如何修改Azure B2C自定义策略禁止社交登录注册
禁止Azure B2C社交登录注册的自定义策略修改方案
要实现禁止社交登录用户注册、仅允许已有社交用户登录的需求,你需要对现有用户旅程做以下核心修改:
- 移除社交用户注册相关步骤:删掉原流程中用于收集社交用户信息(步骤5)和创建新社交用户(步骤7)的环节,这两步是默认允许社交注册的关键。
- 新增错误校验步骤:在验证社交用户是否存在的步骤(步骤4)之后,添加一个校验逻辑——如果是社交登录且用户不存在(无
objectId),直接抛出错误提示。
修改后的完整用户旅程配置
<UserJourney Id="CustomSignUpOrSignIn"> <OrchestrationSteps> <OrchestrationStep Order="1" Type="CombinedSignInAndSignUp" ContentDefinitionReferenceId="api.signuporsignin"> <ClaimsProviderSelections> <ClaimsProviderSelection TargetClaimsExchangeId="AzureADCommonExchange" /> <ClaimsProviderSelection ValidationClaimsExchangeId="LocalAccountSigninEmailExchange" /> <ClaimsProviderSelection TargetClaimsExchangeId="ForgotPasswordExchange" /> </ClaimsProviderSelections> <ClaimsExchanges> <ClaimsExchange Id="LocalAccountSigninEmailExchange" TechnicalProfileReferenceId="SelfAsserted-LocalAccountSignin-Email" /> </ClaimsExchanges> </OrchestrationStep> <!-- Check if the user has selected to sign in using one of the social providers --> <OrchestrationStep Order="2" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimsExist" ExecuteActionsIf="true"> <Value>objectId</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="AzureADCommonExchange" TechnicalProfileReferenceId="AADCommon-OpenIdConnect" /> <ClaimsExchange Id="SignUpWithLogonEmailExchange" TechnicalProfileReferenceId="LocalAccountSignUpWithLogonEmail" /> <ClaimsExchange Id="ForgotPasswordExchange" TechnicalProfileReferenceId="ForgotPassword" /> </ClaimsExchanges> </OrchestrationStep> <OrchestrationStep Order="3" Type="InvokeSubJourney"> <Preconditions> <Precondition Type="ClaimsExist" ExecuteActionsIf="false"> <Value>isForgotPassword</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <JourneyList> <Candidate SubJourneyReferenceId="PasswordReset" /> </JourneyList> </OrchestrationStep> <!-- For social IDP authentication, attempt to find the user account in the directory. --> <OrchestrationStep Order="4" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimEquals" ExecuteActionsIf="true"> <Value>authenticationSource</Value> <Value>localAccountAuthentication</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="AADUserReadUsingAlternativeSecurityId" TechnicalProfileReferenceId="AAD-UserReadUsingAlternativeSecurityId-NoError" /> </ClaimsExchanges> </OrchestrationStep> <!-- 新增:校验社交用户是否存在,不存在则抛出错误 --> <OrchestrationStep Order="5" Type="ClaimsExchange"> <Preconditions> <!-- 如果是本地账户,跳过此步骤 --> <Precondition Type="ClaimEquals" ExecuteActionsIf="true"> <Value>authenticationSource</Value> <Value>localAccountAuthentication</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> <!-- 如果用户已存在(有objectId),跳过此步骤 --> <Precondition Type="ClaimsExist" ExecuteActionsIf="true"> <Value>objectId</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <!-- 使用SelfAsserted技术 profile抛出错误 --> <ClaimsExchange Id="SocialSignUpBlocked" TechnicalProfileReferenceId="SelfAsserted-SocialSignUpBlocked" /> </ClaimsExchanges> </OrchestrationStep> <!-- This step reads any user attributes that we may not have received when authenticating using ESTS so they can be sent in the token. --> <OrchestrationStep Order="6" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimEquals" ExecuteActionsIf="true"> <Value>authenticationSource</Value> <Value>socialIdpAuthentication</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="AADUserReadWithObjectId" TechnicalProfileReferenceId="AAD-UserReadUsingObjectId" /> </ClaimsExchanges> </OrchestrationStep> <OrchestrationStep Order="7" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" /> </OrchestrationSteps> <ClientDefinition ReferenceId="DefaultWeb" /> </UserJourney>
配套需要添加的SelfAsserted技术配置
你还需要在<ClaimsProviders>节点下添加一个用于展示错误的技术 profile,内容如下:
<ClaimsProvider> <DisplayName>Self Asserted</DisplayName> <TechnicalProfiles> <TechnicalProfile Id="SelfAsserted-SocialSignUpBlocked"> <DisplayName>Social Sign-Up Blocked</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ContentDefinitionReferenceId">api.selfasserted</Item> <!-- 隐藏继续按钮,只显示错误信息 --> <Item Key="showContinueButton">false</Item> <Item Key="showCancelButton">true</Item> </Metadata> <InputClaims> <!-- 传递用户的邮箱(可选,用于显示个性化错误) --> <InputClaim ClaimTypeReferenceId="email" /> </InputClaims> <OutputClaims> <!-- 这里不需要输出任何声明,只是展示错误 --> </OutputClaims> <ValidationTechnicalProfiles> <!-- 使用ValidationError技术 profile抛出错误 --> <ValidationTechnicalProfile ReferenceId="Validation-SocialSignUpBlocked" /> </ValidationTechnicalProfiles> </TechnicalProfile> <TechnicalProfile Id="Validation-SocialSignUpBlocked"> <DisplayName>Validation for Social Sign-Up Blocked</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.ClaimsTransformationProtocolProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <OutputClaims> <!-- 抛出自定义错误信息 --> <OutputClaim ClaimTypeReferenceId="errorMessage" DefaultValue="抱歉,不允许使用该社交账号注册,请使用已有账号登录或联系管理员。" /> </OutputClaims> <OutputClaimsTransformations> <OutputClaimsTransformation ReferenceId="CreateErrorMessage" /> </OutputClaimsTransformations> </TechnicalProfile> </TechnicalProfiles> </ClaimsProvider>
关键修改说明
- 移除原步骤5和7:这两步原本负责收集社交用户额外信息并创建新用户,直接删除即可阻断注册流程。
- 新增步骤5:通过前置条件判断仅对社交登录且无
objectId的用户触发,调用自定义的错误展示技术 profile。 - 自定义错误提示:通过
Validation-SocialSignUpBlocked技术 profile生成错误信息,用户会看到友好的提示而不是默认的系统错误。
内容的提问来源于stack exchange,提问作者Smith Dwayne
相关产品推荐
相关产品推荐

