You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C TOTP自定义策略对接Google IDP登录异常问题

解决方案:Azure AD B2C TOTP策略兼容第三方IDP登录问题

核心问题分析

你遇到的问题根源有两个:

  1. 第三方IDP(如Google)登录后,未正确从B2C目录中读取用户的objectId(第三方用户以AlternativeSecurityId存储,而非直接使用objectId作为登录标识);
  2. 未配置会话复用,导致已登录用户被要求重新验证。

具体修复步骤

1. 新增第三方用户objectId读取步骤

在你的UserJourney中,Google登录完成后,添加**基于AlternativeSecurityId读取用户objectId**的步骤,替代仅适用于本地账号的AAD-UserReadUsingObjectId:

<!-- Google登录步骤之后添加 -->
<OrchestrationStep Order="3" Type="ClaimsExchange">
  <ClaimsExchanges>
    <ClaimsExchange Id="AADUserReadUsingAlternativeSecurityId" TechnicalProfileReferenceId="AAD-UserReadUsingAlternativeSecurityId" />
  </ClaimsExchanges>
</OrchestrationStep>

同时确保AAD-UserReadUsingAlternativeSecurityId技术配置文件正确输出objectId:

<TechnicalProfile Id="AAD-UserReadUsingAlternativeSecurityId">
  <Metadata>
    <Item Key="Operation">Read</Item>
    <Item Key="RaiseErrorIfClaimsPrincipalDoesNotExist">true</Item>
  </Metadata>
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="AlternativeSecurityId" Required="true" />
  </InputClaims>
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="objectId" />
    <!-- 按需添加其他需要的用户声明 -->
  </OutputClaims>
  <IncludeTechnicalProfile ReferenceId="AAD-Common" />
</TechnicalProfile>

2. 配置会话复用避免重复登录

在你的信赖方(Relying Party)策略中添加会话复用配置,确保已登录用户无需重新验证:

<RelyingParty>
  <DefaultUserJourney ReferenceId="你的UserJourneyID" />
  <UserJourneyBehaviors>
    <SingleSignOn Scope="Tenant" KeepAliveInDays="30" />
    <SessionExpiryType>Absolute</SessionExpiryType>
    <SessionExpiryInSeconds>86400</SessionExpiryInSeconds>
  </UserJourneyBehaviors>
  <!-- 其他信赖方配置 -->
</RelyingParty>

3. 确保TOTP流程依赖正确的objectId声明

检查TOTP相关技术配置文件(如TOTPSetup、TOTPVerify)的输入声明,确保objectId直接从声明袋中获取,而非触发重新登录:

<TechnicalProfile Id="TOTPSetup">
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="objectId" Required="true" />
    <!-- 其他输入声明 -->
  </InputClaims>
  <!-- 其他配置 -->
</TechnicalProfile>

验证要点

  • 登录Google后,检查声明袋中是否存在objectId(可通过Application Insights或调试工具查看);
  • 确认TOTP二维码页面直接加载,无二次登录跳转;
  • 检查Application Insights中是否再出现"找不到objectId声明"的错误。

内容的提问来源于stack exchange,提问作者user20406743

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 06:07:40