<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure OpenID Connect logins in ArcGIS Enterprise Portal Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1067075#M11108</link>
    <description>&lt;P&gt;I do not think that is the case.&lt;/P&gt;&lt;P&gt;In the OIDC configuration we have "openid email profile" and I can confirm that the client in the Identity Server is setup in the way to allow those scopes.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jun 2021 19:41:58 GMT</pubDate>
    <dc:creator>RomanBoros</dc:creator>
    <dc:date>2021-06-10T19:41:58Z</dc:date>
    <item>
      <title>Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1065554#M11070</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are trying to setup an OpenID Connection to our ArcGIS Online.&lt;/P&gt;&lt;P&gt;All the necessary configurations were done on our Identity Provider and in the ArcGIS Online admin panel.&lt;/P&gt;&lt;P&gt;The button appeared on the login screen and after pressing we are redirected to the Identity Provider. After successful authentication the server redirects back to the portal and an error message is displayed.&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Did not receive 'user profile' parameter from the provider.&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RomanBoros_0-1623056922667.png" style="width: 400px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/15301iB8614B8ACACD60F4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RomanBoros_0-1623056922667.png" alt="RomanBoros_0-1623056922667.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Can you provide more details what might be the problem?&lt;/P&gt;&lt;P&gt;This is the response format that the identity provider returns from the user info endpoint&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RomanBoros_1-1623057291228.png" style="width: 400px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/15302i3FAB7DC62BA919F2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RomanBoros_1-1623057291228.png" alt="RomanBoros_1-1623057291228.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As Identity Provider we are using Identity Server 4.&lt;/P&gt;&lt;P&gt;The grant type for this client is&amp;nbsp;&lt;STRONG&gt;authorization_code&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;We tried looking into documentation, but there is nothing about this error.&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 09:38:03 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1065554#M11070</guid>
      <dc:creator>RomanBoros</dc:creator>
      <dc:date>2021-06-07T09:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1065863#M11076</link>
      <description>&lt;P&gt;I'm facing the same issue using the Keycloak IDM, we had previously used Keycloak's SAML integration but would like to transition to OIDC to align with other applications in our environment&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 05:29:12 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1065863#M11076</guid>
      <dc:creator>TomRussell1</dc:creator>
      <dc:date>2021-06-08T05:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1065889#M11078</link>
      <description>&lt;P&gt;Unfortunately, SAML is not an option for us at the moment.&lt;/P&gt;&lt;P&gt;Our guess is they are expecting some non-standard parameter to be returned in the token.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 08:41:30 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1065889#M11078</guid>
      <dc:creator>RomanBoros</dc:creator>
      <dc:date>2021-06-08T08:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1066947#M11104</link>
      <description>&lt;P&gt;That error message typically means that the scopes are not being released to the service provider. Depending on whether you've specified those scopes in the OIDC configuration for ArcGIS Online/Portal for ArcGIS, you may need to remove them and potentially add other scopes if your provider is not set to allow the listed scopes to the service provider for the registered application.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 15:38:40 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1066947#M11104</guid>
      <dc:creator>ChristopherPawlyszyn</dc:creator>
      <dc:date>2021-06-10T15:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1067075#M11108</link>
      <description>&lt;P&gt;I do not think that is the case.&lt;/P&gt;&lt;P&gt;In the OIDC configuration we have "openid email profile" and I can confirm that the client in the Identity Server is setup in the way to allow those scopes.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 19:41:58 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1067075#M11108</guid>
      <dc:creator>RomanBoros</dc:creator>
      <dc:date>2021-06-10T19:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1067305#M11114</link>
      <description>&lt;P&gt;Another possibility may be that you haven't selected the option to include the access token in the header of the authentication request. I had the same issue on an ADFS 4.0 OpenID Connect configuration I was working on earlier in the week.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 11:48:02 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1067305#M11114</guid>
      <dc:creator>ChristopherPawlyszyn</dc:creator>
      <dc:date>2021-06-11T11:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1067320#M11115</link>
      <description>&lt;P&gt;Should I look for that option in the&amp;nbsp;&lt;SPAN&gt;ArcGIS Online/Portal or on the Identity Server?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;On the server the closes thing there is this parameter and that is set to true.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RomanBoros_0-1623414699518.png" style="width: 400px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/15750iB86ABEC6B19AB54F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RomanBoros_0-1623414699518.png" alt="RomanBoros_0-1623414699518.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 12:31:59 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1067320#M11115</guid>
