@@ -44,6 +44,7 @@ The following claims are in the restricted claim set for a JWT.
44
44
- ` acr `
45
45
- ` acrs `
46
46
- ` actor `
47
+ - ` actortoken `
47
48
- ` ageGroup `
48
49
- ` aio `
49
50
- ` altsecid `
@@ -55,41 +56,68 @@ The following claims are in the restricted claim set for a JWT.
55
56
- ` appctxsender `
56
57
- ` appid `
57
58
- ` appidacr `
59
+ - ` assertion `
58
60
- ` at_hash `
61
+ - ` aud `
62
+ - ` auth_data `
59
63
- ` auth_time `
64
+ - ` authorization_code `
60
65
- ` azp `
61
66
- ` azpacr `
67
+ - ` bk_claim `
68
+ - ` bk_enclave `
69
+ - ` bk_pub `
70
+ - ` brk_client_id `
71
+ - ` brk_redirect_uri `
62
72
- ` c_hash `
63
73
- ` ca_enf `
64
74
- ` ca_policy_result `
65
- - ` capolids_latebind `
66
75
- ` capolids `
76
+ - ` capolids_latebind `
67
77
- ` cc `
78
+ - ` cert_token_use `
79
+ - ` child_client_id `
80
+ - ` child_redirect_uri `
81
+ - ` client_id `
82
+ - ` client_ip `
83
+ - ` cloud_graph_host_name `
84
+ - ` cloud_instance_host_name `
85
+ - ` cloud_instance_name `
86
+ - ` CloudAssignedMdmId `
68
87
- ` cnf `
69
88
- ` code `
70
- - ` controls_auds `
71
89
- ` controls `
90
+ - ` controls_auds `
72
91
- ` credential_keys `
92
+ - ` csr `
93
+ - ` csr_type `
73
94
- ` ctry `
74
95
- ` deviceid `
96
+ - ` dns_names `
75
97
- ` domain_dns_name `
76
98
- ` domain_netbios_name `
77
99
- ` e_exp `
78
100
- ` email `
79
101
- ` endpoint `
80
102
- ` enfpolids `
103
+ - ` exp `
81
104
- ` expires_on `
105
+ - ` extn. as prefix `
82
106
- ` fido_auth_data `
83
- - ` fwd_appidacr `
107
+ - ` fido_ver `
84
108
- ` fwd `
109
+ - ` fwd_appidacr `
110
+ - ` grant_type `
85
111
- ` graph `
86
112
- ` group_sids `
87
113
- ` groups `
88
114
- ` hasgroups `
115
+ - ` hash_alg `
89
116
- ` haswids `
90
117
- ` home_oid `
91
118
- ` home_puid `
92
119
- ` home_tid `
120
+ - ` iat `
93
121
- ` identityprovider `
94
122
- ` idp `
95
123
- ` idtyp `
@@ -98,16 +126,23 @@ The following claims are in the restricted claim set for a JWT.
98
126
- ` inviteTicket `
99
127
- ` ipaddr `
100
128
- ` isbrowserhostedapp `
129
+ - ` iss `
101
130
- ` isViral `
131
+ - ` jwk `
132
+ - ` key_id `
133
+ - ` key_type `
102
134
- ` login_hint `
103
135
- ` mam_compliance_url `
104
136
- ` mam_enrollment_url `
105
137
- ` mam_terms_of_use_url `
106
138
- ` mdm_compliance_url `
107
139
- ` mdm_enrollment_url `
108
140
- ` mdm_terms_of_use_url `
141
+ - ` msgraph_host `
109
142
- ` msproxy `
110
143
- ` nameid `
144
+ - ` nbf `
145
+ - ` netbios_name `
111
146
- ` nickname `
112
147
- ` nonce `
113
148
- ` oid `
@@ -116,25 +151,35 @@ The following claims are in the restricted claim set for a JWT.
