You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置Azure AD B2C自定义SAML策略时遇ParseRelyingPartyInputClaimsAsync不支持错误

Azure AD B2C SAML自定义策略报错:ParseRelyingPartyInputClaimsAsync is not supported for Web.TPEngine.Providers.SamlProtocolProvider

问题原因

这个错误的核心触发点是:你的SAML依赖方(RP)策略中错误添加了<InputClaims>或<InputClaimsTransformations>节点——SAML协议提供者不支持解析依赖方层级的输入声明配置。

修复步骤

  1. 移除依赖方节点中的输入声明配置
    打开自定义策略的<RelyingParty>节点,检查是否存在<InputClaims>或<InputClaimsTransformations>区块,直接删除这些内容即可。

    错误配置示例:

    <RelyingParty>
      <DefaultUserJourney ReferenceId="SignUpOrSignIn" />
      <InputClaims>
        <InputClaim ClaimTypeReferenceId="email" />
      </InputClaims>
      <OutputClaims>
        <!-- 输出声明配置 -->
      </OutputClaims>
    </RelyingParty>
    

    修复后配置:

    <RelyingParty>
      <DefaultUserJourney ReferenceId="SignUpOrSignIn" />
      <OutputClaims>
        <!-- 输出声明配置 -->
      </OutputClaims>
    </RelyingParty>
    
  2. 正确传递初始声明(如需)
    如果需要在流程中使用初始声明,不要在依赖方节点配置,而是通过以下方式处理:

    • 从SAML AuthnRequest请求中直接提取声明(SAML协议本身会携带必要参数)
    • 在用户旅程的<OrchestrationStep>中通过声明转换规则处理
  3. 验证策略合规性
    使用Azure AD B2C内置的策略验证工具检查自定义策略的XML语法和配置逻辑,排除隐性错误。

内容的提问来源于stack exchange,提问作者Daniel Krzyczkowski

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 18:02:39