You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C自定义策略:如何让用户选择MFA验证方式

合并Azure AD B2C自定义策略实现MFA方式自主选择

核心思路

把现有两套独立策略的MFA验证逻辑整合到同一用户旅程中,通过自定义选择页面收集用户的MFA方式偏好,再根据选择分支执行对应的验证流程。

具体实现步骤

1. 添加自定义声明存储用户选择

在策略的<BuildingBlocks>下的<ClaimsSchema>中新增自定义声明,用于记录用户选的MFA方式:

<ClaimType Id="mfaMethod">
  <DisplayName>选择MFA验证方式</DisplayName>
  <DataType>string</DataType>
  <UserHelpText>请选择您要使用的MFA验证方式</UserHelpText>
  <UserInputType>SingleSelectDropdown</UserInputType>
  <Restriction>
    <Enumeration Text="Microsoft Authenticator应用" Value="TOTP" />
    <Enumeration Text="手机/邮箱验证码" Value="OTP" />
  </Restriction>
</ClaimType>

如果想用按钮选择而非下拉框,声明保持string类型即可,后续在自定义页面用按钮提交对应值。

2. 创建MFA选择的自定义页面

制作符合Azure AD B2C页面模板规范的HTML页面,包含两个选择按钮,示例核心代码:

<div class="choice-group">
  <button id="totpBtn" name="mfaMethod" value="TOTP" type="submit">使用Microsoft Authenticator</button>
  <button id="otpBtn" name="mfaMethod" value="OTP" type="submit">使用手机/邮箱验证码</button>
</div>

接着在策略的<ContentDefinitions>中配置该页面:

<ContentDefinition Id="api.mfa.select">
  <LoadUri>https://你的自定义页面域名/mfa-select.html</LoadUri>
  <RecoveryUri>~/common/default_page_error.html</RecoveryUri>
  <DataUri>urn:com:microsoft:aad:b2c:elements:contract:selfasserted:2.1.0</DataUri>
  <Metadata>
    <Item Key="DisplayName">MFA方式选择</Item>
  </Metadata>
</ContentDefinition>

3. 配置显示选择页面的技术配置文件

在<ClaimsProviders>下添加SelfAsserted类型的技术配置文件,用于渲染选择页面并收集用户选择:

<ClaimsProvider>
  <DisplayName>MFA选择</DisplayName>
  <TechnicalProfiles>
    <TechnicalProfile Id="SelfAsserted-MfaSelect">
      <DisplayName>选择MFA验证方式</DisplayName>
      <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
      <Metadata>
        <Item Key="ContentDefinitionReferenceId">api.mfa.select</Item>
        <Item Key="UserMessageIfClaimsTransformationBooleanValueIsNotEqual">请选择一种MFA验证方式</Item>
      </Metadata>
      <OutputClaims>
        <OutputClaim ClaimTypeReferenceId="mfaMethod" Required="true" />
      </OutputClaims>
      <ValidationTechnicalProfiles>
        <!-- 仅收集选择,无需额外验证 -->
      </ValidationTechnicalProfiles>
    </TechnicalProfile>
  </TechnicalProfiles>
</ClaimsProvider>

4. 修改用户旅程,添加分支逻辑

调整现有用户旅程,在外部IDP认证步骤后加入MFA选择环节,再根据用户选择分支到对应验证流程:

<UserJourney Id="SignInWithExternalIdpAndMfaChoice">
  <OrchestrationSteps>
    <!-- 步骤1:外部IDP认证 -->
    <OrchestrationStep Order="1" Type="CombinedSignInAndSignUp" ContentDefinitionReferenceId="api.signuporsignin">
      <ClaimsProviderSelections>
        <!-- 配置你的外部IDP,比如Google、Facebook等 -->
        <ClaimsProviderSelection TargetClaimsExchangeId="GoogleExchange" />
      </ClaimsProviderSelections>
      <ClaimsExchanges>
        <ClaimsExchange Id="GoogleExchange" TechnicalProfileReferenceId="Google-OAUTH" />
      </ClaimsExchanges>
    </OrchestrationStep>

    <!-- 步骤2:处理外部IDP返回的声明 -->
    <OrchestrationStep Order="2" Type="ClaimsExchange">
      <Preconditions>
        <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
          <Value>authenticationSource</Value>
          <Value>localAccountAuthentication</Value>
          <Action>SkipThisOrchestrationStep</Action>
        </Precondition>
      </Preconditions>
      <ClaimsExchanges>
        <ClaimsExchange Id="AADUserReadUsingAlternativeSecurityId" TechnicalProfileReferenceId="AAD-UserReadUsingAlternativeSecurityId-NoError" />
      </ClaimsExchanges>
    </OrchestrationStep>

    <!-- 步骤3:显示MFA选择页面 -->
    <OrchestrationStep Order="3" Type="ClaimsExchange">
      <ClaimsExchanges>
        <ClaimsExchange Id="MfaSelectExchange" TechnicalProfileReferenceId="SelfAsserted-MfaSelect" />
      </ClaimsExchanges>
    </OrchestrationStep>

    <!-- 步骤4:分支到TOTP验证 -->
    <OrchestrationStep Order="4" Type="ClaimsExchange">
      <Preconditions>
        <Precondition Type="ClaimEquals" ExecuteActionsIf="false">
          <Value>mfaMethod</Value>
          <Value>TOTP</Value>
          <Action>SkipThisOrchestrationStep</Action>
        </Precondition>
      </Preconditions>
      <ClaimsExchanges>
        <ClaimsExchange Id="TOTPVerifyExchange" TechnicalProfileReferenceId="TOTP-Verify" />
      </ClaimsExchanges>
    </OrchestrationStep>

    <!-- 步骤5:分支到OTP验证 -->
    <OrchestrationStep Order="5" Type="ClaimsExchange">
      <Preconditions>
        <Precondition Type="ClaimEquals" ExecuteActionsIf="false">
          <Value>mfaMethod</Value>
          <Value>OTP</Value>
          <Action>SkipThisOrchestrationStep</Action>
        </Precondition>
      </Preconditions>
      <ClaimsExchanges>
        <ClaimsExchange Id="OTPVerifyExchange" TechnicalProfileReferenceId="OTP-Verify" />
      </ClaimsExchanges>
    </OrchestrationStep>

    <!-- 步骤6:完成认证,返回令牌 -->
    <OrchestrationStep Order="6" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" />
  </OrchestrationSteps>
  <ClientDefinition ReferenceId="DefaultWeb" />
</UserJourney>

5. 迁移原有MFA验证的技术配置文件

把你现有两套策略中的TOTP验证(如TOTP-Verify)和OTP验证(如OTP-Verify)的技术配置文件完整迁移到合并后的策略中,确保ID与用户旅程中的引用一致。

6. 测试与调试

  • 将修改后的策略上传到Azure AD B2C租户
  • 使用测试用户登录,验证外部IDP认证后是否显示MFA选择页面
  • 分别选择两种方式,确认能否正常完成MFA验证并获取令牌

内容的提问来源于stack exchange,提问作者anemoneyy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 00:27:07