116
151
- ` onprem_sid `
117
152
- ` openid2_id `
118
153
- ` origin_header `
154
+ - ` password `
119
155
- ` platf `
120
156
- ` polids `
121
157
- ` pop_jwk `
122
158
- ` preferred_username `
159
+ - ` previous_refresh_token `
123
160
- ` primary_sid `
124
161
- ` prov_data `
125
162
- ` puid `
126
163
- ` pwd_exp `
127
164
- ` pwd_url `
128
165
- ` rdp_bt `
166
+ - ` redirect_uri `
167
+ - ` refresh_token `
129
168
- ` refresh_token_issued_on `
130
169
- ` refreshtoken `
170
+ - ` request_nonce `
171
+ - ` resource `
131
172
- ` rh `
173
+ - ` role `
132
174
- ` roles `
175
+ - ` rp_id `
133
176
- ` rt_type `
177
+ - ` scope `
134
178
- ` scp `
135
179
- ` secaud `
136
180
- ` sid `
137
181
- ` sid `
182
+ - ` signature `
138
183
- ` signin_state `
139
184
- ` source_anchor `
140
185
- ` src1 `
@@ -145,6 +190,7 @@ The following claims are in the restricted claim set for a JWT.
145
190
- ` tbidv2 `
146
191
- ` tenant_ctry `
147
192
- ` tenant_display_name `
193
+ - ` tenant_id `
148
194
- ` tenant_region_scope `
149
195
- ` tenant_region_sub_scope `
150
196
- ` thumbnail_photo `
@@ -154,60 +200,88 @@ The following claims are in the restricted claim set for a JWT.
154
200
- ` ttr `
155
201
- ` unique_name `
156
202
- ` upn `
203
+ - ` user_agent `
157
204
- ` user_setting_sync_url `
205
+ - ` username `
158
206
- ` uti `
159
207
- ` ver `
160
208
- ` verified_primary_email `
161
209
- ` verified_secondary_email `
162
210
- ` vnet `
211
+ - ` vsm_binding_key `
163
212
- ` wamcompat_client_info `
164
213
- ` wamcompat_id_token `
165
214
- ` wamcompat_scopes `
166
215
- ` wids `
216
+ - ` win_ver `
217
+ - ` x5c_ca `
167
218
- ` xcb2b_rclient `
168
219
- ` xcb2b_rcloud `
169
220
- ` xcb2b_rtenant `
170
221
- ` ztdid `
171
222
223
+
172
224
> [ !NOTE]
173
225
> Any claim starting with ` xms_ ` is restricted.
174
226
175
227
### SAML restricted claim set
176
228
177
229
The following table lists the SAML claims that are in the restricted claim set.
178
230
179
- | Claim type (URI) |
180
- | ----- |
181
- | ` http://schemas.microsoft.com/2012/01/devicecontext/claims/ismanaged ` |
182
- | ` http://schemas.microsoft.com/2014/02/devicecontext/claims/isknown ` |
183
- | ` http://schemas.microsoft.com/2014/03/psso ` |
184
- | ` http://schemas.microsoft.com/2014/09/devicecontext/claims/iscompliant ` |
185
- | ` http://schemas.microsoft.com/claims/authnmethodsreferences ` |
186
- | ` http://schemas.microsoft.com/claims/groups.link ` |
187
- | ` http://schemas.microsoft.com/identity/claims/accesstoken ` |
188
- | ` http://schemas.microsoft.com/identity/claims/acct ` |
189
- | ` http://schemas.microsoft.com/identity/claims/agegroup ` |
190
- | ` http://schemas.microsoft.com/identity/claims/aio ` |
191
- | ` http://schemas.microsoft.com/identity/claims/identityprovider ` |
192
- | ` http://schemas.microsoft.com/identity/claims/objectidentifier ` |
193
- | ` http://schemas.microsoft.com/identity/claims/openid2_id ` |
194
- | ` http://schemas.microsoft.com/identity/claims/puid ` |
195
- | ` http://schemas.microsoft.com/identity/claims/tenantid ` |
196
- | ` http://schemas.microsoft.com/identity/claims/xms_et ` |
197
- | ` http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant ` |
198
- | ` http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod ` |
199
- | ` http://schemas.microsoft.com/ws/2008/06/identity/claims/expiration ` |
200
- | ` http://schemas.microsoft.com/ws/2008/06/identity/claims/groups ` |
201
- | ` http://schemas.microsoft.com/ws/2008/06/identity/claims/role ` |
202
- | ` http://schemas.microsoft.com/ws/2008/06/identity/claims/wids ` |
203
- | ` http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier ` |
204
- | ` http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname ` |
205
- | ` http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid ` |
206
- | ` http://schemas.microsoft.com/ws/2008/06/identity/claims/primarygroupsid ` |
207
- | ` http://schemas.xmlsoap.org/ws/2005/05/identity/claims/sid ` |
208
- | ` http://schemas.xmlsoap.org/ws/2005/05/identity/claims/x500distinguishedname ` |
209
- | ` http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn ` |
