You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AzureAD Claims Mapping Policy在Terraform中配置后不生效

问题原因与解决方案

你创建了Claims Mapping Policy但没有将其关联到目标企业应用的服务主体,这是策略未生效的核心原因。Azure AD的声明映射策略必须绑定到服务主体后,才会在企业应用的属性和声明中显示并生效。

修正步骤

  1. 确认目标应用的服务主体
    创建azuread_application.MyApp时,Terraform会自动生成对应的服务主体,可通过azuread_application.MyApp.object_id获取其ID;也可以显式声明服务主体资源:

    resource "azuread_service_principal" "MyApp" {
      application_id = azuread_application.MyApp.application_id
    }
    
  2. 添加策略关联资源
    新增azuread_service_principal_policy_assignment资源,将声明映射策略绑定到服务主体:

    resource "azuread_service_principal_policy_assignment" "claims_mapping" {
      service_principal_id = azuread_application.MyApp.object_id # 或 azuread_service_principal.MyApp.id
      policy_id            = azuread_claims_mapping_policy.this.id
    }
    

完整修正代码示例

resource "azuread_application" "MyApp" {
  display_name = "MyApplication"
  # 你的其他应用配置...
}

resource "azuread_service_principal" "MyApp" {
  application_id = azuread_application.MyApp.application_id
}

resource "azuread_claims_mapping_policy" "this" {
  display_name = "Claims Mapping for ${azuread_application.MyApp.display_name}"
  definition = [
    jsonencode(
      {
        ClaimsMappingPolicy = {
          Version              = 1
          IncludeBasicClaimSet = true  
          ClaimsSchema = [
            {
              Source        = "user"
              ID            = "user.onpremisessamaccountname"
              SamlClaimType = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/onpremisessamaccountname" # 补充完整Claim类型
            }  
          ]
          ClaimsTransformation = [{  
            ID                   = "ToUppercase"
            TransformationMethod = "ToUppercase"
            InputParameters = [{  
                ID       = "Attribute"
                DataType = "string"
                Value    = "user.onpremisessamaccountname"  
              }]
            OutputClaims = [{
              ClaimTypeReferenceId    = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/onpremisessamaccountname"
              TransformationClaimType = "outputClaim"
            }]
          }]
        }
      }
    ) 
  ]
}

# 关键:绑定策略到服务主体
resource "azuread_service_principal_policy_assignment" "claims_mapping" {
  service_principal_id = azuread_service_principal.MyApp.id
  policy_id            = azuread_claims_mapping_policy.this.id
}

额外说明

  • 原代码中SamlClaimType仅填写了命名空间,未指定具体Claim类型(如/onpremisessamaccountname),会导致声明无法被正确识别,建议补充完整。
  • 执行terraform apply后,需等待数分钟(Azure AD策略同步存在延迟),再进入GUI查看企业应用的属性和声明即可看到配置内容。

内容的提问来源于stack exchange,提问作者Nea_Johny

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 00:56:09