You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure AD B2C中限制特定用户/组访问应用

如何在Azure AD B2C中限制特定用户/组访问Spring Boot应用

Azure AD B2C的访问控制逻辑和Azure AD略有不同,核心是通过用户流/自定义策略注入声明,再结合Spring Security的权限校验实现精准控制。以下是针对你的需求的具体操作步骤:

一、Azure AD B2C端配置

1. 按需求划分用户/组(可选,按组控制时需要)

  • 登录Azure门户进入你的AD B2C租户,左侧菜单选用户 -> 组
  • 新建两个组(比如AppA_Allowed_Users、AppB_Allowed_Users),分别将用户A、用户B加入对应组
  • 记录每个组的Object ID(组详情页可查看),后续Spring配置会用到

2. 配置用户流,注入必要声明

不管是按用户还是按组控制,都需要让ID令牌携带用户标识信息:

  • 进入AD B2C的用户流,选择你正在使用的登录/注册流
  • 切换到应用程序声明,勾选以下选项并保存:
    • 若按用户控制:勾选用户ID
    • 若按组控制:勾选组
  • 重新运行用户流,确保新生成的ID令牌包含上述声明

3. (可选)用应用角色实现更灵活控制

如果需要后续快速调整权限,推荐用应用角色:

  • 进入目标应用注册的应用角色,点击创建应用角色,分别创建AppA_Access、AppB_Access角色
  • 回到用户和组页面,给用户A分配AppA_Access角色,用户B分配AppB_Access角色

二、Spring Boot应用端配置

1. 确保依赖正确

在pom.xml中引入Azure AD B2C依赖:

<dependency>
    <groupId>com.azure.spring</groupId>
    <artifactId>azure-spring-boot-starter-active-directory-b2c</artifactId>
</dependency>

2. 基础配置(application.yml)

azure:
  activedirectory:
    b2c:
      tenant-id: <你的B2C租户ID>
      client-id: <你的应用注册ID>
      client-secret: <你的应用密钥>
      user-flows:
        sign-up-or-sign-in: <你的登录用户流名称,比如B2C_1_signup_signin>

3. 实现访问控制逻辑

方式一:直接按用户ID控制

@Configuration
@EnableWebSecurity
public class SecurityConfig extends AadB2cWebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        super.configure(http);
        http.authorizeRequests()
                // 仅允许用户A访问AppA接口
                .antMatchers("/appA/**").hasAuthority("<用户A的Object ID>")
                // 仅允许用户B访问AppB接口
                .antMatchers("/appB/**").hasAuthority("<用户B的Object ID>")
                .anyRequest().authenticated();
    }
}

注:用户的Object ID可在AD B2C用户详情页获取

方式二:按用户组控制

@Configuration
@EnableWebSecurity
public class SecurityConfig extends AadB2cWebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        super.configure(http);
        http.authorizeRequests()
                .antMatchers("/appA/**").hasAuthority("<AppA组的Object ID>")
                .antMatchers("/appB/**").hasAuthority("<AppB组的Object ID>")
                .anyRequest().authenticated();
    }

    // 自定义转换器,将ID令牌中的groups声明转为权限
    @Bean
    public GrantedAuthoritiesConverter grantedAuthoritiesConverter() {
        AadB2cGrantedAuthoritiesConverter converter = new AadB2cGrantedAuthoritiesConverter();
        converter.setAuthoritiesClaimName("groups");
        return converter;
    }
}

方式三:按应用角色控制

@Configuration
@EnableWebSecurity
public class SecurityConfig extends AadB2cWebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        super.configure(http);
        http.authorizeRequests()
                .antMatchers("/appA/**").hasRole("AppA_Access")
                .antMatchers("/appB/**").hasRole("AppB_Access")
                .anyRequest().authenticated();
    }

    @Bean
    public GrantedAuthoritiesConverter grantedAuthoritiesConverter() {
        AadB2cGrantedAuthoritiesConverter converter = new AadB2cGrantedAuthoritiesConverter();
        converter.setAuthoritiesClaimName("roles");
        converter.setAuthorityPrefix("ROLE_");
        return converter;
    }
}

三、测试验证

  • 用用户A登录后,访问/appB/**会被权限拦截,访问/appA/**正常
  • 用用户B登录后,访问/appA/**会被权限拦截,访问/appB/**正常

内容的提问来源于stack exchange,提问作者Aldo Inácio da Silva

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 01:40:08