Microsoft has implemented a new feature on Azure AD where it is possible to select more than one value for GroupMemberShipClaims@AADApplication.
In Identity Manager, this has a limited value defined, which is ok when only one value is selected. However, if more than one is selected, there is a comma-separated value and the below error can occur.
[810457] Error saving AADApplication [application_name]
[810306] Error running 'CheckValues' in logic module 'VI.DB.Entities.ValueFormatEntityLogic'.
[810149] Azure Active Directory app registrations: Value 'SecurityGroup, ApplicationGroup' is not valid for
field 'Group membership claim' (Valid values: None, All, SecurityGroup, DirectoryRole, ApplicationGroup).
This is due to a new feature in Azure.
WORKAROUND: As Identity Manager only reads this information, it's possible to delete the mapping or delete the limited value for the column.
STATUS: Enhancement request 456597 has been submitted to Development for consideration in a future release of Identity Manager.
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center