You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为Azure B2C配置通用SAML联合的PartnerEntity?

Azure B2C 通用SAML联合策略中PartnerEntity的通用配置方案

我们有一款以Azure B2C作为身份提供商(IDP)的SaaS应用,当前通过SAML联合实现企业单点登录(SSO)。目前的做法是为每个企业单独配置ClaimsProvider,每个配置里都要指定具体的PartnerEntity,示例代码如下:

<TechnicalProfile Id="Contoso-SAML2">
      <DisplayName>Contoso</DisplayName>
      <Description>Login with your AD FS account</Description>
      <Protocol Name="SAML2"/>
      <Metadata>
        <Item Key="RequestsSigned">false</Item>
        <Item Key="ResponsesSigned">false</Item>
        <Item Key="WantsEncryptedAssertions">false</Item>
        <Item Key="PartnerEntity">https://login.microsoftonline.com/..tenantid../federationmetadata/2007-06/federationmetadata.xml?appid=..appid..</Item>
      </Metadata>
      <CryptographicKeys>
        <Key Id="SamlMessageSigning" StorageReferenceId="B2C_1A_SAMLSigningCert"/>
      </CryptographicKeys>
      ...
    </TechnicalProfile>

我们希望创建通用的联合策略,让PartnerEntity可以通用配置,不用为每个外部合作伙伴单独添加技术配置文件,当前模板中PartnerEntity的位置不知道该如何填写,模板示例如下:

<ClaimsProvider>
  <DisplayName>SAML</DisplayName>
  <TechnicalProfiles>
    <TechnicalProfile Id="Contoso-SAML2">
      <DisplayName>SAML</DisplayName>
      <Description>Login with your AD FS account</Description>
      <Protocol Name="SAML2"/>
      <Metadata>
        <Item Key="RequestsSigned">false</Item>
        <Item Key="ResponsesSigned">false</Item>
        <Item Key="WantsEncryptedAssertions">false</Item>
        <Item Key="PartnerEntity"> what to add here for generic ??? </Item>
      </Metadata>
      <CryptographicKeys>
        <Key Id="SamlMessageSigning" StorageReferenceId="B2C_1A_SAMLSigningCert"/>
      </CryptographicKeys>
      ...
    </TechnicalProfile>
  </TechnicalProfiles>
</ClaimsProvider>

通用配置方案

Azure B2C无法直接设置固定的通用PartnerEntity值,而是需要通过动态声明传递+元数据地址引用的方式实现通用SAML联合策略,具体步骤如下:

  1. 移除固定的PartnerEntity项,改用MetadataAddress来动态指定IDP元数据地址
  2. 添加输入声明,用于接收依赖方应用发起请求时传入的目标企业SAML元数据URL
  3. 在Metadata中使用声明占位符,将动态传入的元数据地址绑定到配置中

修改后的通用技术配置文件示例:

<ClaimsProvider>
  <DisplayName>Generic SAML SSO</DisplayName>
  <TechnicalProfiles>
    <TechnicalProfile Id="Generic-SAML2">
      <DisplayName>Enterprise SAML Login</DisplayName>
      <Description>Login with your enterprise SAML account</Description>
      <Protocol Name="SAML2"/>
      <!-- 定义输入声明,接收外部传入的IDP元数据URL -->
      <InputClaims>
        <InputClaim ClaimTypeReferenceId="IdpMetadataUrl" Required="true"/>
      </InputClaims>
      <Metadata>
        <Item Key="RequestsSigned">false</Item>
        <Item Key="ResponsesSigned">false</Item>
        <Item Key="WantsEncryptedAssertions">false</Item>
        <!-- 通过声明占位符动态获取元数据地址,替代固定的PartnerEntity -->
        <Item Key="MetadataAddress">{Claim:IdpMetadataUrl}</Item>
      </Metadata>
      <CryptographicKeys>
        <Key Id="SamlMessageSigning" StorageReferenceId="B2C_1A_SAMLSigningCert"/>
      </CryptographicKeys>
      <IncludeInSso>true</IncludeInSso>
      ...
    </TechnicalProfile>
  </TechnicalProfiles>
</ClaimsProvider>

关键说明

  • MetadataAddress是Azure B2C用来指定SAML IDP元数据地址的标准配置项,支持使用声明占位符{Claim:ClaimName}动态取值
  • 依赖方应用在发起认证请求时,需要将对应企业的SAML元数据URL作为IdpMetadataUrl声明传递给Azure B2C
  • 也可以通过传递IDP的实体ID(EntityId)结合元数据自动发现机制,但直接传递元数据URL更直接可靠

内容的提问来源于stack exchange,提问作者Rasmus Vesterskov F.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 10:40:55