You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何修改Azure B2C自定义策略禁止社交登录注册

禁止Azure B2C社交登录注册的自定义策略修改方案

要实现禁止社交登录用户注册、仅允许已有社交用户登录的需求,你需要对现有用户旅程做以下核心修改:

  1. 移除社交用户注册相关步骤:删掉原流程中用于收集社交用户信息(步骤5)和创建新社交用户(步骤7)的环节,这两步是默认允许社交注册的关键。
  2. 新增错误校验步骤:在验证社交用户是否存在的步骤(步骤4)之后,添加一个校验逻辑——如果是社交登录且用户不存在(无objectId),直接抛出错误提示。

修改后的完整用户旅程配置

<UserJourney Id="CustomSignUpOrSignIn">
  <OrchestrationSteps>
    <OrchestrationStep Order="1" Type="CombinedSignInAndSignUp" ContentDefinitionReferenceId="api.signuporsignin">
      <ClaimsProviderSelections>
        <ClaimsProviderSelection TargetClaimsExchangeId="AzureADCommonExchange" />
        <ClaimsProviderSelection ValidationClaimsExchangeId="LocalAccountSigninEmailExchange" />
        <ClaimsProviderSelection TargetClaimsExchangeId="ForgotPasswordExchange" />
      </ClaimsProviderSelections>
      <ClaimsExchanges>
        <ClaimsExchange Id="LocalAccountSigninEmailExchange" TechnicalProfileReferenceId="SelfAsserted-LocalAccountSignin-Email" />
      </ClaimsExchanges>
    </OrchestrationStep>
    <!-- Check if the user has selected to sign in using one of the social providers -->
    <OrchestrationStep Order="2" Type="ClaimsExchange">
      <Preconditions>
        <Precondition Type="ClaimsExist" ExecuteActionsIf="true">
          <Value>objectId</Value>
          <Action>SkipThisOrchestrationStep</Action>
        </Precondition>
      </Preconditions>
      <ClaimsExchanges>
        <ClaimsExchange Id="AzureADCommonExchange" TechnicalProfileReferenceId="AADCommon-OpenIdConnect" />
        <ClaimsExchange Id="SignUpWithLogonEmailExchange" TechnicalProfileReferenceId="LocalAccountSignUpWithLogonEmail" />
        <ClaimsExchange Id="ForgotPasswordExchange" TechnicalProfileReferenceId="ForgotPassword" />
      </ClaimsExchanges>
    </OrchestrationStep>
    <OrchestrationStep Order="3" Type="InvokeSubJourney">
      <Preconditions>
        <Precondition Type="ClaimsExist" ExecuteActionsIf="false">
          <Value>isForgotPassword</Value>
          <Action>SkipThisOrchestrationStep</Action>
        </Precondition>
      </Preconditions>
      <JourneyList>
        <Candidate SubJourneyReferenceId="PasswordReset" />
      </JourneyList>
    </OrchestrationStep>
    <!-- For social IDP authentication, attempt to find the user account in the directory. -->
    <OrchestrationStep Order="4" Type="ClaimsExchange">
      <Preconditions>
        <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
          <Value>authenticationSource</Value>
          <Value>localAccountAuthentication</Value>
          <Action>SkipThisOrchestrationStep</Action>
        </Precondition>
      </Preconditions>
      <ClaimsExchanges>
        <ClaimsExchange Id="AADUserReadUsingAlternativeSecurityId" TechnicalProfileReferenceId="AAD-UserReadUsingAlternativeSecurityId-NoError" />
      </ClaimsExchanges>
    </OrchestrationStep>
    <!-- 新增:校验社交用户是否存在,不存在则抛出错误 -->
    <OrchestrationStep Order="5" Type="ClaimsExchange">
      <Preconditions>
        <!-- 如果是本地账户,跳过此步骤 -->
        <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
          <Value>authenticationSource</Value>
          <Value>localAccountAuthentication</Value>
          <Action>SkipThisOrchestrationStep</Action>
        </Precondition>
        <!-- 如果用户已存在(有objectId),跳过此步骤 -->
        <Precondition Type="ClaimsExist" ExecuteActionsIf="true">
          <Value>objectId</Value>
          <Action>SkipThisOrchestrationStep</Action>
        </Precondition>
      </Preconditions>
      <ClaimsExchanges>
        <!-- 使用SelfAsserted技术 profile抛出错误 -->
        <ClaimsExchange Id="SocialSignUpBlocked" TechnicalProfileReferenceId="SelfAsserted-SocialSignUpBlocked" />
      </ClaimsExchanges>
    </OrchestrationStep>
    <!-- This step reads any user attributes that we may not have received when authenticating using ESTS so they can be sent 
      in the token. -->
    <OrchestrationStep Order="6" Type="ClaimsExchange">
      <Preconditions>
        <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
          <Value>authenticationSource</Value>
          <Value>socialIdpAuthentication</Value>
          <Action>SkipThisOrchestrationStep</Action>
        </Precondition>
      </Preconditions>
      <ClaimsExchanges>
        <ClaimsExchange Id="AADUserReadWithObjectId" TechnicalProfileReferenceId="AAD-UserReadUsingObjectId" />
      </ClaimsExchanges>
    </OrchestrationStep>
    <OrchestrationStep Order="7" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" />
  </OrchestrationSteps>
  <ClientDefinition ReferenceId="DefaultWeb" />
</UserJourney>

