如何在Azure AD B2C自定义策略中实现高流量场景会话阈值检查?
Azure AD B2C自定义策略会话阈值管理方案
1. 通过Azure AD B2C日志监控当前会话数
- 先启用Azure AD B2C诊断日志:在Azure门户的B2C资源中进入「诊断设置」,添加新配置,选择将日志发送到Log Analytics工作区,勾选
SignInLogs等核心日志类别。 - 使用Kusto查询统计活跃会话数:在Log Analytics中运行以下查询(可根据实际会话超时时间调整时间范围),实时统计当前活跃会话总量:
SignInLogs | where TimeGenerated > ago(24h) // 假设会话超时为24小时,按需修改 | where ResultType == 0 // 仅统计成功登录的会话 | summarize ActiveSessions = dcount(CorrelationId) // 按关联ID去重计算会话数
- 可将该查询保存为仪表板,实现会话数量的实时监控。
2. 登录时检查会话数阈值的最佳方式
Azure AD B2C自定义策略无法直接读取会话统计数据,需借助外部服务实现阈值检查,推荐使用Azure Functions作为中间层:
- 步骤1:编写Azure Function
创建一个Azure Function,调用Log Analytics API查询当前活跃会话数,判断是否超过10000阈值后返回结果。核心逻辑示例(C#):public static async Task<IActionResult> Run(HttpRequest req, ILogger log) { // 调用Log Analytics查询会话数的逻辑(需实现GetActiveSessionsFromLogAnalytics方法) int activeSessions = await GetActiveSessionsFromLogAnalytics(); bool isOverThreshold = activeSessions > 10000; return new OkObjectResult(new { IsOverThreshold = isOverThreshold }); } - 步骤2:在自定义策略中配置REST API调用
添加REST API技术配置,指向上述Azure Function:<ClaimsProvider> <DisplayName>SessionCheckAPI</DisplayName> <TechnicalProfiles> <TechnicalProfile Id="SessionCheck-REST"> <DisplayName>Check Active Sessions Threshold</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ServiceUrl">https://your-function-app.azurewebsites.net/api/CheckSessionThreshold</Item> <Item Key="AuthenticationType">None</Item> <Item Key="SendClaimsIn">Body</Item> </Metadata> <OutputClaims> <OutputClaim ClaimTypeReferenceId="isOverThreshold" PartnerClaimType="IsOverThreshold" /> </OutputClaims> <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" /> </TechnicalProfile> </TechnicalProfiles> </ClaimsProvider> - 步骤3:在用户旅程中加入检查步骤
在登录流程的前置步骤中调用该API,获取阈值判断结果:<OrchestrationStep Order="1" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="SessionCheckExchange" TechnicalProfileReferenceId="SessionCheck-REST" /> </ClaimsExchanges> </OrchestrationStep> - 步骤4:添加条件分支
根据返回的isOverThreshold声明,决定是否继续正常登录流程:<OrchestrationStep Order="2" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimEquals" ExecuteActionsIf="true"> <Value>isOverThreshold</Value> <Value>true</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <!-- 此处添加正常登录的ClaimsExchange,比如LocalAccountSigninEmailExchange --> </ClaimsExchanges> </OrchestrationStep>
3. 阈值超出时重定向到提示页面
- 步骤1:定义自定义提示页面
在策略的ContentDefinitions中添加“稍后重试”页面的配置:<ContentDefinitions> <ContentDefinition Id="api.sessionLimitExceeded"> <LoadUri>https://your-static-host.com/session-limit.html</LoadUri> <RecoveryUri>~/common/default_page_error.html</RecoveryUri> <DataUri>urn:com:microsoft:aad:b2c:elements:contract:globalexception:1.2.0</DataUri> <Metadata> <Item Key="DisplayName">Session Limit Exceeded Page</Item> </Metadata> </ContentDefinition> </ContentDefinitions> - 步骤2:创建页面技术配置
添加对应技术配置指向该内容页面:<ClaimsProvider> <DisplayName>SessionLimitPages</DisplayName> <TechnicalProfiles> <TechnicalProfile Id="SessionLimitExceededPage"> <DisplayName>Session Limit Exceeded Page</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ContentDefinitionReferenceId">api.sessionLimitExceeded</Item> <Item Key="ShowCancelButton">false</Item> </Metadata> <InputClaims /> <OutputClaims /> </TechnicalProfile> </TechnicalProfiles> </ClaimsProvider> - 步骤3:在用户旅程中添加跳转步骤
当isOverThreshold为true时,跳转到提示页面:<OrchestrationStep Order="2" Type="ShowPage"> <Preconditions> <Precondition Type="ClaimEquals" ExecuteActionsIf="false"> <Value>isOverThreshold</Value> <Value>true</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="SessionLimitPageExchange" TechnicalProfileReferenceId="SessionLimitExceededPage" /> </ClaimsExchanges> </OrchestrationStep>
内容的提问来源于stack exchange,提问作者nullmicgo
相关产品推荐
相关产品推荐

