We need Northapss to be able to parse the group id information in the JWT
"We want Northpass to be able to support parsing a custom claim containing the Northpass group ID from the JWT used in SSO-based authentication. Mark43 (perhaps the TSE team) would be responsible for ensuring that new & existing SSO identity provider configurations (e.g., Azure AD) contain a custom property with the appropriate Northpass group ID for that customer."
"We would need to have a separate method for customers who have no external identity provider configured (i.e., customers who authenticate with Northpass via their Mark43 application credentials). We currently have no automated way to link these users (whole departments, really) to a given Northpass group automatically"
* OAuth 2.0 would work best for passing groups and IDs
* We built out an Okta integration, it uses our default SAML
* Okta provides group provisioning
* Generically availble with anyone who uses OAuth 2.0
* For non-external IPs, there needs to be a single identity provider, such as Mark43
* Charlie Question: Is there a centralized place where all the information lives? With minor dev resources, we could set up API calls to constantly update their Northpass people and accounts
* Whenever something is changed in their system, auto updated (i.e. someone changes departments)
Them setting up as an IDP is not out of the realm of possibilities, but they would have to have a discussion. They generally only handle the handshake one way, so this would be two way.
They don't know if setting up an IDP is the "technological direction" they want to go in.