配套需要添加的SelfAsserted技术配置

你还需要在<ClaimsProviders>节点下添加一个用于展示错误的技术 profile,内容如下:

<ClaimsProvider>
  <DisplayName>Self Asserted</DisplayName>
  <TechnicalProfiles>
    <TechnicalProfile Id="SelfAsserted-SocialSignUpBlocked">
      <DisplayName>Social Sign-Up Blocked</DisplayName>
      <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
      <Metadata>
        <Item Key="ContentDefinitionReferenceId">api.selfasserted</Item>
        <!-- 隐藏继续按钮,只显示错误信息 -->
        <Item Key="showContinueButton">false</Item>
        <Item Key="showCancelButton">true</Item>
      </Metadata>
      <InputClaims>
        <!-- 传递用户的邮箱(可选,用于显示个性化错误) -->
        <InputClaim ClaimTypeReferenceId="email" />
      </InputClaims>
      <OutputClaims>
        <!-- 这里不需要输出任何声明,只是展示错误 -->
      </OutputClaims>
      <ValidationTechnicalProfiles>
        <!-- 使用ValidationError技术 profile抛出错误 -->
        <ValidationTechnicalProfile ReferenceId="Validation-SocialSignUpBlocked" />
      </ValidationTechnicalProfiles>
    </TechnicalProfile>

    <TechnicalProfile Id="Validation-SocialSignUpBlocked">
      <DisplayName>Validation for Social Sign-Up Blocked</DisplayName>
      <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.ClaimsTransformationProtocolProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
      <OutputClaims>
        <!-- 抛出自定义错误信息 -->
        <OutputClaim ClaimTypeReferenceId="errorMessage" DefaultValue="抱歉,不允许使用该社交账号注册,请使用已有账号登录或联系管理员。" />
      </OutputClaims>
      <OutputClaimsTransformations>
        <OutputClaimsTransformation ReferenceId="CreateErrorMessage" />
      </OutputClaimsTransformations>
    </TechnicalProfile>
  </TechnicalProfiles>
</ClaimsProvider>

关键修改说明

  • 移除原步骤5和7:这两步原本负责收集社交用户额外信息并创建新用户,直接删除即可阻断注册流程。
  • 新增步骤5:通过前置条件判断仅对社交登录且无objectId的用户触发,调用自定义的错误展示技术 profile。
  • 自定义错误提示:通过Validation-SocialSignUpBlocked技术 profile生成错误信息,用户会看到友好的提示而不是默认的系统错误。

内容的提问来源于stack exchange,提问作者Smith Dwayne

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 21:08:10