You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Active Directory Provider不支持Groups声明的问题求助

解决Azure AD Provider不支持groups声明的问题

Azure AD Provider(在Azure AD B2C自定义策略的技术配置文件中)不支持直接输出groups声明,因为它默认仅返回用户的核心身份属性(如objectId、displayName等),不会主动获取用户所属的组数据。你需要通过调用Microsoft Graph API来获取组信息,具体步骤如下:

1. 创建调用Graph API的技术配置文件

新建一个专门用于读取用户组的技术配置文件,使用OAuth2Bearer协议调用Graph的memberOf端点(该端点会返回用户所属的所有组):

<TechnicalProfile Id="Graph-GetUserGroups">
  <DisplayName>Fetch User Groups via Graph API</DisplayName>
  <Protocol Name="OAuth2Bearer" />
  <Metadata>
    <!-- 配置Graph API端点,仅返回组ID -->
    <Item Key="ClaimsEndpoint">https://graph.microsoft.com/v1.0/me/memberOf?$select=id</Item>
    <Item Key="HttpBinding">GET</Item>
    <!-- 配置Bearer令牌获取信息 -->
    <Item Key="BearerTokenEndpoint">https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token</Item>
    <Item Key="ClientId">{你的B2C应用客户端ID}</Item>
    <Item Key="ClientSecret">{你的B2C应用客户端密钥}</Item>
    <Item Key="Scope">https://graph.microsoft.com/.default</Item>
    <Item Key="UseCommonEndpoint">false</Item>
  </Metadata>
  <InputClaims>
    <!-- 传入用户的objectId用于定位目标用户 -->
    <InputClaim ClaimTypeReferenceId="objectId" />
  </InputClaims>
  <OutputClaims>
    <!-- 将Graph返回的组ID映射到你的`groups`声明 -->
    <OutputClaim ClaimTypeReferenceId="groups" PartnerClaimType="id" />
  </OutputClaims>
  <!-- 将返回的数组转为stringCollection类型(若需要) -->
  <OutputClaimsTransformations>
    <OutputClaimsTransformation ReferenceId="ConvertArrayToStringCollection" />
  </OutputClaimsTransformations>
  <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" />
</TechnicalProfile>

2. 配置应用权限

确保你的B2C应用注册(用于调用Graph API的应用)已添加Microsoft Graph的应用权限:

  • 添加User.Read.All或Directory.Read.All权限(前者足够读取当前用户的组信息)
  • 完成管理员同意操作,否则Graph API会返回权限不足的错误

3. 在用户旅程中调用该技术配置文件

将这个新的技术配置文件添加到你的用户旅程流程中,比如在读取用户核心信息之后执行:

<UserJourney Id="SignUpOrSignIn">
  <OrchestrationSteps>
    <!-- 其他步骤:登录验证、读取用户核心属性等 -->
    <OrchestrationStep Order="3" Type="ClaimsExchange">
      <ClaimsExchanges>
        <ClaimsExchange Id="GetUserGroups" TechnicalProfileReferenceId="Graph-GetUserGroups" />
      </ClaimsExchanges>
    </OrchestrationStep>
    <!-- 后续流程步骤 -->
  </OrchestrationSteps>
</UserJourney>

关键说明

  • 不要尝试在AzureActiveDirectory类型的技术配置文件中直接添加groups输出声明,该Provider本身不支持返回组数据,这就是你收到错误提示的根本原因。
  • 确保groups声明的类型设置为stringCollection,因为一个用户可能属于多个组,数组类型更适配这种场景。

内容的提问来源于stack exchange,提问作者IriaAM

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 11:52:18