You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C自定义声明无法在登录令牌返回的问题求助

Azure AD B2C 自定义声明无法返回问题排查

问题描述

我已将B2C应用ID和对象ID添加到TrustFrameworkExtensions.xml文件中,接着在**注册流程(SignUpWithMFA)**的RelyingParty节点内添加了以下配置:

<PersistedClaims>
  <PersistedClaim ClaimTypeReferenceId="extension_signupGuid" DefaultValue="SomeRandomValue" AlwaysUseDefaultValue="true"/>
</PersistedClaims>

随后在**登录流程(SignInWithForgetPasswordAndMFA)**的RelyingParty节点内添加:

<OutputClaim ClaimTypeReferenceId="extension_signupGuid" />

原本预期登录时会返回名为signupGuid、值为SomeRandomValue的额外声明,但实际并未返回,目前已无排查思路。

更新补充

我已在自定义策略中定义了该声明类型:

<ClaimType Id="extension_signupGuid">
  <DataType>string</DataType>
</ClaimType>

我清楚如何获取令牌,当前仅通过拉取声明列表测试该声明是否返回,核心问题是无法将自定义声明添加到用户令牌中。我原以为只需在RelyingParty的PolicyProfile里添加extension_signupGuid作为输出声明即可,示例配置如下:

<RelyingParty>
  <DefaultUserJourney ReferenceId="SignInWithForgetPasswordAndMFA" />
  <UserJourneyBehaviors>...</UserJourneyBehaviors>

  <TechnicalProfile Id="PolicyProfile">
    <DisplayName>PolicyProfile</DisplayName>
    <Protocol Name="OpenIdConnect" />
    <OutputClaims>
      ...
      <OutputClaim ClaimTypeReferenceId="extension_signupGuid" />   
    </OutputClaims>
    <SubjectNamingInfo ClaimType="sub" />
  </TechnicalProfile>
</RelyingParty>

但有人告诉我,即使注册时已持久化该声明,仍需通过REST调用才能获取,请问这是否必要?


内容的提问来源于stack exchange,提问作者CraigM

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 17:07:16