You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C自定义策略:TOTP选项MFA选择屏重复显示求助

解决方案:让TOTP选项的MFA选择持久化

问题核心是TOTP子旅程未将用户选择的MFA方式写入用户扩展属性,导致每次登录时extension_mfaByPhoneOrEmail声明不存在,重复触发选择界面。按以下步骤修复:

1. 在TOTP子旅程中添加声明持久化步骤

找到TOTP子旅程(SignUpOrSignInTOTP)的最后一个编排步骤,添加写入用户属性的逻辑,将extension_mfaByPhoneOrEmail设为TOTP:

<OrchestrationStep Order="最后一步序号+1" Type="ClaimsExchange">
  <Preconditions>
    <Precondition Type="ClaimEquals" ExecuteActionsIf="false">
      <Value>extension_mfaByPhoneOrEmail</Value>
      <Value>TOTP</Value>
      <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
  </Preconditions>
  <ClaimsExchanges>
    <ClaimsExchange Id="WriteTOTPMFASelection" TechnicalProfileReferenceId="AAD-UserWriteUsingAlternativeSecurityId" />
  </ClaimsExchanges>
</OrchestrationStep>

同时,确保AAD-UserWriteUsingAlternativeSecurityId技术配置文件支持持久化该声明,在其<PersistedClaims>节点中添加:

<PersistedClaim ClaimTypeReferenceId="extension_mfaByPhoneOrEmail" />

2. 确保登录时读取用户的MFA选择声明

在读取用户属性的技术配置文件(如AAD-UserReadUsingEmailAddress或AAD-UserReadUsingAlternativeSecurityId)中,添加输出该声明的配置:

<OutputClaim ClaimTypeReferenceId="extension_mfaByPhoneOrEmail" />

3. 修改MFA选择界面的前置条件

找到显示MFA选择界面的编排步骤(通常是调用SelfAsserted-LocalAccountSignin-Email类技术配置文件的步骤),添加前置条件:如果用户已存在extension_mfaByPhoneOrEmail声明,则跳过该界面:

<Precondition Type="ClaimExists" ExecuteActionsIf="true">
  <Value>extension_mfaByPhoneOrEmail</Value>
  <Action>SkipThisOrchestrationStep</Action>
</Precondition>

或者更精确地针对三种MFA方式判断:

<Precondition Type="Or">
  <Preconditions>
    <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
      <Value>extension_mfaByPhoneOrEmail</Value>
      <Value>phone</Value>
      <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
    <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
      <Value>extension_mfaByPhoneOrEmail</Value>
      <Value>email</Value>
      <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
    <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
      <Value>extension_mfaByPhoneOrEmail</Value>
      <Value>TOTP</Value>
      <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
  </Preconditions>
</Precondition>

完成以上配置后,用户首次选择TOTP作为MFA方式时,该选择会被写入用户属性,后续登录时系统会直接读取该值并跳过选择界面,和邮箱、电话的表现一致。

内容的提问来源于stack exchange,提问作者Arjun

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 07:15:54