      <dc:creator>RomanBoros</dc:creator>
      <dc:date>2021-06-11T12:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1067834#M11119</link>
      <description>&lt;P&gt;After another attempt we found that parameter.&lt;/P&gt;&lt;P&gt;Setting that to true was the solution.&lt;/P&gt;&lt;P&gt;For anyone still wondering, you can find that at the bottom, when you try to edit the configuration.&lt;/P&gt;&lt;P&gt;Organization -&amp;gt; Settings -&amp;gt; Security -&amp;gt;&amp;nbsp;Logins-&amp;gt;&amp;nbsp;Configure login&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RomanBoros_0-1623668238436.png" style="width: 400px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/15865iFC4C1429ABC24ED3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RomanBoros_0-1623668238436.png" alt="RomanBoros_0-1623668238436.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 10:58:42 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1067834#M11119</guid>
      <dc:creator>RomanBoros</dc:creator>
      <dc:date>2021-06-14T10:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1117701#M11743</link>
      <description>&lt;P&gt;I'm playing around with IdentityServer4 as an OpenID Connect source, and I am getting the same "user profile" error, although it works fine for a MVC client that uses the same parameters as ArcGIS Online.&amp;nbsp; Next I created a custom IProfileService implementation to see if it's actually being called, and again it works fine for the MVC client, but with AGOL only IsActiveAsync is being called (and returning true); GetProfileDataAsync is never called.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 15:02:10 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1117701#M11743</guid>
      <dc:creator>MarkCederholm</dc:creator>
      <dc:date>2021-11-17T15:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1153111#M12097</link>
      <description>&lt;P&gt;Hi Mark&lt;/P&gt;&lt;P&gt;Did you find a solution for the OpenID problem - I have the exact same issue using KeyCloak!&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 22:11:05 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1153111#M12097</guid>
      <dc:creator>pocalipse</dc:creator>
      <dc:date>2022-03-11T22:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1159782#M12141</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I understand, you were able to use IdentityServer4 as an OpenID Connect IDP and connect ArcGIS Online with your IDP. By checking the "Send access token in header" seemed to help you out. Unfortunately, this approach does not solve this issue for my setup. I have used the IdentityServer4 QuickStart sample and just for now is using the in-memory user store. Trying to check the mentioned checkbox, making sure that the claims is sent with the access token&amp;nbsp; setting the&amp;nbsp; AlwaysIncludeUserClaimsInIdToken = true, for the client setup does not help. I still get the message "&lt;SPAN&gt;Did not receive 'user profile' parameter from the provider."&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have successfully managed to set up Okta as an OpenID Connect IDP. It does not seem to me that userinfo endpoint is ever called from ESRI, even when the configuration does not have specified&amp;nbsp;the JWKS URL and added the usserinfo URL.&lt;BR /&gt;&lt;BR /&gt;What else have you configured with your IDP,&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/397621"&gt;@RomanBoros&lt;/a&gt;?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 08:18:21 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1159782#M12141</guid>
      <dc:creator>HaraldLund</dc:creator>
      <dc:date>2022-03-31T08:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1159785#M12142</link>
      <description>&lt;P&gt;This will probably not help you directly, but I have a customer who were able to setup KeyCloak with ArcGIS Portal 10.9, but I do not have any details on the configuration. But when I was setting up the Okta setup, I also struggled with this error. I ended up with not checking the&amp;nbsp;&lt;SPAN&gt;"Send access token in header", setting the&amp;nbsp; UserInfo URL to empty but filling out the JWKS url. With the Okta configuration I uses Client Credential and&amp;nbsp;Authorization Code. I also had to make sure the Claims where mapping correctly. I also have a sub claim added.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 08:28:45 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1159785#M12142</guid>
      <dc:creator>HaraldLund</dc:creator>
      <dc:date>2022-03-31T08:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1159805#M12143</link>
      <description>&lt;P&gt;I think my problem is exactly the mapping - did you manage to figure out what claims ArcGIS is expecting?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 10:10:26 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1159805#M12143</guid>
      <dc:creator>pocalipse</dc:creator>
      <dc:date>2022-03-31T10:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1161061#M12154</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are the claims you need:&lt;/P&gt;&lt;P&gt;name&lt;BR /&gt;nickname&lt;BR /&gt;given_name&lt;BR /&gt;middle_name&lt;BR /&gt;family_name&lt;BR /&gt;email&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 09:04:09 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1161061#M12154</guid>
      <dc:creator>HaraldLund</dc:creator>
      <dc:date>2022-04-05T09:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1163498#M12188</link>
      <description>&lt;P&gt;Did you get this working? I am also using IdentityServer4 and I see the same "Did not receive 'user profile' parameter from the provider." error, though I have tried all the suggestions in this thread. I see that later you give a list of claims that ArcGIS expects, but, as &lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/1465"&gt;@MarkCederholm&lt;/a&gt;&amp;nbsp;says, GetProfileDataAsync is never called, so I'm not sure that the claims are the problem.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 14:51:18 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1163498#M12188</guid>
