You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何基于条件从Azure AD B2C自定义策略自动重定向到Auth0 IDP

在Azure AD B2C自定义策略中实现基于条件自动重定向到Auth0

需求背景

我们已通过自定义策略在Azure AD B2C中集成Auth0作为身份提供商(IDP),希望满足以下条件时自动重定向到Auth0登录页面,无需用户点击UI按钮:

  • idp值为none
  • connection值不为B2CLocalUser

当前流程会在UI上显示Auth0登录按钮,无法实现无交互的自动重定向,需调整自定义策略配置。

原UserJourney配置

<UserJourneys>
    <UserJourney Id="Internal" DefaultCpimIssuerTechnicalProfileReferenceId="JwtIssuer">
        <OrchestrationSteps>
            <OrchestrationStep Order="1" Type="ClaimsExchange">
                <ClaimsExchanges>
                    <ClaimsExchange Id="pre-hrd" TechnicalProfileReferenceId="SelfAsserted-EmailOrUsernameCollect" />
                </ClaimsExchanges>
            </OrchestrationStep>
            <OrchestrationStep Order="2" Type="ClaimsExchange">
                <Preconditions>
                    <Precondition Type="ClaimsExist" ExecuteActionsIf="true">
                        <Value>objectIdFromSession</Value>
                        <Action>SkipThisOrchestrationStep</Action>
                    </Precondition>
                </Preconditions>
                <ClaimsExchanges>
                    <ClaimsExchange Id="HRD" TechnicalProfileReferenceId="HRD_Api" />
                </ClaimsExchanges>
            </OrchestrationStep>
            <OrchestrationStep Order="3" Type="ClaimsExchange">
                <Preconditions>
                    <Precondition Type="ClaimsExist" ExecuteActionsIf="false">
                        <Value>objectIdFromSession</Value>
                        <Action>SkipThisOrchestrationStep</Action>
                    </Precondition>
                </Preconditions>
                <ClaimsExchanges>
                    <ClaimsExchange Id="SSO_HRD" TechnicalProfileReferenceId="HRD_Api_SSO" />
                </ClaimsExchanges>
            </OrchestrationStep>

            <OrchestrationStep Order="4" Type="CombinedSignInAndSignUp" ContentDefinitionReferenceId="api.signuporsignin">
                <Preconditions>
                    <Precondition Type="ClaimEquals" ExecuteActionsIf="false">
                        <Value>idp</Value>
                        <Value>none</Value>
                        <Action>SkipThisOrchestrationStep</Action>
                    </Precondition>
                    <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
                        <Value>connection</Value>
                        <Value>B2CLocalUser</Value>
                        <Action>SkipThisOrchestrationStep</Action>
                    </Precondition>
                </Preconditions>
                <ClaimsProviderSelections>                              
                    <ClaimsProviderSelection TargetClaimsExchangeId="Auth0Login" />             
                </ClaimsProviderSelections>                     
            </OrchestrationStep>

            <OrchestrationStep Order="5" Type="ClaimsExchange">
                <Preconditions>
                    <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
                        <Value>connection</Value>
                        <Value>B2CLocalUser</Value>
                        <Action>SkipThisOrchestrationStep</Action>
                    </Precondition>                      
                </Preconditions>
                <ClaimsExchanges>                                        
                    <ClaimsExchange Id="Auth0Login" TechnicalProfileReferenceId="Auth0-OID" />           
                </ClaimsExchanges>
            </OrchestrationStep>

            <OrchestrationStep Order="6" Type="ClaimsExchange">
                <Preconditions>
                    <Precondition Type="ClaimEquals" ExecuteActionsIf="false">
                        <Value>idp</Value>
                        <Value>none</Value>
                        <Action>SkipThisOrchestrationStep</Action>
                    </Precondition>              
                </Preconditions>
                <ClaimsExchanges>
                    <ClaimsExchange Id="SignUpWithLogonEmailExchange" TechnicalProfileReferenceId="LocalAccountSignUpWithLogonEmail" />
                </ClaimsExchanges>
            </OrchestrationStep>-->

            <OrchestrationStep Order="6" Type="ClaimsExchange">
                <Preconditions>
                    <Precondition Type="ClaimEquals" ExecuteActionsIf="false">
                        <Value>idp</Value>
                        <Value>costcoaad</Value>
                        <Action>SkipThisOrchestrationStep</Action>
                    </Precondition>
                    <Precondition Type="ClaimsExist" ExecuteActionsIf="true">
                        <Value>objectId</Value>
                        <Action>SkipThisOrchestrationStep</Action>
                    </Precondition>
                </Preconditions>
                <ClaimsExchanges>
                    <ClaimsExchange Id="HintedAzureADExchange" TechnicalProfileReferenceId="Client-AAD" />
                </ClaimsExchanges>
            </OrchestrationStep>

            <!-- further steps -->

        </OrchestrationSteps>
    </UserJourney>
</UserJourneys>

解决方案:修改第4步配置

将原第4步的CombinedSignInAndSignUp类型改为ClaimsExchange,并调整前置条件,直接触发Auth0的登录流程,实现无交互自动重定向。修改后的第4步配置如下:

<OrchestrationStep Order="4" Type="ClaimsExchange">
    <Preconditions>
        <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
            <Value>connection</Value>
            <Value>B2CLocalUser</Value>
            <Action>SkipThisOrchestrationStep</Action>
        </Precondition> 
        <Precondition Type="ClaimsExist" ExecuteActionsIf="true">
            <Value>objectId</Value>
            <Action>SkipThisOrchestrationStep</Action>
        </Precondition>
    </Preconditions>
    <ClaimsExchanges>
        <ClaimsExchange Id="Auth0Login" TechnicalProfileReferenceId="Auth0-OID" />
    </ClaimsExchanges>
</OrchestrationStep>

配置说明

  1. 步骤类型修改:从CombinedSignInAndSignUp(展示登录UI)改为ClaimsExchange(直接执行身份提供商的Claims交换),跳过UI展示环节。
  2. 前置条件调整:
    • 当connection为B2CLocalUser时,跳过该步骤,走本地用户登录流程。
    • 当objectId存在(用户已通过SSO登录)时,跳过该步骤,无需再次重定向。
  3. 自动触发重定向:满足条件时,直接执行Auth0-OID技术配置文件,自动跳转至Auth0登录页面。

内容的提问来源于stack exchange,提问作者Sachin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 20:24:55