You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C自定义策略中获取newUser属性失败的问题咨询

Azure AD B2C自定义策略获取newUser属性排查方案

核心问题定位

newUser属性并非由SelfAsserted技术配置文件生成,而是由实际与Azure AD交互创建用户的技术配置文件自动生成,你的两种尝试未命中正确的配置节点,导致无法获取该属性。以下是具体排查和解决步骤:


1. 在正确的技术配置文件中声明输出

找到负责用户注册的核心技术配置文件,添加newUser作为输出声明:

  • 本地账号注册:找到LocalAccountSignUpWithLogonEmail技术配置文件,在<OutputClaims>节点中添加:
    <OutputClaim ClaimTypeReferenceId="newUser" />
    
  • 社交账号注册:找到AAD-UserWriteUsingAlternativeSecurityId技术配置文件,同样在<OutputClaims>中添加上述声明。

这些配置文件是直接与Azure AD交互创建用户的节点,newUser属性在此处生成,而非你之前修改的NewUserAccountUpdatePrimaryDetails(仅用于收集用户信息)。

2. 修正会话管理策略

若注册流程后还有后续步骤,确保会话管理不使用SM-Noop(该策略不会保存会话中的声明):
在注册核心技术配置文件的<UseTechnicalProfileForSessionManagement>节点中,替换为默认的会话管理策略:

<UseTechnicalProfileForSessionManagement ReferenceId="SM-AAD" />

这样newUser声明才能在整个流程中传递下去。

3. 完善声明定义与RelyingParty输出

  • 检查<ClaimsSchema>中是否已定义newUser类型:
    <ClaimType Id="newUser">
      <DisplayName>New User</DisplayName>
      <DataType>boolean</DataType>
    </ClaimType>
    
  • 在RelyingParty的PolicyProfile中确保输出声明配置正确:
    <OutputClaims>
      <OutputClaim ClaimTypeReferenceId="newUser" />
      <!-- 其他输出声明 -->
    </OutputClaims>
    

4. 排查流程中的声明传递

若注册后还有补充信息填写等步骤,需在中间的技术配置文件中添加newUser作为输入声明,确保属性传递不中断:
比如在NewUserAccountUpdatePrimaryDetails的<InputClaims>中添加:

<InputClaim ClaimTypeReferenceId="newUser" />

内容的提问来源于stack exchange,提问作者John Doe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 06:42:07