Azure AD B2C TOTP自定义策略对接Google IDP登录异常问题
解决方案:Azure AD B2C TOTP策略兼容第三方IDP登录问题
核心问题分析
你遇到的问题根源有两个:
- 第三方IDP(如Google)登录后,未正确从B2C目录中读取用户的
objectId(第三方用户以AlternativeSecurityId存储,而非直接使用objectId作为登录标识); - 未配置会话复用,导致已登录用户被要求重新验证。
具体修复步骤
1. 新增第三方用户objectId读取步骤
在你的UserJourney中,Google登录完成后,添加**基于AlternativeSecurityId读取用户objectId**的步骤,替代仅适用于本地账号的AAD-UserReadUsingObjectId:
<!-- Google登录步骤之后添加 --> <OrchestrationStep Order="3" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="AADUserReadUsingAlternativeSecurityId" TechnicalProfileReferenceId="AAD-UserReadUsingAlternativeSecurityId" /> </ClaimsExchanges> </OrchestrationStep>
同时确保AAD-UserReadUsingAlternativeSecurityId技术配置文件正确输出objectId:
<TechnicalProfile Id="AAD-UserReadUsingAlternativeSecurityId"> <Metadata> <Item Key="Operation">Read</Item> <Item Key="RaiseErrorIfClaimsPrincipalDoesNotExist">true</Item> </Metadata> <InputClaims> <InputClaim ClaimTypeReferenceId="AlternativeSecurityId" Required="true" /> </InputClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="objectId" /> <!-- 按需添加其他需要的用户声明 --> </OutputClaims> <IncludeTechnicalProfile ReferenceId="AAD-Common" /> </TechnicalProfile>
2. 配置会话复用避免重复登录
在你的信赖方(Relying Party)策略中添加会话复用配置,确保已登录用户无需重新验证:
<RelyingParty> <DefaultUserJourney ReferenceId="你的UserJourneyID" /> <UserJourneyBehaviors> <SingleSignOn Scope="Tenant" KeepAliveInDays="30" /> <SessionExpiryType>Absolute</SessionExpiryType> <SessionExpiryInSeconds>86400</SessionExpiryInSeconds> </UserJourneyBehaviors> <!-- 其他信赖方配置 --> </RelyingParty>
3. 确保TOTP流程依赖正确的objectId声明
检查TOTP相关技术配置文件(如TOTPSetup、TOTPVerify)的输入声明,确保objectId直接从声明袋中获取,而非触发重新登录:
<TechnicalProfile Id="TOTPSetup"> <InputClaims> <InputClaim ClaimTypeReferenceId="objectId" Required="true" /> <!-- 其他输入声明 --> </InputClaims> <!-- 其他配置 --> </TechnicalProfile>
验证要点
- 登录Google后,检查声明袋中是否存在
objectId(可通过Application Insights或调试工具查看); - 确认TOTP二维码页面直接加载,无二次登录跳转;
- 检查Application Insights中是否再出现"找不到objectId声明"的错误。
内容的提问来源于stack exchange,提问作者user20406743
相关产品推荐
相关产品推荐

