You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure B2C多租户Microsoft Entra自定义流程中获取登录邮箱

解决Azure B2C多租户Entra认证后无法获取用户邮箱的问题

以下是按优先级排序的排查和解决步骤:

1. 确认多租户Entra ID身份提供者请求了邮箱属性

在自定义策略的多租户AAD <ClaimsProvider> 配置中:

  • 检查<TechnicalProfile>的<Metadata>里的scope是否包含email(比如设置为openid profile email),确保向用户的源AAD请求了邮箱权限。
  • 在<OutputClaims>中添加邮箱声明映射:
    <OutputClaim ClaimTypeReferenceId="email" PartnerClaimType="email" />
    
    注意:部分场景下源AAD返回的邮箱字段可能是mail,需根据实际返回值调整PartnerClaimType。

2. 验证声明映射与持久化配置

  • 在策略的<ClaimsSchema>中确认已定义email声明:
    <ClaimType Id="email">
      <DisplayName>Email Address</DisplayName>
      <DataType>string</DataType>
      <UserHelpText>Email address of the user.</UserHelpText>
      <UserInputType>TextBox</UserInputType>
    </ClaimType>
    
  • 检查用户创建/更新的TechnicalProfile(如AAD-UserWriteUsingAlternativeSecurityId),确保添加邮箱输出声明,让B2C将邮箱写入用户存储:
    <OutputClaim ClaimTypeReferenceId="email" />
    

3. 确认源Entra ID用户的邮箱属性存在

部分用户账户(如仅用手机号注册的Entra ID账户)可能未设置邮箱字段,先登录源Entra ID确认该用户的邮箱或mail属性非空,否则B2C无法获取有效数据。

4. 检查RelyingParty配置是否输出邮箱到客户端令牌

在策略的<RelyingParty>节点下的<OutputClaims>中,确保包含邮箱声明,这样才会将其加入返回给客户端的JWT:

<OutputClaim ClaimTypeReferenceId="email" />

5. 验证Graph权限的有效性

  • 确认给IdentityExperienceFramework应用授予的是应用权限(而非委托权限),且已完成管理员同意。
  • 检查权限是否包含User.ReadWrite.All或User.Read.All,避免权限不足导致无法写入邮箱到B2C用户对象。

内容的提问来源于stack exchange,提问作者Thierry Cot

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 10:42:22