You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C自定义策略:TOTP与SendGrid集成后注册二维码不显示及Claim缺失报错

问题诊断与修复方案

核心原因

注册流程里未初始化或传递totpIdentifier声明,导致CreateUriLabel这个ClaimsTransformation找不到该声明,触发PolicyException,进而二维码页面加载失败;而登录流程中该声明已正常生成或传递,因此运行无异常。

具体修复步骤

  • 检查策略的<BuildingBlocks><ClaimsSchema>节点,若未定义totpIdentifier声明,直接添加以下代码:
    <ClaimType Id="totpIdentifier">
      <DisplayName>TOTP Identifier</DisplayName>
      <DataType>string</DataType>
      <UserHelpText>TOTP认证的唯一标识</UserHelpText>
    </ClaimType>
    
  • 在注册流程的用户旅程中,需在调用CreateUriLabel转换前生成totpIdentifier的值。通常用用户的Object ID与租户ID组合生成,示例转换代码如下:
    <ClaimsTransformation Id="GenerateTotpIdentifier" TransformationMethod="FormatStringMultipleClaims">
      <InputClaims>
        <InputClaim ClaimTypeReferenceId="objectId" TransformationClaimType="inputClaim1" />
        <InputClaim ClaimTypeReferenceId="tenantId" TransformationClaimType="inputClaim2" />
      </InputClaims>
      <InputParameters>
        <InputParameter Id="stringFormat" Value="{0}@{1}" />
      </InputParameters>
      <OutputClaims>
        <OutputClaim ClaimTypeReferenceId="totpIdentifier" TransformationClaimType="outputClaim" />
      </OutputClaims>
    </ClaimsTransformation>
    
  • 将上述GenerateTotpIdentifier转换添加到注册流程对应的<TechnicalProfile>或<OrchestrationStep>中,确保在执行CreateUriLabel前完成totpIdentifier的赋值。
  • 核对注册流程的用户旅程,确认展示二维码的步骤中,totpIdentifier已正确传递到对应的显示控件或技术配置里。

验证方式

  • 重新上传修改后的扩展策略文件
  • 测试注册流程,确认二维码页面正常显示
  • 查看Application Insights,确认PolicyException不再出现

内容的提问来源于stack exchange,提问作者momin naveed

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 01:45:07