You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure B2C租户迁移:无法读取旧租户自定义Claim值求助

Azure B2C租户迁移:读取旧租户自定义声明失败问题

需求

  • 将用户从旧B2C租户迁移至新Azure B2C租户,用于统一登录。
  • 用户使用新租户自定义策略登录时:先检查新租户是否存在该用户;若不存在,则验证旧租户的用户凭据、配置文件及自定义声明Extension_UserRole。仅当旧租户用户存在且Extension_UserRole值为Customer时,才在新租户创建对应用户。

实施方式

  • 基于B2C到B2C迁移自定义策略模板实现登录扩展逻辑。
  • 不执行预迁移脚本,用户首次登录新租户时自动完成迁移创建。

问题挑战

  • 用户首次登录新租户时,无法读取旧租户用户的自定义声明extension_[ExtensionAppRegistratrionID]_UserRole,返回空值。

尝试方案

已配置如下XML技术Profile调用旧租户ROPC接口,但自定义声明读取失败:

<TechnicalProfiles>
    <!-- REMOTE ROPC Call to Legacy B2C Instance -->
    <TechnicalProfile Id="login-Remote">
        <DisplayName>Remote Account SignIn</DisplayName>
        <Protocol Name="OpenIdConnect" />
        <Metadata>
            <Item Key="METADATA">https://login.microsoftonline.com/legacy B2C tenant name/.well-known/openid-configuration</Item>
            <Item Key="authorization_endpoint">https://login.microsoftonline.com/legacy B2C tenant name/oauth2/token</Item>
            <Item Key="response_types">id_token</Item>
            <Item Key="response_mode">query</Item>
            <Item Key="scope">email openid</Item>
            <!-- Policy Engine Clients -->
            <Item Key="UsePolicyInRedirectUri">false</Item>
            <Item Key="HttpBinding">POST</Item>
            <Item Key="client_id">RemoteB2CProxyIdentityExperienceFrameworkAppId</Item>
            <Item Key="IdTokenAudience">RemoteB2CIdentityExperienceFrameworkAppId</Item>
        </Metadata>
        <InputClaims>
            <InputClaim ClaimTypeReferenceId="signInName" PartnerClaimType="username" Required="true" />
            <InputClaim ClaimTypeReferenceId="password" Required="true" />
            <InputClaim ClaimTypeReferenceId="grant_type" DefaultValue="password" />
            <InputClaim ClaimTypeReferenceId="scope" DefaultValue="openid" />
            <InputClaim ClaimTypeReferenceId="nca" PartnerClaimType="nca" DefaultValue="1" />
            <InputClaim ClaimTypeReferenceId="client_id" DefaultValue="RemoteB2CProxyIdentityExperienceFrameworkAppId" />
            <InputClaim ClaimTypeReferenceId="tenantId" PartnerClaimType="resource" DefaultValue="RemoteB2CIdentityExperienceFrameworkAppId" />
        </InputClaims>
        <OutputClaims>
            <OutputClaim ClaimTypeReferenceId="givenName" PartnerClaimType="given_name" />
            <OutputClaim ClaimTypeReferenceId="email" />
            <OutputClaim ClaimTypeReferenceId="surName" PartnerClaimType="family_name" />
            <OutputClaim ClaimTypeReferenceId="displayName" PartnerClaimType="name" />
            <OutputClaim ClaimTypeReferenceId="authenticationSource" DefaultValue="localAccountAuthentication" />
            <OutputClaim ClaimTypeReferenceId="isLocalUser" DefaultValue="false"/> 
            <OutputClaim ClaimTypeReferenceId="extension_UserRole" PartnerClaimType="extension_b2c-extensions-app-guid_UserRole"/> 
        </OutputClaims>
    </TechnicalProfile>
</TechnicalProfiles>

解决方案

1. 修正自定义声明的PartnerClaimType

旧租户的自定义声明完整键名格式为extension_{b2c-extensions-app-client-id-无横杠}_UserRole:

  • 登录旧B2C租户,找到b2c-extensions-app应用注册,复制其Client ID并移除所有横杠(例如123e4567-e89b-12d3-a456-426614174000改为123e4567e89b12d3a456426614174000)
  • 将技术Profile中的PartnerClaimType替换为实际值:
    <OutputClaim ClaimTypeReferenceId="extension_UserRole" PartnerClaimType="extension_123e4567e89b12d3a456426614174000_UserRole"/>
    

2. 配置旧租户策略输出自定义声明到ID Token

在旧B2C租户的登录自定义策略中,找到本地账户登录对应的TechnicalProfile(如login-NonInteractive),在<OutputClaims>中添加该声明:

<OutputClaim ClaimTypeReferenceId="extension_UserRole" />

确保旧租户ROPC接口返回的ID Token包含该自定义声明。

3. 扩展新租户技术Profile的Scope

更新login-Remote的Metadata中的Scope,添加旧租户b2c-extensions-app的访问权限:

<Item Key="scope">email openid https://{旧租户域名}.onmicrosoft.com/b2c-extensions-app/user_impersonation</Item>

替换{旧租户域名}为实际的旧B2C租户域名(如contosolegacy)。

4. 验证旧租户应用权限

在旧B2C租户中,确认RemoteB2CProxyIdentityExperienceFrameworkAppId应用注册已获得b2c-extensions-app的user_impersonation权限,并完成管理员同意。


内容的提问来源于stack exchange,提问作者alisha garg

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 22:52:34