You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AAD B2C自定义策略添加extension_UserRole后未在JWT中显示的问题咨询

Azure AAD B2C自定义属性extension_UserRole显示问题修改建议

针对你遇到的自定义属性extension_UserRole未在登录环节及JWT令牌中显示的问题,可按以下步骤修改自定义策略:

  • 在ClaimsSchema中定义属性
    打开自定义策略的基础文件,在<ClaimsSchema>节点下添加该属性的定义,确保策略能识别这个属性:

    <ClaimType Id="extension_UserRole">
      <DisplayName>User Role</DisplayName>
      <DataType>string</DataType>
      <UserHelpText>用户在系统中的角色</UserHelpText>
    </ClaimType>
    
  • 在用户信息读取步骤中添加属性输出
    找到登录流程中读取用户信息的TechnicalProfile(通常是AAD-UserReadUsingEmailAddress或AAD-UserReadUsingObjectId),在其<OutputClaims>节点中加入该属性,让策略从AAD中读取这个值:

    <OutputClaim ClaimTypeReferenceId="extension_UserRole" />
    
  • 在令牌签发环节包含该属性
    定位到负责签发JWT的TechnicalProfile(一般为JwtIssuer),在它的<OutputClaims>里添加该属性,确保属性被写入最终的JWT令牌:

    <OutputClaim ClaimTypeReferenceId="extension_UserRole" />
    
  • 注册流程同步配置(如需用户注册时设置)
    如果需要用户在注册时填写该角色,在注册对应的TechnicalProfile(如LocalAccountSignUpWithLogonEmail)中,同时配置<OutputClaims>(展示输入框)和<PersistedClaims>(持久化到AAD):

    <OutputClaim ClaimTypeReferenceId="extension_UserRole" Required="false" />
    <PersistedClaim ClaimTypeReferenceId="extension_UserRole" />
    
  • 验证基础配置

    1. 确认Azure门户中已成功创建extension_UserRole属性
    2. 检查自定义策略中使用的应用程序ID拥有读取该属性的权限
  • 测试前清理缓存
    修改策略后,使用浏览器无痕模式或清理缓存后测试,避免旧策略缓存干扰结果

内容的提问来源于stack exchange,提问作者Nikhil Mittal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 09:15:37