You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过编程获取Azure B2C令牌时出现协议处理程序未解析错误

解决Azure B2C非交互式登录的500错误及AADB2C90225问题

问题核心

你遇到的500错误是因为交互式的SelfAsserted-LocalAccountSignin-Email技术Profile被错误地用于非交互式流程——这类Profile依赖用户交互输入,协议类型为"Proprietary",不支持无交互场景。跳过它直接调用login-NonInteractive出现的AADB2C90225错误,是因为非交互式流程的配置不完整,缺少必要的输入声明或Profile映射。

解决方案步骤

1. 创建专属的非交互式自定义策略

不要复用交互式的B2C_1A_signup_signin策略,单独创建非交互式策略,确保用户旅程中只包含非交互步骤:

  • 移除所有依赖用户交互的步骤(比如SelfAsserted类Profile)
  • 直接调用login-NonInteractive完成认证

2. 正确配置login-NonInteractive技术Profile

确保该Profile的协议为OpenIdConnect,并正确映射输入输出声明:

<TechnicalProfile Id="login-NonInteractive">
  <DisplayName>Local Account Non-Interactive Signin</DisplayName>
  <Protocol Name="OpenIdConnect" />
  <Metadata>
    <Item Key="UserMessageIfClaimsPrincipalDoesNotExist">账户不存在</Item>
    <Item Key="UserMessageIfInvalidPassword">密码错误</Item>
    <Item Key="ProviderName">https://sts.windows.net/</Item>
    <Item Key="METADATA">https://login.microsoftonline.com/{tenant}/v2.0/.well-known/openid-configuration</Item>
    <Item Key="authorization_endpoint">https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token</Item>
    <Item Key="response_types">id_token</Item>
    <Item Key="response_mode">query</Item>
    <Item Key="scope">openid</Item>
    <Item Key="UsePolicyInRedirectUri">false</Item>
    <Item Key="HttpBinding">POST</Item>
    <Item Key="client_id">你的ProxyIdentityExperienceFramework应用ID</Item>
    <Item Key="IdTokenAudience">你的IdentityExperienceFramework应用ID</Item>
  </Metadata>
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="signInName" PartnerClaimType="username" Required="true" />
    <InputClaim ClaimTypeReferenceId="password" Required="true" />
    <InputClaim ClaimTypeReferenceId="grant_type" DefaultValue="password" />
    <InputClaim ClaimTypeReferenceId="scope" DefaultValue="openid" />
    <InputClaim ClaimTypeReferenceId="nca" PartnerClaimType="nca" DefaultValue="1" />
  </InputClaims>
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="objectId" PartnerClaimType="oid" />
    <OutputClaim ClaimTypeReferenceId="tenantId" PartnerClaimType="tid" />
    <!-- 按需添加你需要的增强声明 -->
    <OutputClaim ClaimTypeReferenceId="givenName" PartnerClaimType="given_name" />
    <OutputClaim ClaimTypeReferenceId="surName" PartnerClaimType="family_name" />
  </OutputClaims>
  <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" />
</TechnicalProfile>

3. 配置非交互式用户旅程

用户旅程只保留认证和发令牌的步骤:

<UserJourney Id="NonInteractiveSignIn">
  <OrchestrationSteps>
    <OrchestrationStep Order="1" Type="ClaimsProviderSelection">
      <ClaimsProviderSelections>
        <ClaimsProviderSelection TargetClaimsExchangeId="LocalAccountSigninExchange" />
      </ClaimsProviderSelections>
    </OrchestrationStep>
    <OrchestrationStep Order="2" Type="ClaimsExchange">
      <ClaimsExchanges>
        <ClaimsExchange Id="LocalAccountSigninExchange" TechnicalProfileReferenceId="login-NonInteractive" />
      </ClaimsExchanges>
    </OrchestrationStep>
    <OrchestrationStep Order="3" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" />
  </OrchestrationSteps>
  <ClientDefinition ReferenceId="DefaultWeb" />
</UserJourney>

4. 代码调用时指定非交互式策略

使用MSAL的AcquireTokenByUsernamePassword方法,确保Authority指向你的非交互式策略:

var scopes = new[] { "https://yourtenant.onmicrosoft.com/yourapi/api.read" };
var pca = PublicClientApplicationBuilder
    .Create("你的客户端应用ID")
    .WithB2CAuthority("https://yourtenant.b2clogin.com/yourtenant.onmicrosoft.com/B2C_1A_noninteractive_signin")
    .Build();

var authResult = await pca.AcquireTokenByUsernamePassword(scopes, "user@example.com", "UserPassword123")
    .ExecuteAsync();

// 获取包含增强声明的Bearer令牌
string bearerToken = authResult.AccessToken;

关键注意事项

  • 非交互式登录仅支持本地账户(用户名密码),不支持社交账户登录
  • 确保ProxyIdentityExperienceFramework和IdentityExperienceFramework应用已正确配置,且策略中引用的ID正确
  • 不要在非交互式流程中包含任何需要用户交互的步骤(如SelfAsserted、DisplayControl等)

内容的提问来源于stack exchange,提问作者francoiswnel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 19:57:04