210
- | ` http://schemas.microsoft.com/ws/2008/06/identity/claims/role ` |
231
+ Restricted Claim type (URI):
232
+ - ` http://schemas.microsoft.com/2012/01/devicecontext/claims/ismanaged `
233
+ - ` http://schemas.microsoft.com/2014/02/devicecontext/claims/isknown `
234
+ - ` http://schemas.microsoft.com/2014/03/psso `
235
+ - ` http://schemas.microsoft.com/2014/09/devicecontext/claims/iscompliant `
236
+ - ` http://schemas.microsoft.com/claims/authnmethodsreferences `
237
+ - ` http://schemas.microsoft.com/claims/groups.link `
238
+ - ` http://schemas.microsoft.com/identity/claims/accesstoken `
239
+ - ` http://schemas.microsoft.com/identity/claims/acct `
240
+ - ` http://schemas.microsoft.com/identity/claims/agegroup `
241
+ - ` http://schemas.microsoft.com/identity/claims/aio `
242
+ - ` http://schemas.microsoft.com/identity/claims/identityprovider `
243
+ - ` http://schemas.microsoft.com/identity/claims/objectidentifier `
244
+ - ` http://schemas.microsoft.com/identity/claims/openid2_id `
245
+ - ` http://schemas.microsoft.com/identity/claims/puid `
246
+ - ` http://schemas.microsoft.com/identity/claims/scope `
247
+ - ` http://schemas.microsoft.com/identity/claims/tenantid `
248
+ - ` http://schemas.microsoft.com/identity/claims/xms_et `
249
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant `
250
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod `
251
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/confirmationkey `
252
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarygroupsid `
253
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarysid `
254
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlywindowsdevicegroup `
255
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/expiration `
256
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/expired `
257
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/groups `
258
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid `
259
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/ispersistent `
260
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/primarygroupsid `
261
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid `
262
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/role `
263
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/role `
264
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/samlissuername `
265
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/wids `
266
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname `
267
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsdeviceclaim `
268
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsdevicegroup `
269
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsfqbnversion `
270
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/windowssubauthority `
271
+ - ` http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsuserclaim `
272
+ - ` http://schemas.xmlsoap.org/ws/2005/05/identity/claims/authentication `
273
+ - ` http://schemas.xmlsoap.org/ws/2005/05/identity/claims/authorizationdecision `
274
+ - ` http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysid `
275
+ - ` http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress `
276
+ - ` http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name `
277
+ - ` http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier `
278
+ - ` http://schemas.xmlsoap.org/ws/2005/05/identity/claims/privatepersonalidentifier `
279
+ - ` http://schemas.xmlsoap.org/ws/2005/05/identity/claims/sid `
280
+ - ` http://schemas.xmlsoap.org/ws/2005/05/identity/claims/spn `
281
+ - ` http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn `
282
+ - ` http://schemas.xmlsoap.org/ws/2005/05/identity/claims/x500distinguishedname `
283
+ - ` http://schemas.xmlsoap.org/ws/2009/09/identity/claims/actor `
284
+
211
285
212
286
These claims are restricted by default, but aren't restricted if you [ set the AcceptMappedClaims property] ( saml-claims-customization.md ) to ` true ` in your app manifest * or* have a [ custom signing key] ( saml-claims-customization.md ) :
213
287
0 commit comments