You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure B2C自定义策略报错:Azure AD Provider不支持输出Claim 'role'

解决Azure B2C自定义策略上传SignUpOrSignin.xml时的"role"输出声明验证错误

错误原因解析

报错的核心问题是:你配置的AzureFunctions-WebHook技术配置文件中,输出声明role要么无法从Azure Function的响应中获取对应值,要么没有正确配置默认值规则,导致B2C无法识别该声明的有效性。

分步解决方法

1. 检查Azure Function的响应格式

确保你的Azure Function返回的JSON响应中,包含你在技术配置文件OutputClaim里指定的PartnerClaimType字段。比如你在配置里写的是:

<OutputClaim ClaimTypeReferenceId="role" PartnerClaimType="userRole" />

那Function必须返回类似这样的JSON结构:

{
  "userRole": "admin"
}

如果Function没有返回这个字段,B2C会判定该输出声明不被支持,触发验证报错。

2. 给输出声明添加默认值配置

如果存在部分用户无法通过Function获取到角色的场景(比如新注册用户还未分配角色),直接在OutputClaim标签里添加默认值属性即可解决报错:

<OutputClaim ClaimTypeReferenceId="role" PartnerClaimType="userRole" DefaultValue="guest" AlwaysUseDefaultValue="true" />

AlwaysUseDefaultValue="true"会告诉B2C:如果Function没有返回对应值,就使用指定的DefaultValue,而不是抛出验证错误。

3. 确认ClaimType定义存在

检查TrustFrameworkBase.xml或TrustFrameworkExtensions.xml中,是否已经定义了role这个声明类型,确保配置如下:

<ClaimType Id="role">
  <DisplayName>User Role</DisplayName>
  <DataType>string</DataType>
</ClaimType>

如果没有这个定义,B2C无法识别role声明,也会引发验证错误。

4. 确保依赖方策略包含role输出

在SignUpOrSignin.xml的RelyingParty节点下,要把role加入输出声明列表,这样最终的JWT令牌才会包含该字段:

<TechnicalProfile Id="PolicyProfile">
  <DisplayName>PolicyProfile</DisplayName>
  <Protocol Name="OpenIdConnect" />
  <OutputClaims>
    <!-- 保留其他默认输出声明 -->
    <OutputClaim ClaimTypeReferenceId="role" />
  </OutputClaims>
</TechnicalProfile>

内容的提问来源于stack exchange,提问作者Craig Martin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 05:47:34