You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C策略问题:已验证MFA手机号无法写入用户档案

问题:Azure AD B2C 已验证MFA手机号无法写入用户档案

我们正在创建首个Azure AD B2C策略,需求是新用户输入并验证MFA手机号后,将该号码写入用户档案。但复制示例XML配置后,用户每次登录都需要重新输入并验证手机号,且该号码从未被记录到用户档案中。我们尝试修改甚至移除步骤8中的<Preconditions>元素,但完全没有效果,反复检查配置仍未找到问题,恳请排查已验证手机号无法写入的原因。


相关TechnicalProfile配置

PhoneFactor-InputOrVerify

<TechnicalProfile Id="PhoneFactor-InputOrVerify">
  <DisplayName>PhoneFactor</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.PhoneFactorProtocolProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null"/>
  <Metadata>
    <Item Key="ContentDefinitionReferenceId">api.phonefactor</Item>
    <Item Key="ManualPhoneNumberEntryAllowed">true</Item>
  </Metadata>
  <CryptographicKeys>
    <Key Id="issuer_secret" StorageReferenceId="B2C_1A_TokenSigningKeyContainer"/>
  </CryptographicKeys>
  <InputClaimsTransformations>
    <InputClaimsTransformation ReferenceId="CreateUserIdForMFA"/>
  </InputClaimsTransformations>
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="userIdForMFA" PartnerClaimType="UserId"/>
    <InputClaim ClaimTypeReferenceId="strongAuthenticationPhoneNumber"/>
  </InputClaims>
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="Verified.strongAuthenticationPhoneNumber" PartnerClaimType="Verified.OfficePhone"/>
    <OutputClaim ClaimTypeReferenceId="newPhoneNumberEntered" PartnerClaimType="newPhoneNumberEntered"/>
  </OutputClaims>
  <UseTechnicalProfileForSessionManagement ReferenceId="SM-MFA"/>
</TechnicalProfile>

AAD-UserWritePhoneNumberUsingObjectId

<TechnicalProfile Id="AAD-UserWritePhoneNumberUsingObjectId">
  <Metadata>
    <Item Key="Operation">Write</Item>
    <Item Key="RaiseErrorIfClaimsPrincipalAlreadyExists">false</Item>
    <Item Key="RaiseErrorIfClaimsPrincipalDoesNotExist">true</Item>
  </Metadata>
  <IncludeInSso>false</IncludeInSso>
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="objectId" Required="true"/>
    </InputClaims>
<PersistedClaims>
    <PersistedClaim ClaimTypeReferenceId="objectId"/>
    <PersistedClaim ClaimTypeReferenceId="Verified.strongAuthenticationPhoneNumber" PartnerClaimType="strongAuthenticationPhoneNumber"/>
  </PersistedClaims>
  <IncludeTechnicalProfile ReferenceId="AAD-Common"/>
</TechnicalProfile>

引用配置的OrchestrationStep条目

<OrchestrationStep Order="7" Type="ClaimsExchange">
  <Preconditions>
    <Precondition Type="ClaimsExist" ExecuteActionsIf="false">
    <Value>newUser</Value>
    <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
  </Preconditions>
  <ClaimsExchanges>
    <ClaimsExchange Id="PhoneFactor-Verify" TechnicalProfileReferenceId="PhoneFactor-InputOrVerify"/>
  </ClaimsExchanges>
</OrchestrationStep>

<OrchestrationStep Order="8" Type="ClaimsExchange">
  <Preconditions>
    <Precondition Type="ClaimsExist" ExecuteActionsIf="false">
    <Value>newPhoneNumberEntered</Value>
    <Action>SkipThisOrchestrationStep</Action>
    </Precondition>
  </Preconditions>
  <ClaimsExchanges>
    <ClaimsExchange Id="AADUserWriteWithObjectId" TechnicalProfileReferenceId="AAD-UserWritePhoneNumberUsingObjectId"/>
  </ClaimsExchanges>
</OrchestrationStep>

排查关键点及解决方案

  • newPhoneNumberEntered声明有效性:该声明仅在用户首次输入新号码时被设为true,需确保策略的<ClaimsSchema>中已定义该声明:

    <ClaimType Id="newPhoneNumberEntered">
      <DisplayName>New Phone Number Entered</DisplayName>
      <DataType>boolean</DataType>
    </ClaimType>
    

    即使移除步骤8的Precondition,也要确认Verified.strongAuthenticationPhoneNumber声明存在于声明包中,否则写入操作无数据可写。

  • 声明映射与属性权限:检查AAD-UserWritePhoneNumberUsingObjectId中PersistedClaim的PartnerClaimType="strongAuthenticationPhoneNumber"是否对应Azure AD用户的合法属性,同时确保AAD-Common技术配置文件拥有写入该属性的权限。

  • objectId的可用性:写入操作依赖objectId,需确保步骤7(MFA验证)在用户创建步骤之后执行——新用户的objectId是在用户创建环节生成的,若步骤7提前执行,步骤8会因objectId缺失导致写入失败。

  • 会话管理干扰:暂时移除PhoneFactor-InputOrVerify中的<UseTechnicalProfileForSessionManagement ReferenceId="SM-MFA"/>,验证声明是否能正常传递到步骤8的写入操作。

  • 日志排查:查看Azure Portal中B2C的「审核日志」,确认步骤8是否被执行,以及是否存在写入错误(如权限不足、声明为空等)。

内容的提问来源于stack exchange,提问作者Don R

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 14:31:52