Azure Active Directory Provider不支持Groups声明的问题求助
解决Azure AD Provider不支持
groups声明的问题 Azure AD Provider(在Azure AD B2C自定义策略的技术配置文件中)不支持直接输出groups声明,因为它默认仅返回用户的核心身份属性(如objectId、displayName等),不会主动获取用户所属的组数据。你需要通过调用Microsoft Graph API来获取组信息,具体步骤如下:
1. 创建调用Graph API的技术配置文件
新建一个专门用于读取用户组的技术配置文件,使用OAuth2Bearer协议调用Graph的memberOf端点(该端点会返回用户所属的所有组):
<TechnicalProfile Id="Graph-GetUserGroups"> <DisplayName>Fetch User Groups via Graph API</DisplayName> <Protocol Name="OAuth2Bearer" /> <Metadata> <!-- 配置Graph API端点,仅返回组ID --> <Item Key="ClaimsEndpoint">https://graph.microsoft.com/v1.0/me/memberOf?$select=id</Item> <Item Key="HttpBinding">GET</Item> <!-- 配置Bearer令牌获取信息 --> <Item Key="BearerTokenEndpoint">https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token</Item> <Item Key="ClientId">{你的B2C应用客户端ID}</Item> <Item Key="ClientSecret">{你的B2C应用客户端密钥}</Item> <Item Key="Scope">https://graph.microsoft.com/.default</Item> <Item Key="UseCommonEndpoint">false</Item> </Metadata> <InputClaims> <!-- 传入用户的objectId用于定位目标用户 --> <InputClaim ClaimTypeReferenceId="objectId" /> </InputClaims> <OutputClaims> <!-- 将Graph返回的组ID映射到你的`groups`声明 --> <OutputClaim ClaimTypeReferenceId="groups" PartnerClaimType="id" /> </OutputClaims> <!-- 将返回的数组转为stringCollection类型(若需要) --> <OutputClaimsTransformations> <OutputClaimsTransformation ReferenceId="ConvertArrayToStringCollection" /> </OutputClaimsTransformations> <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" /> </TechnicalProfile>
2. 配置应用权限
确保你的B2C应用注册(用于调用Graph API的应用)已添加Microsoft Graph的应用权限:
- 添加
User.Read.All或Directory.Read.All权限(前者足够读取当前用户的组信息) - 完成管理员同意操作,否则Graph API会返回权限不足的错误
3. 在用户旅程中调用该技术配置文件
将这个新的技术配置文件添加到你的用户旅程流程中,比如在读取用户核心信息之后执行:
<UserJourney Id="SignUpOrSignIn"> <OrchestrationSteps> <!-- 其他步骤:登录验证、读取用户核心属性等 --> <OrchestrationStep Order="3" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="GetUserGroups" TechnicalProfileReferenceId="Graph-GetUserGroups" /> </ClaimsExchanges> </OrchestrationStep> <!-- 后续流程步骤 --> </OrchestrationSteps> </UserJourney>
关键说明
- 不要尝试在
AzureActiveDirectory类型的技术配置文件中直接添加groups输出声明,该Provider本身不支持返回组数据,这就是你收到错误提示的根本原因。 - 确保
groups声明的类型设置为stringCollection,因为一个用户可能属于多个组,数组类型更适配这种场景。
内容的提问来源于stack exchange,提问作者IriaAM
相关产品推荐
相关产品推荐

