Updated FAQ (markdown)

fufesou
2026-02-04 13:34:33 +08:00
parent ff355e01d4
commit d6a1206a38

28
FAQ.md

@@ -1839,20 +1839,20 @@ Configurations:
- Okta https://developer.okta.com/docs/guides/customize-tokens-groups-claim/main/#add-a-groups-claim-for-the-org-authorization-server - Okta https://developer.okta.com/docs/guides/customize-tokens-groups-claim/main/#add-a-groups-claim-for-the-org-authorization-server
- Azure https://learn.microsoft.com/en-us/entra/identity-platform/optional-claims?tabs=manifest#configuring-group-optional-claims - Azure https://learn.microsoft.com/en-us/entra/identity-platform/optional-claims?tabs=manifest#configuring-group-optional-claims
Returning group names (instead of IDs) requires setting these fields: Returning group names (instead of IDs) requires setting these fields:
```json ```json
"groupMembershipClaims": "ApplicationGroup", "groupMembershipClaims": "ApplicationGroup",
"optionalClaims": { "optionalClaims": {
"idToken": [ "idToken": [
{ {
"name": "groups", "name": "groups",
"additionalProperties": [ "additionalProperties": [
"sam_account_name", "sam_account_name",
"cloud_displayname" "cloud_displayname"
] ]
} }
] ]
} }
``` ```
- Keycloak Clients -> (your client) -> Client scopes -> (clientid)-dedicated -> Mappers -> Add mappers -> By configuration -> Group Membership - Keycloak Clients -> (your client) -> Client scopes -> (clientid)-dedicated -> Mappers -> Add mappers -> By configuration -> Group Membership
"Token Claim Name": "groups" "Token Claim Name": "groups"