Loading

ADFS OIDC Integration – Authentication-Server RS256 Validation Errors and Missing User Profile Attributes

Julkaisupäivä: Jun 23, 2026
Kuvaus

Affected Products
MuleSoft Private Cloud Edition (PCE) 4.1.2, 4.1.3, and 4.2.0
Microsoft ADFS configured as an OIDC Identity Provider using RS256-signed ID tokens
Note: Additional validation is in progress to determine whether this behavior also affects other MuleSoft control plane deployments.

Impact
Customers using ADFS as an OIDC Identity Provider may be unable to populate user profile attributes through the OIDC authentication flow.

Recommendation
For customers using Microsoft ADFS, Engineering recommends using SAML 2.0 instead of OIDC for MuleSoft authentication integrations. SAML supports attribute mapping and does not have this limitation.


How to Determine Whether You Are Affected
You may be affected if all of the following apply:
MuleSoft PCE is configured to use Microsoft ADFS as an OIDC Identity Provider.
ADFS is issuing RS256-signed ID tokens.
Authentication-server logs contain JsonWebTokenError: invalid algorithm messages.
User profile attributes such as given_name, family_name, and email remain blank after successful login.

Ratkaisu

Issue 1: RS256 Token Validation Errors

This issue has been addressed in authentication-server version 1.2.703 and later, which is included in PCE 4.2.1.
Customers experiencing this behavior should upgrade to PCE 4.2.1 or later.

 

Issue 2: User Profile Attributes Not Populated
This behavior is expected with the current implementation and is not caused by an ADFS misconfiguration.

Knowledge-artikkelin numero

005387525

 
Ladataan
Salesforce Help | Article