You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure DevOps流水线中用用户账户自动化创建Azure AD B2C租户及资源

解决方案:Azure DevOps流水线中使用用户账户创建Azure AD B2C租户及自动化参考

一、配置基于用户账户的Azure DevOps服务连接

要替代服务主体完成B2C租户创建,需创建使用用户凭据的Azure Resource Manager服务连接:

  • 进入Azure DevOps项目的项目设置 > 服务连接,点击新建服务连接
  • 选择Azure Resource Manager类型,接着选中**用户身份验证(基于浏览器)**选项
  • 点击下一步后,使用父目录Azure AD中拥有全局管理员权限的用户账户完成登录(该账户需具备创建B2C租户的权限)
  • 关联目标订阅,设置服务连接名称,勾选允许所有管道使用此连接,完成创建
  • 在Terraform流水线任务中指定使用该服务连接,Azure DevOps会自动注入身份凭据环境变量(如ARM_ACCESS_TOKEN、ARM_TENANT_ID),Terraform的Azure Provider会自动读取这些变量完成身份验证

二、Terraform核心配置示例

1. Azure Provider基础配置

无需手动指定服务主体参数,直接使用默认配置即可:

provider "azurerm" {
  features {}
  skip_provider_registration = true
}

2. 创建B2C租户

使用azurerm_aadb2c_tenant资源,注意必须通过用户身份执行:

resource "azurerm_resource_group" "b2c_rg" {
  name     = "b2c-resource-group"
  location = "eastus"
}

resource "azurerm_aadb2c_tenant" "main" {
  name                = "myb2ctenant.onmicrosoft.com"
  location            = "United States"
  resource_group_name = azurerm_resource_group.b2c_rg.name
  sku_name            = "PremiumP1"
}

3. 注册IEF相关应用

创建B2C租户内的Identity Experience Framework核心应用:

# IdentityExperienceFramework应用
resource "azurerm_aadb2c_application" "ief" {
  name                = "IdentityExperienceFramework"
  resource_group_name = azurerm_resource_group.b2c_rg.name
  tenant_id           = azurerm_aadb2c_tenant.main.id
  identifier_uris     = ["https://${azurerm_aadb2c_tenant.main.name}/IdentityExperienceFramework"]
  web {
    redirect_uris = ["https://${azurerm_aadb2c_tenant.main.name}/token"]
  }
}

# ProxyIdentityExperienceFramework应用
resource "azurerm_aadb2c_application" "proxy_ief" {
  name                = "ProxyIdentityExperienceFramework"
  resource_group_name = azurerm_resource_group.b2c_rg.name
  tenant_id           = azurerm_aadb2c_tenant.main.id
  identifier_uris     = ["https://${azurerm_aadb2c_tenant.main.name}/ProxyIdentityExperienceFramework"]
  web {
    redirect_uris = ["https://${azurerm_aadb2c_tenant.main.name}/oauth2/authresp"]
  }
}

三、自定义策略流水线部署

通过Azure CLI任务在流水线中部署自定义策略,示例命令:

# 部署基础策略
az adb2c policy create --tenant myb2ctenant.onmicrosoft.com --definition-file ./policies/TrustFrameworkBase.xml --type TrustFrameworkBase

# 部署扩展策略
az adb2c policy create --tenant myb2ctenant.onmicrosoft.com --definition-file ./policies/TrustFrameworkExtensions.xml --type TrustFrameworkExtensions

# 部署用户流策略
az adb2c policy create --tenant myb2ctenant.onmicrosoft.com --definition-file ./policies/SignUpOrSignin.xml --type SignUpOrSignin

四、自动化关键注意事项

  • 创建B2C租户后,用于登录的用户账户会自动成为该租户的全局管理员,可直接用于后续应用权限配置、策略部署等操作
  • 后续管理B2C租户时,可创建B2C租户内的服务主体,用于非租户创建类的自动化操作
  • 确保流水线使用的用户账户在父目录Azure AD中具备足够权限,避免因权限不足导致操作失败

内容的提问来源于stack exchange,提问作者Spuneet

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 23:35:24