You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Entra Verified ID规则中自定义安全属性声明的正确语法

问题:Entra External ID自定义安全属性无法在Verified Credentials签发规则中读取

已搭建Entra External ID系统,创建了自定义安全属性(用于存储会员编号与等级,当前演示用Foo.Bar),尝试在Verified Credentials的签发规则中引用该属性时,始终报错「Missing provided claims in issuance」;但使用given_name这类默认字段可以正常运行。试过Foo.Bar、user.Bar、extension_..._Bar等语法都无效,求正确的引用语法。

当前失败的签发规则

{
  "attestations": {
    "idTokenHints": [
      {
        "mapping": [
          {
            "outputClaim": "foobar",
            "required": true,
            "inputClaim": "Foo.Bar",
            "indexed": false
          }
        ],
        "required": false
      }
    ]
  },
  "validityInterval": 2592000,
  "vc": {
    "type": [
      "Foobar"
    ]
  }
}

报错信息

调用demo项目1-asp-net-core-api-idtokenhint的Issue API时返回:

issuance error: "Something went wrong calling the API: 
{
  "requestId": "2b020237faffd90eaed9d034a296775e",
  "date": "Tue, 21 May 2024 22:43:44 GMT",
  "mscv": "cpMoovB/XjpznKMR.3",
  "error": {
    "code": "badRequest",
    "message": "The request is invalid.",
    "innererror": {
      "code": "badOrMissingField",
      "message": "Missing provided claims in issuance: [Foo.Bar]",
      "target": "claims"
    }
  }
}"

配置截图

  • 自定义属性配置:
    Foo.Bar自定义属性配置界面
  • 用户属性配置:
    用户的Foo.Bar自定义属性配置界面

解决方案:正确引用自定义安全属性的语法

在Verified Credentials的签发规则中,自定义安全属性的正确引用格式是 customsecurityattributes.<AttributeSetName>.<AttributeName>,对应你的场景就是customsecurityattributes.Foo.Bar。

修改后的签发规则如下:

{
  "attestations": {
    "idTokenHints": [
      {
        "mapping": [
          {
            "outputClaim": "foobar",
            "required": true,
            "inputClaim": "customsecurityattributes.Foo.Bar",
            "indexed": false
          }
        ],
        "required": false
      }
    ]
  },
  "validityInterval": 2592000,
  "vc": {
    "type": [
      "Foobar"
    ]
  }
}

额外注意事项

  • 确保用于获取ID Token的应用已被授权读取自定义安全属性:在Entra ID的应用注册中,为应用添加CustomSecAttributeAssignment.Read.All或CustomSecAttribute.Read.All权限,并完成管理员同意。
  • 确认ID Token中包含该自定义属性:可通过解码ID Token查看是否存在customsecurityattributes字段,以及其中的Foo.Bar值是否正确。

内容的提问来源于stack exchange,提问作者EionRobb

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 11:05:22