You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让Azure AD B2C自定义策略识别用户流生成的令牌?

解决Azure AD B2C用户流与自定义策略令牌互认问题

核心问题根源

用户流和自定义策略默认使用不同的应用ID与签名密钥,导致两边颁发的令牌无法互相验证;同时随意修改IdentityExperienceFramework(IEF)应用配置,会直接触发登录验证错误。

具体修复步骤

1. 统一令牌核心标识配置

  • 确保用户流与自定义策略使用**相同的用户主体标识(如Object ID)**作为令牌中的唯一用户ID,避免因标识格式不一致导致识别失败。
  • 检查自定义策略的RelyingParty节点,保证TokenIssuer的签名密钥与用户流使用的密钥一致:
    <RelyingParty>
      <DefaultUserJourney ReferenceId="ProfileEdit" />
      <TechnicalProfile Id="PolicyProfile">
        <DisplayName>PolicyProfile</DisplayName>
        <Protocol Name="OpenIdConnect" />
        <OutputClaims>
          <OutputClaim ClaimTypeReferenceId="displayName" />
          <OutputClaim ClaimTypeReferenceId="givenName" />
          <OutputClaim ClaimTypeReferenceId="surname" />
          <OutputClaim ClaimTypeReferenceId="email" />
          <OutputClaim ClaimTypeReferenceId="objectId" PartnerClaimType="sub"/>
          <OutputClaim ClaimTypeReferenceId="tenantId" AlwaysUseDefaultValue="true" DefaultValue="{Policy:TenantObjectId}" />
        </OutputClaims>
        <SubjectNamingInfo ClaimType="sub" />
      </TechnicalProfile>
    </RelyingParty>
    

2. 还原并正确配置IEF应用

  • 立即恢复IEF应用到初始配置(可参考Azure AD B2C自定义策略入门模板对应的应用设置),禁止随意修改其API权限或应用密钥。
  • 确认IEF应用已获得对ProxyIdentityExperienceFramework应用的user_impersonation委托权限,且已完成管理员同意。
  • 保证IEF应用的应用ID URI与自定义策略TrustFrameworkBase.xml中Metadata节点的配置完全匹配:
    <Item Key="client_id">你的IEF应用ID</Item>
    <Item Key="issuer">{tenant}.onmicrosoft.com/你的IEF应用ID</Item>
    

3. 配置自定义策略接受用户流令牌

在TrustFrameworkExtensions.xml中添加用于验证用户流令牌的技术配置文件,让自定义策略能识别用户流颁发的令牌:

<ClaimsProvider>
  <DisplayName>Azure AD B2C User Flow</DisplayName>
  <TechnicalProfiles>
    <TechnicalProfile Id="AADUserFlowTokenValidation">
      <DisplayName>User Flow Token Validation</DisplayName>
      <Protocol Name="OpenIdConnect" />
      <Metadata>
        <Item Key="METADATA">https://你的租户名.b2clogin.com/你的租户名.onmicrosoft.com/v2.0/.well-known/openid-configuration?p=你的用户流名称</Item>
        <Item Key="client_id">你的应用程序ID</Item>
        <Item Key="response_types">id_token</Item>
        <Item Key="scope">openid profile</Item>
        <Item Key="UsePolicyInRedirectUri">false</Item>
      </Metadata>
      <OutputClaims>
        <OutputClaim ClaimTypeReferenceId="objectId" PartnerClaimType="sub" />
        <OutputClaim ClaimTypeReferenceId="displayName" />
        <OutputClaim ClaimTypeReferenceId="email" />
      </OutputClaims>
      <OutputClaimsTransformations>
        <OutputClaimsTransformation ReferenceId="CreateRandomUPNUserName" />
        <OutputClaimsTransformation ReferenceId="CreateUserPrincipalName" />
        <OutputClaimsTransformation ReferenceId="CreateAlternativeSecurityId" />
      </OutputClaimsTransformations>
      <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" />
    </TechnicalProfile>
  </TechnicalProfiles>
</ClaimsProvider>

随后在自定义策略的用户旅程中添加该验证步骤,允许用户持用户流令牌直接进入账户修改流程。

4. 调整应用的令牌验证逻辑

  • 在你的应用中,将自定义策略的颁发者URL(格式:https://你的租户名.b2clogin.com/你的租户ID/v2.0/)加入可信颁发者列表。
  • 配置应用通过Azure AD B2C的元数据端点自动获取签名密钥,同时支持用户流与自定义策略的令牌验证,避免硬编码密钥。

关键注意事项

  • 所有与自定义策略相关的配置调整,均通过策略XML文件完成,禁止手动修改IEF应用的核心参数。
  • 先在Azure AD B2C门户验证自定义策略与用户流的互操作性,再部署到应用中测试。

内容的提问来源于stack exchange,提问作者Haha ahahah

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 19:02:16