AD B2C技术需求:仅启用登录功能,禁用注册及联合账户自动创建
解决方案:AD B2C仅保留登录+禁止联合账户创建本地用户
一、禁用本地和联合账户的注册功能
1. 本地账户侧
如果用自定义策略,直接在TrustFrameworkExtensions.xml里修改用户旅程:
- 找到
UserJourney节点下的OrchestrationSteps,只保留登录相关步骤,删掉所有涉及注册的环节(比如LocalAccountSignUpWithLogonEmail技术配置文件的引用)。 - 示例用户旅程片段:
<OrchestrationStep Order="1" Type="CombinedSignInAndSignUp" ContentDefinitionReferenceId="api.signuporsignin"> <ClaimsProviderSelections> <ClaimsProviderSelection TargetClaimsExchangeId="LocalAccountSigninEmailExchange" /> <!-- 保留你的第三方身份提供商,比如Google/Facebook --> <ClaimsProviderSelection TargetClaimsExchangeId="GoogleExchange" /> </ClaimsProviderSelections> <ClaimsExchanges> <ClaimsExchange Id="LocalAccountSigninEmailExchange" TechnicalProfileReferenceId="SelfAsserted-LocalAccountSignin-Email" /> </ClaimsExchanges> </OrchestrationStep>
要是用内置用户流程,直接在Azure门户里把用户流程的注册选项设为“无”就行,但内置流程解决不了联合账户不创建用户的问题,所以还是得用自定义策略。
2. 联合账户侧
在第三方身份提供商的技术配置文件里,确保不触发注册逻辑,同时用户旅程里不要包含注册入口选项。
二、阻止联合账户首次登录时创建AD B2C本地用户
这是核心需求,默认联合账户第一次登录会自动在AD B2C用户池生成记录,要禁用这个得改自定义策略的两个关键部分:
1. 删除用户旅程中的创建用户步骤
找到用户旅程里第三方身份提供商登录后的OrchestrationStep,通常会有一个调用AAD-UserWriteUsingAlternativeSecurityId的步骤——直接删掉这个步骤,让流程登录后直接跳转至令牌颁发环节。
示例调整后的步骤:
<OrchestrationStep Order="2" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimsExist" ExecuteActionsIf="true"> <Value>objectId</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <!-- 这里是你的第三方身份提供商登录交换,比如Google --> <ClaimsExchange Id="GoogleExchange" TechnicalProfileReferenceId="Google-OAUTH" /> </ClaimsExchanges> </OrchestrationStep> <!-- 删掉下面这个原本用来创建联合账户本地记录的步骤 --> <!-- <OrchestrationStep Order="3" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="AADUserWriteUsingAlternativeSecurityIdExchange" TechnicalProfileReferenceId="AAD-UserWriteUsingAlternativeSecurityId" /> </ClaimsExchanges> </OrchestrationStep> --> <!-- 直接跳去颁发令牌 --> <OrchestrationStep Order="3" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" />
2. 调整第三方身份提供商技术配置文件的输出声明
打开第三方身份提供商的技术配置文件(比如Google-OAUTH),去掉和创建本地用户相关的声明转换,只保留必要的用户信息声明即可:
<TechnicalProfile Id="Google-OAUTH"> <DisplayName>Google</DisplayName> <Protocol Name="OAuth2" /> <Metadata> <Item Key="ProviderName">google</Item> <Item Key="authorization_endpoint">https://accounts.google.com/o/oauth2/v2/auth</Item> <Item Key="AccessTokenEndpoint">https://www.googleapis.com/oauth2/v4/token</Item> <Item Key="ClaimsEndpoint">https://www.googleapis.com/oauth2/v3/userinfo</Item> <Item Key="scope">email profile openid</Item> <Item Key="HttpBinding">POST</Item> <Item Key="UsePolicyInRedirectUri">false</Item> </Metadata> <CryptographicKeys> <Key Id="client_secret" StorageReferenceId="B2C_1A_GoogleClientSecret" /> </CryptographicKeys> <OutputClaims> <OutputClaim ClaimTypeReferenceId="issuerUserId" PartnerClaimType="sub" /> <OutputClaim ClaimTypeReferenceId="email" PartnerClaimType="email" /> <OutputClaim ClaimTypeReferenceId="givenName" PartnerClaimType="given_name" /> <OutputClaim ClaimTypeReferenceId="surname" PartnerClaimType="family_name" /> <OutputClaim ClaimTypeReferenceId="displayName" PartnerClaimType="name" /> <OutputClaim ClaimTypeReferenceId="identityProvider" DefaultValue="google.com" /> </OutputClaims> <OutputClaimsTransformations> <OutputClaimsTransformation ReferenceId="CreateRandomUPNUserName" /> <OutputClaimsTransformation ReferenceId="CreateUserPrincipalName" /> <OutputClaimsTransformation ReferenceId="CreateAlternativeSecurityId" /> <!-- 删掉CreateSubjectClaimFromAlternativeSecurityId这类和创建用户相关的转换 --> </OutputClaimsTransformations> <UseTechnicalProfileForSessionManagement ReferenceId="SM-SocialLogin" /> </TechnicalProfile>
3. 验证要点
测试时确认:
- 本地账户登录页无注册按钮,访问注册路径会被重定向到登录页。
- 用第三方账户首次登录后,AD B2C用户池无新增用户记录,同时能正常获取ID令牌。
排查小技巧
- 如果策略部署报错,检查是不是删除步骤后导致后续流程引用了不存在的声明,补全必要声明或调整依赖逻辑即可。
- 要是联合账户仍创建了用户,再仔细核对用户旅程里有没有漏删
AAD-UserWriteUsingAlternativeSecurityId相关的步骤。
内容的提问来源于stack exchange,提问作者Sudhir Kumar
相关产品推荐
相关产品推荐

