Where users come from
Understand the sign-in sources a OneiD deployment can use, what users see with each, and how groups become roles.
Every OneiD deployment checks users against one sign-in source. The source decides where users are kept and where their passwords are checked. Applications do not need to know which source is in use: they receive the same kind of tokens either way.
One source per deployment
A OneiD deployment uses exactly one sign-in source. You choose it when the deployment is set up. To use two sources, for example a directory for staff and OneiD accounts for partners, you need two deployments, each with its own OneiD address.
Sources compared
| OneiD accounts | LDAP and Active Directory | OpenID Connect provider (for example Okta) | Microsoft Entra ID | |
|---|---|---|---|---|
| What users see | The OneiD sign-in page | The OneiD sign-in page; they enter their directory user name and password | The provider’s own sign-in page | Not available |
| Where the password is checked | OneiD | Your directory, over LDAPS. OneiD does not store the password. | The provider | |
| Who creates users | OneiD administrators | Your directory administrators | The provider’s administrators | |
sub |
An opaque OneiD user ID | The directory account name, in lower case, without the domain | The provider’s sub, unchanged |
|
idp |
local |
ldap |
oidc |
|
| MFA | OneiD MFA with an authenticator app | OneiD MFA with an authenticator app | The provider’s own MFA | |
amr after sign-in |
["pwd"], or ["pwd","mfa"] with MFA |
["pwd"], or ["pwd","mfa"] with MFA |
["external"] |
Microsoft Entra ID is not available as a sign-in source. Contact us if you need Entra ID.
Read more about each source:
What applications see
Applications use OneiD in the same way whatever the source:
- The same endpoints, flows and token formats.
- The same claims for the same scopes.
name,emailand the other profile claims come from the source. - The same
roleclaim. With OneiD accounts, administrators assign roles in OneiD. With a directory or a provider, roles come from groups (see below).
Three things differ, and your application can read them if it cares:
idp(with theprofilescope) names the source.amrandacrin the ID token say how the user signed in. With an upstream provider,acrisurn:oltin:ac:external; OneiD cannot see whether the provider asked for MFA.- The format of
sub. Treat it as opaque and key users byissandsubtogether. See Scopes, claims and roles.
From groups to roles
With LDAP and Active Directory and with an OpenID Connect provider, OneiD turns the user’s groups into roles at each sign-in. Your OneiD operator configures four rules:
| Rule | What it does |
|---|---|
| Required group | Optional. Users who are not members of this group cannot sign in. |
| Administrators group | Optional. Members get OneiD’s All administrator role, which gives full access to the admin console. |
| Group-to-role mappings | Each listed group becomes the role you name, for example group Order-Viewers becomes role OrderViewer. |
| Pass-through of unmapped groups | Optional. Groups without a mapping become roles named with a prefix you choose, for example ext-Finance. A pass-through role never takes the name of a built-in administrator role. |
Groups that are not mapped and not passed through give no role.
Warning Choose the administrators group with care. Its members can change every setting in OneiD. Use a small, dedicated group.
For an OpenID Connect provider, OneiD reads the groups and role claims the provider sends. For LDAP and Active Directory, OneiD reads the user’s group memberships from the directory.