OIDC Setup on FLEX H
Ally Member
I'm trying to configure OIDC on FLEX H with MS Entra. Tried to follow this guide:
SSLVPN authentication with Microsoft Entra ID — Zyxel Community
But when I press the test button I get this error:
Invalid OIDC authorization_endpoint.
Error Code: (10016)cmd aaa validate-oidc-profile MS365
Normally my Issuer URL, Client ID and secret are identically, but I wonder if it has something to do with the certificate? The guide only mentions potential problems when trying to connect the client..? I have a wildcard certificate (.pfx) on my domain name, but can't import it on the FLEX because it's not compatible…
ANyhow what also is different then in the guide, I'm not using for example zyxeltest.com but firewall.zyxeltest.com because I'm still in testfase and using an onmicrosoft domain name. Bit stuck here with the not saying that much errormessage…
Edit: looking a bit further, I also don't see any sign in tries on my Entra portal
Ok so now it seems like my Issuer URL had a "/" too much. Moving on now I get
OIDC Authentication TestAn error occurred during OIDC processing:
Claim 'email' not found in ID Token claims
But I have allowed this all:
| Delegated | View users' email address | No | ||
|---|---|---|---|---|---|
offline_access | Delegated | Maintain access to data you have given it access to | No | ||
openid | Delegated | Sign users in | No | ||
profile | Delegated | View users' basic profile | No | ||
User.Read | Delegated | Sign in and read user profile | No |
Also added:
All Replies
-
Hi @nielsscheldeman,
Regarding the error "Claim 'email' not found in ID Token claims", this typically means the email attribute is not populated for that user in Entra ID.
We would suggest first verifying the email property of the user account in Entra ID and make sure it is properly filled in.
Additionally, if you prefer, you can also configure the OIDC profile on the FLEX H to use "preferred_username" as the username claim instead, which is already included in the default "profile" scope and requires no extra setup on the Entra ID side.
Zyxel Tina
0
Categories
- All Categories
- 442 Beta Program
- 3K Nebula
- 223 Nebula Ideas
- 129 Nebula Status and Incidents
- 6.6K Security
- 638 USG FLEX H Series
- 357 Security Ideas
- 1.8K Switch
- 86 Switch Ideas
- 1.4K Wireless
- 54 Wireless Ideas
- 7K Consumer Product
- 301 Service & License
- 494 News and Release
- 93 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.8K FAQ
- 34 Documents
- 88 About Community
- 109 Security Highlight

Zyxel Employee

