# Get more UserInfos after Openid Login

**URL:** <https://discuss.elastic.co/t/get-more-userinfos-after-openid-login/256079>\
**Category:** Kibana\
**Tags:** user-experience\
**Created:** [November 20, 2020, 8:03am UTC](https://discuss.elastic.co/t/get-more-userinfos-after-openid-login/256079 "2020-11-20T08:03:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![thetell75](https://avatars.discourse-cdn.com/v4/letter/t/d9b06d/32.png) [@thetell75](https://discuss.elastic.co/u/thetell75)\
**Post date:** [November 20, 2020, 8:03am UTC](https://discuss.elastic.co/t/get-more-userinfos-after-openid-login/256079/1 "2020-11-20T08:03:39Z")

</div>

Hi folks,

I just implemented the OpenID Login with AZURE Login. I also added Claims for personal informatione about the user logging in, like Family\_Name, Given\_Name and Email.

But after Login I just do see that I am logged in with a Username like NUNPBx9kRenrHVAFcwz8e02Clq5d.

This seemed to be generated as I do not have any user on Elasticsearch. I become the permissions through Group Mapping.

So my question is, can I configure the OpenID Claims to be visible in the User Infos?

Thanks

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [November 20, 2020, 8:22am UTC](https://discuss.elastic.co/t/get-more-userinfos-after-openid-login/256079/2 "2020-11-20T08:22:55Z")

</div>

Hello Stefan,

I have not used openID myself, but could you post your configuration? According to the [docs](https://www.elastic.co/guide/en/elasticsearch/reference/master/oidc-guide-authentication.html) there is a setting called `op.userinfo_endpoint`:

> ... This is the endpoint of the OP that can be queried to get further user information, if required. ...

Did you configure this setting?

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![thetell75](https://avatars.discourse-cdn.com/v4/letter/t/d9b06d/32.png) [@thetell75](https://discuss.elastic.co/u/thetell75)\
**Post date:** [November 20, 2020, 12:15pm UTC](https://discuss.elastic.co/t/get-more-userinfos-after-openid-login/256079/3 "2020-11-20T12:15:19Z")

</div>

Hi Wolfram,

thanks for the hint. Could do it by adding the following lines to the realm configuration:

```
        claims.principal: upn
        claims.groups: groups
        claims.name: name
        claims.mail: email
        populate_user_metadata: true

```

Greets Stefan

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2020, 12:15pm UTC](https://discuss.elastic.co/t/get-more-userinfos-after-openid-login/256079/4 "2020-12-18T12:15:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
