Include in job title in jwt-token from AAD

Viewed 110

I’m in the middle of migrating the sign in solution of an React/Dotnet application to an AAD based signing approach. At different parts of the react part of the application I need to know what role/job title the current user holds. I could get this information from a call using the Graph Api utilising the v1.0/me endpoint (the information is in the “jobTitle” field). Either calling the API once and storing the information or calling it when needed and using it straight away. My question is the following: is there any way to instead pass along this jobTitle information in the jwt token? In my world that would be a more elegant solution.

I have gathered that you can add roles to the JWT token but as I far as I’ve understood it these roles refers to application specific roles and not general roles for the tenant.

1 Answers

You can add jobTitle in the ID token using “Claim Mapping Policy”. This can be configured using PowerShell only.

Claims can be customized for a specific application so policy can only be assigned to service principal objects.

Below are the steps to create policy and assign it to service principal.

1.First, you need to connect to Azure AD to sign to your tenant.

Connect-AzureAD

2.Use below cmdlet to create New Azure AD Policy to add Basic Claims "jobTitle".

New-AzureADPolicy -Definition @('{"ClaimsMappingPolicy": {"Version": 1,"IncludeBasicClaimSet": "true","ClaimsSchema":[
{"Source": "user","ID": "jobTitle","JwtClaimType": "jobTitle"}]}}') -DisplayName "BasicClaimJob-title" -Type "ClaimsMappingPolicy"

3.Run the following command to see your newly created policy and copy the policy ObjectId,

Get-AzureADPolicy

4.Then,assign the policy to your service principal. You can get the ObjectId of your service principal from Enterprise applications blade

Add-AzureADServicePrincipalPolicy -Id <ObjectId of the ServicePrincipal> -RefObjectId <ObjectId of the Policy>

Once policy has successfully assigned, then enable the AcceptMappedClaims to true in the App Manifest

Now you should see Basic Claims "jobTitle" appears in ID_Token (JWT token

JWT Token

Related