Azure AD B2C自定义策略:如何让用户选择MFA验证方式
合并Azure AD B2C自定义策略实现MFA方式自主选择
核心思路
把现有两套独立策略的MFA验证逻辑整合到同一用户旅程中,通过自定义选择页面收集用户的MFA方式偏好,再根据选择分支执行对应的验证流程。
具体实现步骤
1. 添加自定义声明存储用户选择
在策略的<BuildingBlocks>下的<ClaimsSchema>中新增自定义声明,用于记录用户选的MFA方式:
<ClaimType Id="mfaMethod"> <DisplayName>选择MFA验证方式</DisplayName> <DataType>string</DataType> <UserHelpText>请选择您要使用的MFA验证方式</UserHelpText> <UserInputType>SingleSelectDropdown</UserInputType> <Restriction> <Enumeration Text="Microsoft Authenticator应用" Value="TOTP" /> <Enumeration Text="手机/邮箱验证码" Value="OTP" /> </Restriction> </ClaimType>
如果想用按钮选择而非下拉框,声明保持string类型即可,后续在自定义页面用按钮提交对应值。
2. 创建MFA选择的自定义页面
制作符合Azure AD B2C页面模板规范的HTML页面,包含两个选择按钮,示例核心代码:
<div class="choice-group"> <button id="totpBtn" name="mfaMethod" value="TOTP" type="submit">使用Microsoft Authenticator</button> <button id="otpBtn" name="mfaMethod" value="OTP" type="submit">使用手机/邮箱验证码</button> </div>
接着在策略的<ContentDefinitions>中配置该页面:
<ContentDefinition Id="api.mfa.select"> <LoadUri>https://你的自定义页面域名/mfa-select.html</LoadUri> <RecoveryUri>~/common/default_page_error.html</RecoveryUri> <DataUri>urn:com:microsoft:aad:b2c:elements:contract:selfasserted:2.1.0</DataUri> <Metadata> <Item Key="DisplayName">MFA方式选择</Item> </Metadata> </ContentDefinition>
3. 配置显示选择页面的技术配置文件
在<ClaimsProviders>下添加SelfAsserted类型的技术配置文件,用于渲染选择页面并收集用户选择:
<ClaimsProvider> <DisplayName>MFA选择</DisplayName> <TechnicalProfiles> <TechnicalProfile Id="SelfAsserted-MfaSelect"> <DisplayName>选择MFA验证方式</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" /> <Metadata> <Item Key="ContentDefinitionReferenceId">api.mfa.select</Item> <Item Key="UserMessageIfClaimsTransformationBooleanValueIsNotEqual">请选择一种MFA验证方式</Item> </Metadata> <OutputClaims> <OutputClaim ClaimTypeReferenceId="mfaMethod" Required="true" /> </OutputClaims> <ValidationTechnicalProfiles> <!-- 仅收集选择,无需额外验证 --> </ValidationTechnicalProfiles> </TechnicalProfile> </TechnicalProfiles> </ClaimsProvider>
4. 修改用户旅程,添加分支逻辑
调整现有用户旅程,在外部IDP认证步骤后加入MFA选择环节,再根据用户选择分支到对应验证流程:
<UserJourney Id="SignInWithExternalIdpAndMfaChoice"> <OrchestrationSteps> <!-- 步骤1:外部IDP认证 --> <OrchestrationStep Order="1" Type="CombinedSignInAndSignUp" ContentDefinitionReferenceId="api.signuporsignin"> <ClaimsProviderSelections> <!-- 配置你的外部IDP,比如Google、Facebook等 --> <ClaimsProviderSelection TargetClaimsExchangeId="GoogleExchange" /> </ClaimsProviderSelections> <ClaimsExchanges> <ClaimsExchange Id="GoogleExchange" TechnicalProfileReferenceId="Google-OAUTH" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤2:处理外部IDP返回的声明 --> <OrchestrationStep Order="2" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimEquals" ExecuteActionsIf="true"> <Value>authenticationSource</Value> <Value>localAccountAuthentication</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="AADUserReadUsingAlternativeSecurityId" TechnicalProfileReferenceId="AAD-UserReadUsingAlternativeSecurityId-NoError" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤3:显示MFA选择页面 --> <OrchestrationStep Order="3" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="MfaSelectExchange" TechnicalProfileReferenceId="SelfAsserted-MfaSelect" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤4:分支到TOTP验证 --> <OrchestrationStep Order="4" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimEquals" ExecuteActionsIf="false"> <Value>mfaMethod</Value> <Value>TOTP</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="TOTPVerifyExchange" TechnicalProfileReferenceId="TOTP-Verify" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤5:分支到OTP验证 --> <OrchestrationStep Order="5" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimEquals" ExecuteActionsIf="false"> <Value>mfaMethod</Value> <Value>OTP</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="OTPVerifyExchange" TechnicalProfileReferenceId="OTP-Verify" /> </ClaimsExchanges> </OrchestrationStep> <!-- 步骤6:完成认证,返回令牌 --> <OrchestrationStep Order="6" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" /> </OrchestrationSteps> <ClientDefinition ReferenceId="DefaultWeb" /> </UserJourney>
5. 迁移原有MFA验证的技术配置文件
把你现有两套策略中的TOTP验证(如TOTP-Verify)和OTP验证(如OTP-Verify)的技术配置文件完整迁移到合并后的策略中,确保ID与用户旅程中的引用一致。
6. 测试与调试
- 将修改后的策略上传到Azure AD B2C租户
- 使用测试用户登录,验证外部IDP认证后是否显示MFA选择页面
- 分别选择两种方式,确认能否正常完成MFA验证并获取令牌
内容的提问来源于stack exchange,提问作者anemoneyy
相关产品推荐
相关产品推荐

