You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure B2C用户令牌中添加Group声明?

Azure B2C 令牌中添加Group声明问题排查与解决

核心前提

Azure B2C 内置用户流不支持通过应用清单的"groupMembershipClaims": "All"配置返回组声明,必须通过自定义策略实现。针对你遇到的自定义策略配置后声明未出现在令牌中的问题,按以下步骤排查:


1. 确认ClaimType定义规范

在TrustFrameworkExtensions.xml或TrustFrameworkBase.xml中,必须正确定义groups声明的类型为stringCollection,示例如下:

<ClaimType Id="groups">
  <DisplayName>用户所属组</DisplayName>
  <DataType>stringCollection</DataType>
  <UserHelpText>当前用户加入的组列表</UserHelpText>
</ClaimType>

2. 确保技术配置文件正确输出声明

如果是通过AAD用户读取技术配置文件获取组数据,需在对应技术配置文件中添加输出声明,示例:

<TechnicalProfile Id="AAD-UserReadUsingObjectId">
  <OutputClaims>
    <!-- 其他原有输出声明 -->
    <OutputClaim ClaimTypeReferenceId="groups" PartnerClaimType="extension_groups" />
    <!-- 若组数据存储在扩展属性中,PartnerClaimType需对应扩展属性名;若通过Graph API获取则按需调整 -->
  </OutputClaims>
</TechnicalProfile>

3. 依赖方(RP)策略必须显式输出声明

在你的登录/注册策略文件(如SignUpOrSignin.xml)的依赖方技术配置中,必须明确添加groups作为输出声明,否则不会写入令牌:

<RelyingParty>
  <DefaultUserJourney ReferenceId="SignUpOrSignIn" />
  <TechnicalProfile Id="PolicyProfile">
    <DisplayName>PolicyProfile</DisplayName>
    <Protocol Name="OpenIdConnect" />
    <OutputClaims>
      <!-- 其他已有声明(如sub、name等) -->
      <OutputClaim ClaimTypeReferenceId="groups" PartnerClaimType="groups" />
    </OutputClaims>
    <SubjectNamingInfo ClaimType="sub" />
  </TechnicalProfile>
</RelyingParty>

4. 验证声明传递链路

检查用户旅程的编排步骤,确保包含组声明的技术配置文件执行后,声明被传递到后续步骤直至依赖方策略。例如,在调用获取组的技术配置文件的编排步骤中,需设置ClaimsExchange并确保声明被保留。

5. 令牌解码验证

使用JWT解码工具解析生成的令牌,查看Payload部分是否存在groups数组。若Webhook中能收到数据但令牌中无,大概率是依赖方策略未配置输出声明。


内容的提问来源于stack exchange,提问作者lokanath das

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 08:12:53