You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C自定义策略能否基于来源URL动态选择外部IdP?

基于来源URL动态选择外部IdP实现静默SSO的方案

可以通过Azure AD B2C自定义策略实现你的需求,具体实现步骤如下:

1. 捕获来源上下文信息

首先需要在自定义策略中捕获用户的来源URL(或自定义来源参数)。考虑到浏览器对referrer的限制(比如跨域场景下可能无法获取),建议前端传递自定义参数(如source),如果依赖referrer也可以直接捕获:

  • 先在<ClaimsSchema>中定义存储来源信息的声明:

    <ClaimType Id="sourceContext">
      <DisplayName>Source Context</DisplayName>
      <DataType>string</DataType>
    </ClaimType>
    
  • 创建技术配置文件来获取请求中的来源参数:

    <TechnicalProfile Id="RetrieveSourceContext">
      <DisplayName>Get Source Context from Request</DisplayName>
      <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.ClaimsTransformationProtocolProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
      <InputClaims>
        <!-- 这里可以用referrer或者自定义的source参数 -->
        <InputClaim ClaimTypeReferenceId="sourceContext" PartnerClaimType="referrer" DefaultValue="" />
        <!-- 如果用自定义参数,替换为:<InputClaim ClaimTypeReferenceId="sourceContext" PartnerClaimType="source" DefaultValue="" /> -->
      </InputClaims>
    </TechnicalProfile>
    
  • 将这个技术配置文件添加到用户旅程的起始步骤,确保在选择IdP前完成信息捕获。

2. 根据来源动态跳转至对应外部IdP

通过编排步骤的Precondition条件判断,自动跳过IdP选择界面,直接跳转到匹配的外部IdP授权端点:

<!-- 步骤1:默认IdP选择界面(仅当无匹配来源时显示) -->
<OrchestrationStep Order="1" Type="ClaimsProviderSelection" ContentDefinitionReferenceId="api.idpselections">
  <Preconditions>
    <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
      <Value>sourceContext</Value>
      <Value>https://referrer-a.com</Value>
      <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
    <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
      <Value>sourceContext</Value>
      <Value>https://referrer-b.com</Value>
      <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
    <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
      <Value>sourceContext</Value>
      <Value>https://referrer-c.com</Value>
      <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
  </Preconditions>
  <ClaimsProviderSelections>
    <ClaimsProviderSelection TargetClaimsExchangeId="IdP-A" />
    <ClaimsProviderSelection TargetClaimsExchangeId="IdP-B" />
    <ClaimsProviderSelection TargetClaimsExchangeId="IdP-C" />
  </ClaimsProviderSelections>
</OrchestrationStep>

<!-- 步骤2:来源A自动跳转至IdP-A -->
<OrchestrationStep Order="2" Type="ClaimsExchange">
  <Preconditions>
    <Precondition Type="ClaimEquals" ExecuteActionsIf="false">
      <Value>sourceContext</Value>
      <Value>https://referrer-a.com</Value>
      <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
  </Preconditions>
  <ClaimsExchanges>
    <ClaimsExchange Id="IdP-A" TechnicalProfileReferenceId="IdP-A-OAuth2" />
  </ClaimsExchanges>
</OrchestrationStep>

<!-- 步骤3:来源B自动跳转至IdP-B -->
<OrchestrationStep Order="3" Type="ClaimsExchange">
  <Preconditions>
    <Precondition Type="ClaimEquals" ExecuteActionsIf="false">
      <Value>sourceContext</Value>
      <Value>https://referrer-b.com</Value>
      <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
  </Preconditions>
  <ClaimsExchanges>
    <ClaimsExchange Id="IdP-B" TechnicalProfileReferenceId="IdP-B-OAuth2" />
  </ClaimsExchanges>
</OrchestrationStep>

<!-- 步骤4:来源C自动跳转至IdP-C -->
<OrchestrationStep Order="4" Type="ClaimsExchange">
  <Preconditions>
    <Precondition Type="ClaimEquals" ExecuteActionsIf="false">
      <Value>sourceContext</Value>
      <Value>https://referrer-c.com</Value>
      <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
  </Preconditions>
  <ClaimsExchanges>
    <ClaimsExchange Id="IdP-C" TechnicalProfileReferenceId="IdP-C-OAuth2" />
  </ClaimsExchanges>
</OrchestrationStep>

3. 配置静默SSO模式

在每个外部IdP的技术配置文件中,添加静默授权相关的元数据,确保使用授权码流且无交互:

<TechnicalProfile Id="IdP-A-OAuth2">
  <DisplayName>IdP A</DisplayName>
  <Protocol Name="OAuth2" />
  <Metadata>
    <Item Key="AuthorizationEndpoint">https://idp-a.com/authorize</Item>
    <Item Key="TokenEndpoint">https://idp-a.com/token</Item>
    <Item Key="response_types">code</Item>
    <Item Key="scope">openid profile</Item>
    <Item Key="prompt">none</Item> <!-- 启用静默模式,无用户交互 -->
    <Item Key="HttpBinding">POST</Item>
    <!-- 其他必要配置:ClientId、ClientSecret等 -->
  </Metadata>
  <!-- 输入输出声明配置 -->
</TechnicalProfile>

关键注意事项

  • 来源参数可靠性:依赖referrer可能存在跨域限制或被篡改的风险,优先使用前端传递的自定义source参数。
  • 会话有效性:静默SSO依赖用户在对应外部IdP的有效会话,若会话已过期,IdP会返回错误,需在策略中添加 fallback 逻辑(比如跳转到IdP登录界面)。
  • 信任关系配置:确保Azure AD B2C与所有外部IdP的信任关系已正确配置,包括回调URL、客户端凭证等。

内容的提问来源于stack exchange,提问作者Andrew Tyson

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 03:21:15