# Where users come from

> Understand the sign-in sources a OneiD deployment can use, what users see with each, and how groups become roles.

Source: https://oltinid.com/docs/sign-in-sources/overview/ · Section: Sign-in sources · All OneiD documentation: https://oltinid.com/llms.txt

Every OneiD deployment checks users against one sign-in source. The source decides where users are kept and where their passwords are checked. Applications do not need to know which source is in use: they receive the same kind of tokens either way.

## One source per deployment

A OneiD deployment uses exactly one sign-in source. You choose it when the deployment is set up. To use two sources, for example a directory for staff and OneiD accounts for partners, you need two deployments, each with its own OneiD address.

## Sources compared

| | OneiD accounts | LDAP and Active Directory | OpenID Connect provider (for example Okta) | Microsoft Entra ID |
|---|---|---|---|---|
| What users see | The OneiD sign-in page | The OneiD sign-in page; they enter their directory user name and password | The provider's own sign-in page | Not available |
| Where the password is checked | OneiD | Your directory, over LDAPS. OneiD does not store the password. | The provider | |
| Who creates users | OneiD administrators | Your directory administrators | The provider's administrators | |
| `sub` | An opaque OneiD user ID | The directory account name, in lower case, without the domain | The provider's `sub`, unchanged | |
| `idp` | `local` | `ldap` | `oidc` | |
| MFA | OneiD MFA with an authenticator app | OneiD MFA with an authenticator app | The provider's own MFA | |
| `amr` after sign-in | `["pwd"]`, or `["pwd","mfa"]` with MFA | `["pwd"]`, or `["pwd","mfa"]` with MFA | `["external"]` | |

Microsoft Entra ID is not available as a sign-in source. [Contact us](https://oltinid.com/contact/?topic=organisation) if you need Entra ID.

Read more about each source:

- [OneiD accounts and MFA](https://oltinid.com/docs/sign-in-sources/oneid-accounts/)
- [LDAP and Active Directory](https://oltinid.com/docs/sign-in-sources/ldap/)
- [Okta and other OpenID Connect providers](https://oltinid.com/docs/sign-in-sources/openid-connect-provider/)

## What applications see

Applications use OneiD in the same way whatever the source:

- The same endpoints, flows and token formats.
- The same claims for the same scopes. `name`, `email` and the other profile claims come from the source.
- The same `role` claim. With OneiD accounts, administrators assign roles in OneiD. With a directory or a provider, roles come from groups (see below).

Three things differ, and your application can read them if it cares:

- `idp` (with the `profile` scope) names the source.
- `amr` and `acr` in the ID token say how the user signed in. With an upstream provider, `acr` is `urn:oltin:ac:external`; OneiD cannot see whether the provider asked for MFA.
- The format of `sub`. Treat it as opaque and key users by `iss` and `sub` together. See [Scopes, claims and roles](https://oltinid.com/docs/guides/scopes-claims-roles/#identify-users-by-issuer-and-subject).

## From groups to roles

With LDAP and Active Directory and with an OpenID Connect provider, OneiD turns the user's groups into roles at each sign-in. Your OneiD operator configures four rules:

| Rule | What it does |
|---|---|
| Required group | Optional. Users who are not members of this group cannot sign in. |
| Administrators group | Optional. Members get OneiD's `All` administrator role, which gives full access to the admin console. |
| Group-to-role mappings | Each listed group becomes the role you name, for example group `Order-Viewers` becomes role `OrderViewer`. |
| Pass-through of unmapped groups | Optional. Groups without a mapping become roles named with a prefix you choose, for example `ext-Finance`. A pass-through role never takes the name of a built-in administrator role. |

Groups that are not mapped and not passed through give no role.

> **Warning:** Choose the administrators group with care. Its members can change every setting in OneiD. Use a small, dedicated group.

For an OpenID Connect provider, OneiD reads the `groups` and `role` claims the provider sends. For LDAP and Active Directory, OneiD reads the user's group memberships from the directory.

## Learn more

- [OneiD accounts and MFA](https://oltinid.com/docs/sign-in-sources/oneid-accounts/)
- [LDAP and Active Directory](https://oltinid.com/docs/sign-in-sources/ldap/)
- [Okta and other OpenID Connect providers](https://oltinid.com/docs/sign-in-sources/openid-connect-provider/)
- [Scopes, claims and roles](https://oltinid.com/docs/guides/scopes-claims-roles/)
