auth test lab saml oidc json setup

SAML · before and after the IdP migration

What the move
changed.

Before: https://sts.windows.net/b164ba84-e972-477c-9709-7b1d0fb7d0c1/, signed in 2026-10-04 11:27:39 UTC. After: http://www.okta.com/exk18cdjgntW2SUDH698, signed in 2026-10-04 11:37:31 UTC. Claims are lined up by what they mean, not what they are called, so a claim the new IdP spells differently still sits opposite its old self. Values are compared case-insensitively except subject identifiers, which are compared exactly, and multi-valued claims are compared as sets.

2 unchanged
3 changed
4 dropped
0 new
The subject identifier changed Before, NameID: BMdsZMIDdSWzT_fxhRdyGP-wA3lQCTOdwY_GeoJDfwA After, NameID: gov@tenantflex.com

The new IdP is sending a different NameID for the same person. Accounts the application keyed on the old one will not be found. Either configure the new IdP to send the old value, or migrate on a claim below that is unchanged — usually the directory object ID or the email address.

The NameID format also changed, from urn:oasis:names:tc:SAML:2.0:nameid-format:persistent to urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress.

Claim by claim 9 rows

● Before ● After —●— unchanged –◆– value changed ●— dropped or new
Before · https://sts.windows.net/b164ba84-e972-477c-9709-7b1d0fb7d0c1/
concept
After · http://www.okta.com/exk18cdjgntW2SUDH698
NameID urn:oasis:names:tc:SAML:2.0:nameid-format:persistent
BMdsZMIDdSWzT_fxhRdyGP-wA3lQCTOdwY_GeoJDfwA
Subject
changed
NameID urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
gov@tenantflex.com

The NameID is whatever the IdP is configured to mint, and a different IdP mints a different one — or the same value in a different NameID format. Do not match existing accounts on it unless the old and new values agree.

email http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
govvy9@gmail.com
Email
changed
email
gov@tenantflex.com

Preferred address. Not guaranteed unique and not necessarily verified.

displayName http://schemas.microsoft.com/identity/claims/displayname
Lee Gov
Display name
changed
displayName
Lee McGovern

Full name as the directory holds it.

givenName http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
Lee
Given name
unchanged
firstName
Lee
surname http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
McGovern
Family name
unchanged
lastName
McGovern
objectId http://schemas.microsoft.com/identity/claims/objectidentifier
6f5d385a-fde9-4a88-8233-2e990af99cb7
Directory object ID
dropped
not sent

The new IdP no longer sends this. Anything in the application that reads it will now get nothing.

tenantId http://schemas.microsoft.com/identity/claims/tenantid
b164ba84-e972-477c-9709-7b1d0fb7d0c1
Tenant
dropped
not sent

The new IdP no longer sends this. Anything in the application that reads it will now get nothing.

identityProvider http://schemas.microsoft.com/identity/claims/identityprovider
live.com
Upstream IdP
dropped
not sent

The new IdP no longer sends this. Anything in the application that reads it will now get nothing.

authnMethods http://schemas.microsoft.com/claims/authnmethodsreferences
http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/passwordhttp://schemas.microsoft.com/claims/multipleauthnhttp://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/unspecified
Authn methods
dropped
not sent

The new IdP no longer sends this. Anything in the application that reads it will now get nothing.

The two snapshots

before

SP-initiated
IdP
https://sts.windows.net/b164ba84-e972-477c-9709-7b1d0fb7d0c1/
subject
BMdsZMIDdSWzT_fxhRdyGP-wA3lQCTOdwY_GeoJDfwA
claims
9
received
2026-10-04 11:27:39 UTC

after

SP-initiated
IdP
http://www.okta.com/exk18cdjgntW2SUDH698
subject
gov@tenantflex.com
claims
5
received
2026-10-04 11:37:31 UTC