We’ve added an optional description field, which can also be set programmatically via our OpenTofu/Terraform provider.
We considered automatically fetching the Azure group “display name,” but the current mapping logic is provider-agnostic. Using the description field avoids introducing provider-specific code.
This decision also aligns with how the OIDC standard and Azure implementation work. Azure includes group IDs (UUID format) in the ID token, but not display names. Retrieving display names would require an extra call to the Graph API. In truth, it’s also possible to configure the Azure App to usecloud_displayname instead of group ID in the ID token, but that requires a manual manifest edit and is fragile—display names can change and break mappings.
Amaranth Cherry
•
Jan 21, 2025
A description/notes/label field would already improve the situation quite a bit. But it would be great if it would work similarly how it works in AWS, where it just shows the group/user name.
Log in to comment and vote
Comments2
Brown Mole
Apr 22, 2025
We’ve added an optional description field, which can also be set programmatically via our OpenTofu/Terraform provider.
We considered automatically fetching the Azure group “display name,” but the current mapping logic is provider-agnostic. Using the description field avoids introducing provider-specific code.
This decision also aligns with how the OIDC standard and Azure implementation work. Azure includes group IDs (UUID format) in the ID token, but not display names. Retrieving display names would require an extra call to the Graph API. In truth, it’s also possible to configure the Azure App to use
cloud_displaynameinstead of group ID in the ID token, but that requires a manual manifest edit and is fragile—display names can change and break mappings.Amaranth Cherry
Jan 21, 2025
A description/notes/label field would already improve the situation quite a bit. But it would be great if it would work similarly how it works in AWS, where it just shows the group/user name.