You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure B2C电话验证页面限流提示未显示问题咨询

Azure AD B2C自定义策略MFA限流提示不显示问题

我们有一个仅支持注册的自定义策略,包含收集MFA电话号码的电话验证步骤,页面与官方示例基本一致。使用multifactor:1.2.5数据URI,已按照本地化字符串ID文档添加了error_tryagain、error_sms_throttled、error_phone_throttled、error_throttled、error_incorrect_code等错误本地化条目。

多次点击重发SMS验证码链接后,短信停止发送,Azure门户用户历史中显示错误提示:“当前请求过多,请稍后重试”,但该限流提示并未在页面上显示,而页面其他本地化功能均正常工作。请问是否遗漏了某些配置,或是该场景本就不会显示错误提示?

<!-- PhoneRegisterOrMFAPage -->
<ContentDefinition Id="api.partners.phoneRegisterOrMFAPage">
    <LoadUri>~/tenant/templates/AzureBlue/multifactor-1.0.0.cshtml</LoadUri>
    <RecoveryUri>~/common/default_page_error.html</RecoveryUri>
    <DataUri>urn:com:microsoft:aad:b2c:elements:contract:multifactor:1.2.5</DataUri>
    <Metadata>
        <Item Key="DisplayName">Multi-factor authentication page</Item>
    </Metadata>
</ContentDefinition>    



<TechnicalProfile Id="PhoneRegisterOrMFAPage">
    <DisplayName>PhoneFactor</DisplayName>
    <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.PhoneFactorProtocolProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
    <Metadata>
        <Item Key="ContentDefinitionReferenceId">api.partners.phoneRegisterOrMFAPage</Item>
        <!-- Setting the below to true, so the same profile can be used for phone MFA, or phone registration. Will avoid coming here when doing MFA and no phone -->
        <Item Key="ManualPhoneNumberEntryAllowed">true</Item>                           
        <Item Key="setting.authenticationMode">sms</Item>
    </Metadata>
    <InputClaimsTransformations>
        <InputClaimsTransformation ReferenceId="CreateUserIdForMFA" />
    </InputClaimsTransformations>
    <InputClaims>
        <InputClaim ClaimTypeReferenceId="userIdForMFA" PartnerClaimType="UserId" />
        <InputClaim ClaimTypeReferenceId="strongAuthenticationPhoneNumber" />
    </InputClaims>
    <OutputClaims>
        <OutputClaim ClaimTypeReferenceId="Verified.strongAuthenticationPhoneNumber" PartnerClaimType="Verified.OfficePhone" />
        <OutputClaim ClaimTypeReferenceId="newPhoneNumberEntered" PartnerClaimType="newPhoneNumberEntered" />
    </OutputClaims>
    <IncludeTechnicalProfile ReferenceId="AAD-Common" />
    <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" />
</TechnicalProfile>


<LocalizedResources Id="api.partners.phoneRegisterOrMFAPage.en">
    <LocalizedStrings>
        ...
        <LocalizedString ElementType="UxElement" StringId="error_tryagain">EN-The phone number you provided is busy or unavailable. Please check the number and try again.</LocalizedString>
        <LocalizedString ElementType="UxElement" StringId="error_sms_throttled">EN-You hit the limit on the number of text messages. Try again shortly.</LocalizedString>
        <LocalizedString ElementType="UxElement" StringId="error_phone_throttled">EN-You hit the limit on the number of call attempts. Try again shortly.</LocalizedString>
        <LocalizedString ElementType="UxElement" StringId="error_throttled">EN-You hit the limit on the number of verification attempts. Try again shortly.</LocalizedString>
        <LocalizedString ElementType="UxElement" StringId="error_incorrect_code">EN-The verification code you have entered does not match our records. Please try again, or request a new code.</LocalizedString>
        ...
    </LocalizedStrings>
</LocalizedResources>

可能的原因及解决方案

1. 限流错误对应的字符串ID不匹配

Azure AD B2C针对SMS重发的高频限流,触发的错误字符串ID可能不是你当前配置的几个。除已配置条目外,需检查是否缺少:

  • error_too_many_attempts:部分版本MFA控件会用这个ID标识高频请求限流
  • 确认error_sms_throttled是否对应重发SMS的限流场景(部分场景下该ID仅针对验证码验证次数过多,而非重发请求)

2. ContentDefinition版本不匹配

你的ContentDefinition中LoadUri使用multifactor-1.0.0.cshtml,但DataUri是multifactor:1.2.5,版本不一致可能导致控件无法识别新的错误字符串ID。建议更新LoadUri:

<LoadUri>~/tenant/templates/AzureBlue/multifactor-1.2.5.cshtml</LoadUri>

3. 未开启页面端限流提示

在PhoneRegisterOrMFAPage技术配置的Metadata中,添加元数据启用页面端限流提示:

<Item Key="setting.showThrottleErrors">true</Item>

4. 后端级限流未传递到前端

部分限流错误属于Azure AD B2C后端拦截,不会直接返回给前端页面。这种情况下需通过自定义策略的ClaimsTransformation或ValidationTechnicalProfile捕获错误,映射为前端可识别的消息。

内容的提问来源于stack exchange,提问作者fei0x

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 04:07:04