如何在Azure B2C多租户Microsoft Entra自定义流程中获取登录邮箱
解决Azure B2C多租户Entra认证后无法获取用户邮箱的问题
以下是按优先级排序的排查和解决步骤:
1. 确认多租户Entra ID身份提供者请求了邮箱属性
在自定义策略的多租户AAD <ClaimsProvider> 配置中:
- 检查
<TechnicalProfile>的<Metadata>里的scope是否包含email(比如设置为openid profile email),确保向用户的源AAD请求了邮箱权限。 - 在
<OutputClaims>中添加邮箱声明映射:
注意:部分场景下源AAD返回的邮箱字段可能是<OutputClaim ClaimTypeReferenceId="email" PartnerClaimType="email" />mail,需根据实际返回值调整PartnerClaimType。
2. 验证声明映射与持久化配置
- 在策略的
<ClaimsSchema>中确认已定义email声明:<ClaimType Id="email"> <DisplayName>Email Address</DisplayName> <DataType>string</DataType> <UserHelpText>Email address of the user.</UserHelpText> <UserInputType>TextBox</UserInputType> </ClaimType> - 检查用户创建/更新的TechnicalProfile(如
AAD-UserWriteUsingAlternativeSecurityId),确保添加邮箱输出声明,让B2C将邮箱写入用户存储:<OutputClaim ClaimTypeReferenceId="email" />
3. 确认源Entra ID用户的邮箱属性存在
部分用户账户(如仅用手机号注册的Entra ID账户)可能未设置邮箱字段,先登录源Entra ID确认该用户的邮箱或mail属性非空,否则B2C无法获取有效数据。
4. 检查RelyingParty配置是否输出邮箱到客户端令牌
在策略的<RelyingParty>节点下的<OutputClaims>中,确保包含邮箱声明,这样才会将其加入返回给客户端的JWT:
<OutputClaim ClaimTypeReferenceId="email" />
5. 验证Graph权限的有效性
- 确认给
IdentityExperienceFramework应用授予的是应用权限(而非委托权限),且已完成管理员同意。 - 检查权限是否包含
User.ReadWrite.All或User.Read.All,避免权限不足导致无法写入邮箱到B2C用户对象。
内容的提问来源于stack exchange,提问作者Thierry Cot
相关产品推荐
相关产品推荐

