You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C中能否拒绝含用户身份信息及字典词的密码?

在Azure AD B2C中配置拒绝含个人信息及字典词的密码

可以实现这类自定义密码规则,你已部署的自定义密码验证器(基于自定义策略)是实现该需求的核心载体,具体配置方向如下:

  • 拒绝包含个人信息(名字、姓氏、用户名)的密码
    在自定义密码验证器的业务逻辑中,需要获取用户的givenName(名字)、surname(姓氏)、signInName(用户名)等属性,将密码与这些属性的多种变体(全小写、全大写、姓名组合等)做匹配校验。如果密码中包含任意一种个人信息变体,直接返回验证失败。
    示例伪代码逻辑:

    function validatePersonalInfo(password, userAttributes) {
      const personalValues = [
        userAttributes.givenName?.toLowerCase() || '',
        userAttributes.surname?.toLowerCase() || '',
        userAttributes.signInName?.toLowerCase() || '',
        `${userAttributes.givenName?.toLowerCase() || ''}${userAttributes.surname?.toLowerCase() || ''}`
      ].filter(val => val);
      
      const lowerPassword = password.toLowerCase();
      for (const val of personalValues) {
        if (lowerPassword.includes(val)) {
          return { isValid: false, errorMessage: "密码不能包含您的姓名或用户名信息" };
        }
      }
      return { isValid: true };
    }
    
  • 拒绝包含字典词的密码
    在验证器中集成常用弱密码字典(可自定义扩展词库),先对密码做标准化处理(转小写、移除特殊字符),再检查是否包含字典内的词汇。
    示例伪代码逻辑:

    const weakPasswordDictionary = ["password", "123456", "admin", "welcome", "qwerty"];
    
    function checkDictionaryWords(password) {
      const processedPassword = password.toLowerCase().replace(/[^a-z0-9]/g, '');
      for (const word of weakPasswordDictionary) {
        if (processedPassword.includes(word)) {
          return { isValid: false, errorMessage: "密码不能包含常见弱密码词汇" };
        }
      }
      return { isValid: true };
    }
    
  • 整合验证逻辑并配置策略
    将上述两个验证逻辑整合到已部署的自定义密码验证器函数中,确保在密码创建/重置的用户流程中触发该验证器。同时在自定义策略的技术配置文件里,确认已正确传递用户的个人属性到验证器,保证逻辑能获取到所需的用户数据。

内容的提问来源于stack exchange,提问作者codeshinobi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 02:19:57