---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Attributes for OIDC

# Identity Provider attributes for OpenID Connect {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Use the Identity Provider attributes that are received from the OpenID Connect (OIDC) from the Identity Provider (IdP) as a filter criteria for authentication.

You can manually create the IdP attributes based on the claims received as part of the ID token.  
Hinweis:  
* Identity Provider filter is available with Zero Trust Access feature. For more information, see [Zero Trust Access (ZTA)](https://servicenow-prod.fluidtopics.net/NxCt_r6~52TWhm29xo89mQ "Zero Trust Access (ZTA) is a security model that assumes that no user or device is trusted by default.").
* IdP attribute filter criteria can be used in [Post-authentication context](https://servicenow-prod.fluidtopics.net/WP0WKYBprUP8geObixGBXw "The Post Authentication policy context defines how and when a policy is enforced during the login process. The policy used in this context executes after your users see a login screen."), [Zero Trust Access (ZTA)](https://servicenow-prod.fluidtopics.net/NxCt_r6~52TWhm29xo89mQ "Zero Trust Access (ZTA) is a security model that assumes that no user or device is trusted by default.") session relegation, and [Multi-factor Authentication context](https://servicenow-prod.fluidtopics.net/J4~REDzsHgZRhtvBg6xTbw "The Multi-factor Authentication (MFA) policy context uses a policy to define how and when MFA is enforced during the login process.").
{#idp-attributes-oidc__ul_i52_t51_kfc}

Start the configuration by adding the IdP attributes by selecting New from the Identity Provider Attributes section and use those attributes for Adaptive Authentication by setting it to
<kbd class="ph userinput">true</kbd>.

The RiskFactor defined in the OIDC configuration in the Identity Provider Attributes is from the ID token claims. This value can be an existing claim or custom claim as configured in the IdP side. Use this claim
in various authentication context to customize and control the log in behavior of the user.

The Identity Provider Attributes are displayed with the following details:
{#idp-attributes-oidc__table_tz3_bww_vnb__entry__2}

| Field | Description |
|-|-|
| Name | Attribute name that is provided by the Identity Provider. |
| Display Name | Display Name is the detailed name that is used for the filter criteria. Hinweis: You can provide a readable name as a Display Name, in some cases the Display Name provided by the Identity Providers are lengthy and not readable. |
| Default Value | Default value is used for filter criteria evaluation in case the attribute is missing in the SAML response. |
| Use in Adaptive Authentication | Option to use the Attribute in the Adaptive Authentication. |
[Tabelle : 1. Location Filter Criteria form]

{#idp-attributes-oidc__table_tz3_bww_vnb}  
Hinweis:  
Attributes that are populated from Azure IdP have name and display name limited to characters, due to the name length of the attribute.

You can also add new attributes by selecting New in the Identity Providers Attributes section.

If the Use in Adaptive Authentication is set to true, then the selected attribute is added as filter criteria in the Generic Filter Criteria. For example, risk_score set to <kbd class="ph userinput">true</kbd>. The
Generic Filter Criteria page has a new filter created.

