Updated FAQ (markdown)

fufesou
2026-02-04 13:34:33 +08:00
parent ff355e01d4
commit d6a1206a38

28
FAQ.md

@@ -1839,20 +1839,20 @@ Configurations:
- Okta https://developer.okta.com/docs/guides/customize-tokens-groups-claim/main/#add-a-groups-claim-for-the-org-authorization-server
- Azure https://learn.microsoft.com/en-us/entra/identity-platform/optional-claims?tabs=manifest#configuring-group-optional-claims
Returning group names (instead of IDs) requires setting these fields:
```json
"groupMembershipClaims": "ApplicationGroup",
"optionalClaims": {
"idToken": [
{
"name": "groups",
"additionalProperties": [
"sam_account_name",
"cloud_displayname"
]
}
]
}
```
```json
"groupMembershipClaims": "ApplicationGroup",
"optionalClaims": {
"idToken": [
{
"name": "groups",
"additionalProperties": [
"sam_account_name",
"cloud_displayname"
]
}
]
}
```
- Keycloak Clients -> (your client) -> Client scopes -> (clientid)-dedicated -> Mappers -> Add mappers -> By configuration -> Group Membership
"Token Claim Name": "groups"