Azure B2C租户迁移:无法读取旧租户自定义Claim值求助
Azure B2C租户迁移:读取旧租户自定义声明失败问题
需求
- 将用户从旧B2C租户迁移至新Azure B2C租户,用于统一登录。
- 用户使用新租户自定义策略登录时:先检查新租户是否存在该用户;若不存在,则验证旧租户的用户凭据、配置文件及自定义声明
Extension_UserRole。仅当旧租户用户存在且Extension_UserRole值为Customer时,才在新租户创建对应用户。
实施方式
- 基于B2C到B2C迁移自定义策略模板实现登录扩展逻辑。
- 不执行预迁移脚本,用户首次登录新租户时自动完成迁移创建。
问题挑战
- 用户首次登录新租户时,无法读取旧租户用户的自定义声明
extension_[ExtensionAppRegistratrionID]_UserRole,返回空值。
尝试方案
已配置如下XML技术Profile调用旧租户ROPC接口,但自定义声明读取失败:
<TechnicalProfiles> <!-- REMOTE ROPC Call to Legacy B2C Instance --> <TechnicalProfile Id="login-Remote"> <DisplayName>Remote Account SignIn</DisplayName> <Protocol Name="OpenIdConnect" /> <Metadata> <Item Key="METADATA">https://login.microsoftonline.com/legacy B2C tenant name/.well-known/openid-configuration</Item> <Item Key="authorization_endpoint">https://login.microsoftonline.com/legacy B2C tenant name/oauth2/token</Item> <Item Key="response_types">id_token</Item> <Item Key="response_mode">query</Item> <Item Key="scope">email openid</Item> <!-- Policy Engine Clients --> <Item Key="UsePolicyInRedirectUri">false</Item> <Item Key="HttpBinding">POST</Item> <Item Key="client_id">RemoteB2CProxyIdentityExperienceFrameworkAppId</Item> <Item Key="IdTokenAudience">RemoteB2CIdentityExperienceFrameworkAppId</Item> </Metadata> <InputClaims> <InputClaim ClaimTypeReferenceId="signInName" PartnerClaimType="username" Required="true" /> <InputClaim ClaimTypeReferenceId="password" Required="true" /> <InputClaim ClaimTypeReferenceId="grant_type" DefaultValue="password" /> <InputClaim ClaimTypeReferenceId="scope" DefaultValue="openid" /> <InputClaim ClaimTypeReferenceId="nca" PartnerClaimType="nca" DefaultValue="1" /> <InputClaim ClaimTypeReferenceId="client_id" DefaultValue="RemoteB2CProxyIdentityExperienceFrameworkAppId" /> <InputClaim ClaimTypeReferenceId="tenantId" PartnerClaimType="resource" DefaultValue="RemoteB2CIdentityExperienceFrameworkAppId" /> </InputClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="givenName" PartnerClaimType="given_name" /> <OutputClaim ClaimTypeReferenceId="email" /> <OutputClaim ClaimTypeReferenceId="surName" PartnerClaimType="family_name" /> <OutputClaim ClaimTypeReferenceId="displayName" PartnerClaimType="name" /> <OutputClaim ClaimTypeReferenceId="authenticationSource" DefaultValue="localAccountAuthentication" /> <OutputClaim ClaimTypeReferenceId="isLocalUser" DefaultValue="false"/> <OutputClaim ClaimTypeReferenceId="extension_UserRole" PartnerClaimType="extension_b2c-extensions-app-guid_UserRole"/> </OutputClaims> </TechnicalProfile> </TechnicalProfiles>
解决方案
1. 修正自定义声明的PartnerClaimType
旧租户的自定义声明完整键名格式为extension_{b2c-extensions-app-client-id-无横杠}_UserRole:
- 登录旧B2C租户,找到b2c-extensions-app应用注册,复制其Client ID并移除所有横杠(例如
123e4567-e89b-12d3-a456-426614174000改为123e4567e89b12d3a456426614174000) - 将技术Profile中的
PartnerClaimType替换为实际值:<OutputClaim ClaimTypeReferenceId="extension_UserRole" PartnerClaimType="extension_123e4567e89b12d3a456426614174000_UserRole"/>
2. 配置旧租户策略输出自定义声明到ID Token
在旧B2C租户的登录自定义策略中,找到本地账户登录对应的TechnicalProfile(如login-NonInteractive),在<OutputClaims>中添加该声明:
<OutputClaim ClaimTypeReferenceId="extension_UserRole" />
确保旧租户ROPC接口返回的ID Token包含该自定义声明。
3. 扩展新租户技术Profile的Scope
更新login-Remote的Metadata中的Scope,添加旧租户b2c-extensions-app的访问权限:
<Item Key="scope">email openid https://{旧租户域名}.onmicrosoft.com/b2c-extensions-app/user_impersonation</Item>
替换{旧租户域名}为实际的旧B2C租户域名(如contosolegacy)。
4. 验证旧租户应用权限
在旧B2C租户中,确认RemoteB2CProxyIdentityExperienceFrameworkAppId应用注册已获得b2c-extensions-app的user_impersonation权限,并完成管理员同意。
内容的提问来源于stack exchange,提问作者alisha garg
相关产品推荐
相关产品推荐

