关于UserJourney/PreserveOriginalAssertion的技术问询:该元素存在于多个示例中却无说明且缺失于参考文档
PreserveOriginalAssertion Element in Azure AD B2C Custom Policies? Great question—this is one of those underdocumented elements that pops up in Azure AD B2C custom policy examples but flies under the official documentation radar. Let’s break down what it does, when to use it, and key technical details:
Core Definition
PreserveOriginalAssertion is a boolean configuration element for Azure AD B2C user journeys that controls whether the full original authentication assertion (from either ROPC validation or a federated identity provider) is retained throughout the user journey.
By default, B2C only processes and maps the specific claims you define in your policy (e.g., name, email) and discards the rest of the original assertion. When set to true, it preserves the entire raw assertion for use in subsequent orchestration steps or custom logic.
Common Use Cases
You’ll typically want to enable this element in these scenarios:
- ROPC Flow: When you need to pass the full ROPC authentication assertion to downstream orchestration steps (e.g., custom token enrichment, additional validation checks that rely on the complete assertion data).
- Federated Authentication: If your application or custom logic requires access to all claims returned by the identity provider (not just the ones you explicitly map in your policy), preserving the original assertion ensures no data is lost.
- Debugging: Temporarily enabling it can help troubleshoot issues with assertion data not being mapped correctly, by letting you inspect the full raw assertion content.
Technical Behavior
- It’s a direct child element of the
<UserJourney>node in your custom policy XML. - When set to
<PreserveOriginalAssertion>true</PreserveOriginalAssertion>, B2C stores the raw assertion (either a JWT or SAML token, depending on the auth method) in an internal claim (usually accessible via theoriginalAssertionkey—you’ll need to define this claim in your policy’s<ClaimsSchema>to use it). - If not explicitly set, the default behavior is
false—the original assertion is discarded after B2C extracts the mapped claims.
Example Configuration
Here’s how you’d add it to an ROPC user journey:
<UserJourney Id="SignInWithResourceOwnerPasswordCredentials"> <PreserveOriginalAssertion>true</PreserveOriginalAssertion> <OrchestrationSteps> <!-- Your orchestration steps for ROPC validation, claim mapping, token issuance, etc. --> </OrchestrationSteps> </UserJourney>
To access the preserved assertion, you’ll also need to define the corresponding claim in your <ClaimsSchema>:
<ClaimsSchema> <ClaimType Id="originalAssertion"> <DisplayName>Original Authentication Assertion</DisplayName> <DataType>string</DataType> <AdminHelpText>Stores the full original assertion from the authentication provider</AdminHelpText> </ClaimType> </ClaimsSchema>
内容的提问来源于stack exchange,提问作者Jakub Bochenski

