Skip to Main Content
Interweave Portal - Ideas

This portal provides an open platform for user feedback and product change requests. Anyone can add an idea and remain as a Guest, but please consider signing up so that others can see who has created the ideas!

Note: this is a public facing web portal, any text here can be viewed by anyone over the internet, so please consider carefully the content you wish to share and please do not post anything of a sensitive nature.

Status Needs review
Created by Stephen Handley
Created on Aug 18, 2026

NOTTSCR - Map email claim in OIDC/Entra login to Portal User Email

As identified on https://interweavedigital.atlassian.net/browse/ICR-6417, the “email field is not currently mapped from the OIDC token to the interface in User Administration on the Admin screen.“.

With the OIDC Context Launch (and Entra SSO), portal users are creates with id that matched the ‘sub’ in the OIDC token, The ‘sub’ value is generated by Google Identity Services, and is not something that would be recognised by the DataConsumer (i.e. those id’s do not exist in any of their systems).

This will makes it very difficult to reconcile portal users/usage with users on the local clinical systems. The only option is the use given/family names, which are neither unique or immutable.

Mapping the email claim from the local OIDC token to the portal user, would provide a robust mechanism to join portal audit logs to local user records.

As a As a Data Provider
I would like a unique identifier against each OIDC created user account, that I can use to match to users in the local AD tenancy
So that I can join portal usage to local user account
  • Attach files