You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure B2C SAML本地账户邮件声明传递失败求助

解决Azure B2C SAML自定义策略无法传递Email声明的问题

你的核心问题是从Azure AD读取的邮箱字段(signInNames.emailAddress)没有与你定义的email声明关联,导致最终SAML断言中没有包含该声明。以下是具体修复步骤:

1. 修正AAD-UserReadUsingObjectId技术配置文件

在读取用户信息的技术配置文件中,直接将Azure AD存储的signInNames.emailAddress字段映射到你定义的email声明,替换原有的signInNames.emailAddress输出声明:

<TechnicalProfile Id="AAD-UserReadUsingObjectId">
  <Metadata>
    <Item Key="Operation">Read</Item>
    <Item Key="RaiseErrorIfClaimsPrincipalDoesNotExist">true</Item>
  </Metadata>
  <IncludeInSso>false</IncludeInSso>
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="objectId" Required="true" />
  </InputClaims>
  <OutputClaims>
    <!-- 将AD中的signInNames.emailAddress直接映射到email声明 -->
    <OutputClaim ClaimTypeReferenceId="email" PartnerClaimType="signInNames.emailAddress" />
    <OutputClaim ClaimTypeReferenceId="displayName" />
    <OutputClaim ClaimTypeReferenceId="otherMails" />
    <OutputClaim ClaimTypeReferenceId="givenName" />
    <OutputClaim ClaimTypeReferenceId="surname" />
  </OutputClaims>
  <IncludeTechnicalProfile ReferenceId="AAD-Common" />
</TechnicalProfile>

注:如果你的本地账户邮箱存储在otherMails字段(而非登录用的signInNames.emailAddress),请将PartnerClaimType改为otherMails。

2. 优化RelyingParty配置

移除email声明的DefaultValue(避免空值覆盖实际读取到的邮箱):

<RelyingParty>
  <DefaultUserJourney ReferenceId="SignUpOrSignInWithCA" />
  <TechnicalProfile Id="PolicyProfile">
    <DisplayName>PolicyProfile</DisplayName>
    <Protocol Name="SAML2" />
    <OutputClaims>
      <OutputClaim ClaimTypeReferenceId="displayName" />
      <OutputClaim ClaimTypeReferenceId="givenName" />
      <OutputClaim ClaimTypeReferenceId="surname" />
      <OutputClaim ClaimTypeReferenceId="email" />
      <OutputClaim ClaimTypeReferenceId="identityProvider" DefaultValue="" />
      <OutputClaim ClaimTypeReferenceId="objectId" PartnerClaimType="objectId" />
    </OutputClaims>
    <SubjectNamingInfo ClaimType="objectId" ExcludeAsClaim="true" />
  </TechnicalProfile>
</RelyingParty>

3. 验证用户旅程流程

确保你的用户旅程SignUpOrSignInWithCA中,调用AAD-UserReadUsingObjectId的步骤(通常是登录后的用户信息读取步骤)没有过滤掉email声明。该步骤的配置应类似:

<OrchestrationStep Order="2" Type="ClaimsExchange">
  <ClaimsExchanges>
    <ClaimsExchange Id="AADUserReadWithObjectId" TechnicalProfileReferenceId="AAD-UserReadUsingObjectId" />
  </ClaimsExchanges>
</OrchestrationStep>

测试建议

使用SAML Tracer等工具捕获SAML断言,检查是否包含http://schemas.xmlsoap.org/ws/2005/05/identity/claims/email属性,确认其值是否正确。

内容的提问来源于stack exchange,提问作者RubberDuck804

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 20:10:48