You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Terraform或其他IaC工具在现有Azure B2C租户创建应用注册与用户流?

针对Azure B2C租户的IaC实现方案

一、Terraform创建B2C租户下的应用注册

可以用azuread_application资源,但核心是要把AzureAD Provider指向你的B2C租户,而非主租户。

配置Provider时,指定B2C租户ID,同时使用拥有B2C租户权限的身份(服务主体或用户)完成认证:

provider "azuread" {
  tenant_id = "<你的B2C租户ID>"
  # 可通过环境变量、服务主体信息等配置认证,示例:
  # client_id     = var.client_id
  # client_secret = var.client_secret
}

resource "azuread_application" "b2c_app" {
  display_name      = "B2C业务应用"
  sign_in_audience  = "AzureADandPersonalMicrosoftAccount" # 适配B2C场景的受众范围
  # 根据业务需求配置重定向URI、API权限等
  web {
    redirect_uris = ["https://your-app-domain.com/auth/callback"]
  }
}

注意:用于Terraform认证的身份,需要在B2C租户中拥有Application Administrator或足够的应用注册权限。

二、用户流的IaC实现

Terraform方案

目前AzureRM Provider没有专门的用户流资源,但可以通过azurerm_resource_template_deployment调用ARM模板间接创建:

resource "azurerm_resource_template_deployment" "b2c_user_flow" {
  name                = "b2c-user-flow-deploy"
  resource_group_name = "<B2C租户对应的资源组名>"
  template_content = jsonencode({
    "$schema" = "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#"
    "contentVersion" = "1.0.0.0"
    "resources" = [
      {
        "type": "Microsoft.AzureActiveDirectory/b2cDirectories/userFlows",
        "apiVersion": "2021-04-01",
        "name": "<B2C租户名称>/B2C_1_signup_signin",
        "properties": {
          "userFlowType": "signUpOrSignIn",
          "userFlowTypeVersion": "1.0.0",
          "identityProviders": [
            {
              "clientId": "LocalAccountAuthentication",
              "name": "LocalAccountAuthentication",
              "type": "IdentityProvider"
            }
          ],
          "userAttributes": [
            {
              "name": "displayName",
              "required": true
            }
          ],
          "localAccounts": {
            "passwordResetEnabled": true,
            "usernameAuthentication": {
              "usernameAttribute": "userPrincipalName"
            }
          }
        }
      }
    ]
  })
}

替换模板中的租户名称、用户流名称等参数即可适配你的场景。

其他简便方案

1. Azure CLI脚本

用Azure CLI的B2C专用命令快速创建用户流,适合轻量场景:

# 登录到目标B2C租户
az login --tenant <B2C租户ID>
# 创建注册登录型用户流
az ad b2c user-flow create --resource-group <资源组名> --name B2C_1_signup_signin --type SignUpOrSignIn --identity-providers LocalAccountAuthentication

2. Bicep

Bicep对ARM模板做了语法简化,编写用户流定义更直观:

resource b2cUserFlow 'Microsoft.AzureActiveDirectory/b2cDirectories/userFlows@2021-04-01' = {
  parent: b2cDirectory // 指向已存在的B2C目录资源
  name: 'B2C_1_signup_signin'
  properties: {
    userFlowType: 'signUpOrSignIn'
    userFlowTypeVersion: '1.0.0'
    identityProviders: [
      {
        clientId: 'LocalAccountAuthentication'
        name: 'LocalAccountAuthentication'
        type: 'IdentityProvider'
      }
    ]
    userAttributes: [
      {
        name: 'displayName'
        required: true
      }
    ]
    localAccounts: {
      passwordResetEnabled: true
      usernameAuthentication: {
        usernameAttribute: 'userPrincipalName'
      }
    }
  }
}

通过az deployment group create命令即可部署该Bicep文件。

内容的提问来源于stack exchange,提问作者noctis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 10:15:58