authn methods
new
amr
mfaotppwdokta_verify
not sent
Locale
new
locale via UserInfo
en_US
not sent
Time zone
new
zoneinfo via UserInfo
America/Los_Angeles
picture via UserInfo
https://graph.microsoft.com/v1.0/me/photo/$value
Picture
dropped
not sent

The new IdP no longer sends this. Anything in the application that reads it will now get nothing.

not sent
updated_at
new
updated_at via UserInfo
1791113578 · 2026-10-04 11:32:58 UTC

The two snapshots

before

Authorization code
IdP
https://login.microsoftonline.com/b164ba84-e972-477c-9709-7b1d0fb7d0c1/v2.0
subject
0-_x7MLGOCTAFoxeSvBSFQQp4ODciFjhPhlmdv6CQpM
claims
8
received
2026-10-04 11:27:52 UTC

after

Authorization code
IdP
https://trial-3394347.okta.com
subject
00u17dk517xLGPfvE698
claims
12
received
2026-10-04 11:33:38 UTC