diff --git a/FAQ.md b/FAQ.md index 6a7e6d1..04a8fc5 100644 --- a/FAQ.md +++ b/FAQ.md @@ -1839,20 +1839,20 @@ Configurations: - Okta https://developer.okta.com/docs/guides/customize-tokens-groups-claim/main/#add-a-groups-claim-for-the-org-authorization-server - Azure https://learn.microsoft.com/en-us/entra/identity-platform/optional-claims?tabs=manifest#configuring-group-optional-claims Returning group names (instead of IDs) requires setting these fields: - ```json - "groupMembershipClaims": "ApplicationGroup", - "optionalClaims": { - "idToken": [ - { - "name": "groups", - "additionalProperties": [ - "sam_account_name", - "cloud_displayname" - ] - } - ] - } - ``` +```json + "groupMembershipClaims": "ApplicationGroup", + "optionalClaims": { + "idToken": [ + { + "name": "groups", + "additionalProperties": [ + "sam_account_name", + "cloud_displayname" + ] + } + ] + } +``` - Keycloak Clients -> (your client) -> Client scopes -> (clientid)-dedicated -> Mappers -> Add mappers -> By configuration -> Group Membership "Token Claim Name": "groups"