      <dc:creator>JoshuaAbbott</dc:creator>
      <dc:date>2022-04-12T14:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1163510#M12189</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/578095"&gt;@JoshuaAbbott&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Unfortunately we weren't able to get this to work with ArcGIS Portal 10.9.1. But using the exact same IdentityServer application with ArcGIS Online that also supports PKCE flow, it works. So I suspect that there is a problem with 10.9.1. It would be nice if Esri would be able to support the latest security demands also with ArcGIS Portal 10.9.x and that there were possibilities to manage some mapping and handling of custom scopes and claims. With more and more demands to be able to support the latest secure architecture using OpenID Connect I think it is essential that Portal would support this. I also missing how samples and documentation of how the mapping is done now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;One other thing I'm unsure of is if we would be able to authenticate an user with the federated IDP, and use the token to access the items the user is authorised to use. Or do we always have to trigger the authentication by accessing Portal first and to be redirected to the IDP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 15:24:43 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1163510#M12189</guid>
      <dc:creator>HaraldLund</dc:creator>
      <dc:date>2022-04-12T15:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1163592#M12190</link>
      <description>&lt;P&gt;Many thanks for the response. I agree that they should include support in 10.9.1 since PKCE is now the industry standard. I am using a version of ArcGIS that supports PKCE and I am still seeing that error, that I hope you might be able to shed some light on. Below is my client setup with sensitive info redacted. Also, when configuring the Login on ArcGIS, it asks for a "Provider Issuer ID" is this just the domain of the identity provider? For example I just have "&lt;A href="https://localhost:44360" target="_blank"&gt;https://localhost:44360&lt;/A&gt;". Again, thanks for your collaboration.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="csharp"&gt;{
   ClientId = "arcgis-client",
   ClientName = "API Client",
   AllowedGrantTypes = GrantTypes.Code,
   RequirePkce = true,
   RequireClientSecret = false, // obsolete with PKCE
   AllowOfflineAccess = true,
   AlwaysIncludeUserClaimsInIdToken = false,
   RedirectUris = new string[] { "REDACTED" },
   PostLogoutRedirectUris = new string[] { "REDACTED" },
   ClientSecrets = new Secret[] { new Secret("REDACTED".Sha256()) }, // Not used, but ArcGIS asks for it
   AllowedScopes = new string[]
   {
      IdentityServerConstants.StandardScopes.OpenId,
      IdentityServerConstants.StandardScopes.Profile,
      IdentityServerConstants.StandardScopes.Email
   }
}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 17:34:43 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1163592#M12190</guid>
      <dc:creator>JoshuaAbbott</dc:creator>
      <dc:date>2022-04-12T17:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1163606#M12191</link>
      <description>&lt;P&gt;As issuer I also have used the same as you. Have you tried to set this to true?&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;AlwaysIncludeUserClaimsInIdToken = true&lt;/PRE&gt;&lt;P&gt;If you're using a version supporting PKCE, isn't that ArcGIS Online?&lt;/P&gt;&lt;P&gt;I see you also use a local host for testing. Just wondering if there is an issue if your server isn't reachable for the ArcGIS installation,&amp;nbsp; but the communication should be with in the browser session, if I have understood this correctly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 18:37:04 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1163606#M12191</guid>
      <dc:creator>HaraldLund</dc:creator>
      <dc:date>2022-04-12T18:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1163935#M12198</link>
      <description>&lt;P&gt;Yes, I'm using ArcGIS Online with PKCE support. I have "Include Token in Header" enabled and I have tried&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="c"&gt;AlwaysIncludeUserClaimsInIdToken = true&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;still without success. I do not think the issue is the communication to localhost, since it does redirect to the sign in page of my Identity Provider, the user is authenticated and then returned to ArcGIS with the access token. It is then that ArcGIS shows that error about "no user profile parameter".&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update:&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/439290"&gt;@HaraldLund&lt;/a&gt;&amp;nbsp;I did have to have it running at a publicly accessible URL, so after hosting it on IIS everything worked out fine.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 16:07:46 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1163935#M12198</guid>
      <dc:creator>JoshuaAbbott</dc:creator>
      <dc:date>2022-04-13T16:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: Configure OpenID Connect logins</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1165581#M12215</link>
      <description>&lt;P&gt;Great you managed to solve it, that was my next step for my testing as well. Was also looking into Keycloak but ended up with same error. I will go back to testing with a accessible URL with IdentityServer, even though using KeyCloak may reduce the development time.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 11:49:33 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/configure-openid-connect-logins/m-p/1165581#M12215</guid>
      <dc:creator>HaraldLund</dc:creator>
      <dc:date>2022-04-19T11:49:33Z</dc:date>
    </item>
  </channel>
</rss>

