You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD中为注册应用JWT令牌添加onpremisessamaccountname声明失败求助

问题排查:无法在JWT令牌中获取onpremisessamaccountname声明

以下是你可能遗漏的配置项及对应解决步骤:

1. 修正Claims Mapping Policy的JSON语法错误

你提供的Policy JSON存在格式问题:"ID": "onpremisessamaccountname","SamlClaimType": "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier" 这一行的逗号后缺少空格,且如果不需要映射SAML声明,建议直接移除SamlClaimType字段以避免干扰JWT声明生成。

修正后的Policy示例:

$NewPolicy = @"
{
     "ClaimsMappingPolicy":  {
        "Version":  1,
        "IncludeBasicClaimSet":  true,
        "ClaimsSchema":  [
            {
                "Source":  "user",
                "ID":  "onpremisessamaccountname",
                "JwtClaimType":  "testsamaccountname"
            }
        ]
    }
}
"@
New-AzureADPolicy -Definition $NewPolicy -DisplayName "test_samaccountname_policy" -Type "ClaimsMappingPolicy" -IsOrganizationDefault $false

2. 确认用户对象存在onpremisessamaccountname属性

仅同步自本地AD的用户才会拥有onpremisessamaccountname属性,云原生用户该属性为空。可通过以下命令验证:

Get-AzureADUser -ObjectId <用户对象ID> | Select-Object OnPremisesSamAccountName

若该属性为空,令牌自然不会包含对应声明。

3. 检查令牌请求的范围参数

确保OpenID Connect请求的scope参数包含openid和profile(onpremisessamaccountname属于用户配置文件类属性,需要profile范围触发返回)。例如授权码流的请求URL需包含:
scope=openid profile

4. 验证策略与服务主体的绑定状态

执行以下命令确认策略已成功绑定到目标应用的服务主体:

Get-AzureADServicePrincipalPolicy -Id <应用服务主体对象ID>

若返回列表中无test_samaccountname_policy,需重新执行Add-AzureADServicePrincipalPolicy命令,注意使用服务主体的ObjectId而非应用ID。

5. 清除令牌缓存并重新获取令牌

Azure AD会缓存已生成的令牌,旧令牌不会自动更新新声明。需:

  • 注销用户会话并清除浏览器缓存,或使用隐身模式重新发起认证
  • 后端应用需清除本地令牌缓存,重新请求新令牌

6. 确认应用清单配置无冲突

确保应用清单中acceptMappedClaims已设为true,且未通过optionalClaims配置覆盖声明映射逻辑。若同时配置了optionalClaims,需检查是否存在冲突,或直接依赖Claims Mapping Policy即可。


内容的提问来源于stack exchange,提问作者Jenson

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 19:18:19