Where users come from

Understand the sign-in sources a OneiD deployment can use, what users see with each, and how groups become roles.

View as Markdown

Every OneiD deployment checks users against one sign-in source. The source decides where users are kept and where their passwords are checked. Applications do not need to know which source is in use: they receive the same kind of tokens either way.

One source per deployment

A OneiD deployment uses exactly one sign-in source. You choose it when the deployment is set up. To use two sources, for example a directory for staff and OneiD accounts for partners, you need two deployments, each with its own OneiD address.

Sources compared

OneiD accounts LDAP and Active Directory OpenID Connect provider (for example Okta) Microsoft Entra ID
What users see The OneiD sign-in page The OneiD sign-in page; they enter their directory user name and password The provider’s own sign-in page Not available
Where the password is checked OneiD Your directory, over LDAPS. OneiD does not store the password. The provider
Who creates users OneiD administrators Your directory administrators The provider’s administrators
sub An opaque OneiD user ID The directory account name, in lower case, without the domain The provider’s sub, unchanged
idp local ldap oidc
MFA OneiD MFA with an authenticator app OneiD MFA with an authenticator app The provider’s own MFA
amr after sign-in ["pwd"], or ["pwd","mfa"] with MFA ["pwd"], or ["pwd","mfa"] with MFA ["external"]

Microsoft Entra ID is not available as a sign-in source. Contact us if you need Entra ID.

Read more about each source:

What applications see

Applications use OneiD in the same way whatever the source:

  • The same endpoints, flows and token formats.
  • The same claims for the same scopes. name, email and the other profile claims come from the source.
  • The same role claim. With OneiD accounts, administrators assign roles in OneiD. With a directory or a provider, roles come from groups (see below).

Three things differ, and your application can read them if it cares:

  • idp (with the profile scope) names the source.
  • amr and acr in the ID token say how the user signed in. With an upstream provider, acr is urn:oltin:ac:external; OneiD cannot see whether the provider asked for MFA.
  • The format of sub. Treat it as opaque and key users by iss and sub together. See Scopes, claims and roles.

From groups to roles

With LDAP and Active Directory and with an OpenID Connect provider, OneiD turns the user’s groups into roles at each sign-in. Your OneiD operator configures four rules:

Rule What it does
Required group Optional. Users who are not members of this group cannot sign in.
Administrators group Optional. Members get OneiD’s All administrator role, which gives full access to the admin console.
Group-to-role mappings Each listed group becomes the role you name, for example group Order-Viewers becomes role OrderViewer.
Pass-through of unmapped groups Optional. Groups without a mapping become roles named with a prefix you choose, for example ext-Finance. A pass-through role never takes the name of a built-in administrator role.

Groups that are not mapped and not passed through give no role.

Warning Choose the administrators group with care. Its members can change every setting in OneiD. Use a small, dedicated group.

For an OpenID Connect provider, OneiD reads the groups and role claims the provider sends. For LDAP and Active Directory, OneiD reads the user’s group memberships from the directory.

Learn more