SAML · before and after the IdP migration
What the move
changed.
Before: https://sts.windows.net/b164ba84-e972-477c-9709-7b1d0fb7d0c1/, signed in 2026-10-04 11:27:39 UTC. After: http://www.okta.com/exk18cdjgntW2SUDH698, signed in 2026-10-04 11:37:31 UTC. Claims are lined up by what they mean, not what they are called, so a claim the new IdP spells differently still sits opposite its old self. Values are compared case-insensitively except subject identifiers, which are compared exactly, and multi-valued claims are compared as sets.
The new IdP is sending a different NameID for the same person. Accounts the application keyed on the old one will not be found. Either configure the new IdP to send the old value, or migrate on a claim below that is unchanged — usually the directory object ID or the email address.
The NameID format also changed, from urn:oasis:names:tc:SAML:2.0:nameid-format:persistent to
urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress.
Claim by claim 9 rows
The NameID is whatever the IdP is configured to mint, and a different IdP mints a different one — or the same value in a different NameID format. Do not match existing accounts on it unless the old and new values agree.
Preferred address. Not guaranteed unique and not necessarily verified.
Full name as the directory holds it.
The new IdP no longer sends this. Anything in the application that reads it will now get nothing.
The new IdP no longer sends this. Anything in the application that reads it will now get nothing.
The new IdP no longer sends this. Anything in the application that reads it will now get nothing.
The new IdP no longer sends this. Anything in the application that reads it will now get nothing.
The two snapshots