Claim Settings and Usage on Microsoft Entra ID and NCC
Zyxel Employee
Introduction
Claims are additional user attributes included in each OIDC authentication response, based on the authenticated user’s identity (e.g., country, group membership). These attributes can be leveraged by relying parties (e.g., access points, firewalls) to enable user awareness and enforce user privilege policies.
To ensure that claims are correctly delivered from the Identity Provider (IdP) through the Nebula Identity Federation Service (IFS) to the target devices—and subsequently used for policy enforcement—configuration is required in the following three areas:
- Configure claims to be included in the tokens on Microsoft Entra ID
- Configure which claims IFS forwards to relying parties
- Configure user privilege policies based on claims on NCC
Step 1: Configure Claims to Be Included in Tokens on Microsoft Entra ID
- Sign in to the Microsoft Entra Admin Center.
- Navigate to App registrations > Owned applications.
- Select the application associated with the Nebula identity federation service.
- In the left-hand menu, navigate to Manage > Token configuration.
- Use the top menu to:
- Click Add optional claim or Add group claims
- Select ID as the token type
- Choose the claims you want to include
- After configuration, record the name of Claim from the resulting list.
Step 2: Configure which claims IFS forwards to relying parties
- Sign in to NCC.
- Navigate to Organization-wide > Nebula identity federation service > Identity provider.
- Locate the relevant Identity Provider and click Edit.
- In the Additional claims field, enter the claim names recorded in Step 1.
Note: The claim names entered here must exactly match those configured in Microsoft Entra ID.
Step 3: Configure user privilege policies based on claims on NCC
- Navigate to Org-wide > Nebula identity federation service > User Privilege.
- Click Add, and in the dialog:
- Select the corresponding Identity Provider
- Set Principal type to “Group by claims”
- Click Add to define claim conditions:
- In the Name field, enter the claim name
- In the Value field, specify the matching value
- Repeat as needed to add multiple claims
Note: When multiple claims are configured, users must match all claim names to be selected. Within each claim, matching any listed value is sufficient.
Ensure the value of “groups” claim matches the “Object Id” IN Groups page. (since the token property setting is set with "Group ID" in token configuration)
- Click Next.
- Under Select service, define which services the matched users are allowed to access.
- Click Next.
- Review the configuration in the summary page, then click Create to complete the setup.
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 234 Nebula Ideas
- 6.7K Security
- 695 USG FLEX H Series
- 366 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.4K Wireless
- 56 Wireless Ideas
- 7.1K Consumer Product
- 312 Service & License
- 510 News and Release
- 97 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.1K FAQ
- 34 Documents
- 89 About Community
- 114 Security Highlight






