Azure AD B2C策略问题:已验证MFA手机号无法写入用户档案
我们正在创建首个Azure AD B2C策略,需求是新用户输入并验证MFA手机号后,将该号码写入用户档案。但复制示例XML配置后,用户每次登录都需要重新输入并验证手机号,且该号码从未被记录到用户档案中。我们尝试修改甚至移除步骤8中的<Preconditions>元素,但完全没有效果,反复检查配置仍未找到问题,恳请排查已验证手机号无法写入的原因。
相关TechnicalProfile配置
PhoneFactor-InputOrVerify
<TechnicalProfile Id="PhoneFactor-InputOrVerify"> <DisplayName>PhoneFactor</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.PhoneFactorProtocolProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null"/> <Metadata> <Item Key="ContentDefinitionReferenceId">api.phonefactor</Item> <Item Key="ManualPhoneNumberEntryAllowed">true</Item> </Metadata> <CryptographicKeys> <Key Id="issuer_secret" StorageReferenceId="B2C_1A_TokenSigningKeyContainer"/> </CryptographicKeys> <InputClaimsTransformations> <InputClaimsTransformation ReferenceId="CreateUserIdForMFA"/> </InputClaimsTransformations> <InputClaims> <InputClaim ClaimTypeReferenceId="userIdForMFA" PartnerClaimType="UserId"/> <InputClaim ClaimTypeReferenceId="strongAuthenticationPhoneNumber"/> </InputClaims> <OutputClaims> <OutputClaim ClaimTypeReferenceId="Verified.strongAuthenticationPhoneNumber" PartnerClaimType="Verified.OfficePhone"/> <OutputClaim ClaimTypeReferenceId="newPhoneNumberEntered" PartnerClaimType="newPhoneNumberEntered"/> </OutputClaims> <UseTechnicalProfileForSessionManagement ReferenceId="SM-MFA"/> </TechnicalProfile>
AAD-UserWritePhoneNumberUsingObjectId
<TechnicalProfile Id="AAD-UserWritePhoneNumberUsingObjectId"> <Metadata> <Item Key="Operation">Write</Item> <Item Key="RaiseErrorIfClaimsPrincipalAlreadyExists">false</Item> <Item Key="RaiseErrorIfClaimsPrincipalDoesNotExist">true</Item> </Metadata> <IncludeInSso>false</IncludeInSso> <InputClaims> <InputClaim ClaimTypeReferenceId="objectId" Required="true"/> </InputClaims> <PersistedClaims> <PersistedClaim ClaimTypeReferenceId="objectId"/> <PersistedClaim ClaimTypeReferenceId="Verified.strongAuthenticationPhoneNumber" PartnerClaimType="strongAuthenticationPhoneNumber"/> </PersistedClaims> <IncludeTechnicalProfile ReferenceId="AAD-Common"/> </TechnicalProfile>
引用配置的OrchestrationStep条目
<OrchestrationStep Order="7" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimsExist" ExecuteActionsIf="false"> <Value>newUser</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="PhoneFactor-Verify" TechnicalProfileReferenceId="PhoneFactor-InputOrVerify"/> </ClaimsExchanges> </OrchestrationStep> <OrchestrationStep Order="8" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimsExist" ExecuteActionsIf="false"> <Value>newPhoneNumberEntered</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="AADUserWriteWithObjectId" TechnicalProfileReferenceId="AAD-UserWritePhoneNumberUsingObjectId"/> </ClaimsExchanges> </OrchestrationStep>
排查关键点及解决方案
newPhoneNumberEntered声明有效性:该声明仅在用户首次输入新号码时被设为true,需确保策略的<ClaimsSchema>中已定义该声明:<ClaimType Id="newPhoneNumberEntered"> <DisplayName>New Phone Number Entered</DisplayName> <DataType>boolean</DataType> </ClaimType>即使移除步骤8的Precondition,也要确认
Verified.strongAuthenticationPhoneNumber声明存在于声明包中,否则写入操作无数据可写。声明映射与属性权限:检查
AAD-UserWritePhoneNumberUsingObjectId中PersistedClaim的PartnerClaimType="strongAuthenticationPhoneNumber"是否对应Azure AD用户的合法属性,同时确保AAD-Common技术配置文件拥有写入该属性的权限。objectId的可用性:写入操作依赖objectId,需确保步骤7(MFA验证)在用户创建步骤之后执行——新用户的objectId是在用户创建环节生成的,若步骤7提前执行,步骤8会因objectId缺失导致写入失败。会话管理干扰:暂时移除
PhoneFactor-InputOrVerify中的<UseTechnicalProfileForSessionManagement ReferenceId="SM-MFA"/>,验证声明是否能正常传递到步骤8的写入操作。日志排查:查看Azure Portal中B2C的「审核日志」,确认步骤8是否被执行,以及是否存在写入错误(如权限不足、声明为空等)。
内容的提问来源于stack exchange,提问作者Don R

