OIDC · before and after the IdP migration
What the move
changed.
Before: https://login.microsoftonline.com/b164ba84-e972-477c-9709-7b1d0fb7d0c1/v2.0, signed in 2026-10-04 11:27:52 UTC. After: https://trial-3394347.okta.com, signed in 2026-10-04 11:33:38 UTC. Claims are lined up by what they mean, not what they are called, so a claim the new IdP spells differently still sits opposite its old self. Values are compared case-insensitively except subject identifiers, which are compared exactly, and multi-valued claims are compared as sets.
The new issuer minted a different sub for the same person, as it always will: a
sub is only unique within one issuer. Accounts keyed on the old one will not be
found. Migrate on a claim below that is unchanged — usually the email address or a
directory object ID.
Claim by claim 15 rows
The sub claim is only unique within one issuer, and a new IdP issues new ones for the same people. Existing accounts keyed on the old sub will not be found.
What the user types to sign in. Mutable at the directory — do not use it as a primary key.
Preferred address. Not guaranteed unique and not necessarily verified.
Full name as the directory holds it.
The new IdP no longer sends this. Anything in the application that reads it will now get nothing.
The new IdP no longer sends this. Anything in the application that reads it will now get nothing.
Set when the sign-in was federated from somewhere else.
The new IdP no longer sends this. Anything in the application that reads it will now get nothing.
The two snapshots