You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C自定义策略问题:用户名登录+邮箱重置密码异常

解决Azure AD B2C自定义策略的邮箱保存与密码重置问题

一、修复注册时邮箱未保存的问题

当前注册流程中邮箱未保存的核心原因有两个:一是关闭邮件验证后,Verified.Email声明不存在,导致邮箱值无法传递;二是未将邮箱保存到标准的mail字段。需修改以下两处:

  1. 调整注册页面的邮箱声明传递
    在LocalAccountSignUpWithLogonName技术概要的<OutputClaims>中,移除邮箱声明的PartnerClaimType="Verified.Email"(因为你设置了EnforceEmailVerification="false",不会生成该声明):
<OutputClaim ClaimTypeReferenceId="email" Required="true" />
  1. 同时保存邮箱到多个用户属性
    在AAD-UserWriteUsingLogonName技术概要的<PersistedClaims>中,添加mail字段的保存,确保邮箱同时存储到标准属性和强验证邮箱属性:
<PersistedClaim ClaimTypeReferenceId="email" PartnerClaimType="mail" />
<PersistedClaim ClaimTypeReferenceId="email" PartnerClaimType="strongAuthenticationEmailAddress" />

二、修复邮箱重置密码的错误问题

密码重置失败是因为默认的邮箱查找逻辑仅检查mail或signInNames.emailAddress字段,而你的用户邮箱可能只存储在strongAuthenticationEmailAddress中。需修改用户查找的技术概要:

在TrustFrameworkExtensions.xml中添加或修改LocalAccountDiscoveryUsingEmailAddress及其关联的AAD-UserReadUsingEmailAddress技术概要,让查找逻辑同时匹配mail和strongAuthenticationEmailAddress字段:

<TechnicalProfile Id="LocalAccountDiscoveryUsingEmailAddress">
  <DisplayName>Reset password using email address</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <Item Key="IpAddressClaimReferenceId">IpAddress</Item>
    <Item Key="ContentDefinitionReferenceId">api.localaccountpasswordreset</Item>
    <Item Key="UserMessageIfClaimsPrincipalDoesNotExist">无法找到你的账户</Item>
    <Item Key="UserMessageIfInvalidEmail">请输入有效的邮箱地址</Item>
  </Metadata>
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="email" Required="true" />
  </InputClaims>
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="objectId" />
    <OutputClaim ClaimTypeReferenceId="email" />
    <OutputClaim ClaimTypeReferenceId="userPrincipalName" />
    <OutputClaim ClaimTypeReferenceId="displayName" />
  </OutputClaims>
  <ValidationTechnicalProfiles>
    <ValidationTechnicalProfile ReferenceId="AAD-UserReadUsingEmailAddress" />
  </ValidationTechnicalProfiles>
</TechnicalProfile>

<TechnicalProfile Id="AAD-UserReadUsingEmailAddress">
  <Metadata>
    <Item Key="Operation">Read</Item>
    <Item Key="RaiseErrorIfClaimsPrincipalDoesNotExist">true</Item>
    <Item Key="UserMessageIfClaimsPrincipalDoesNotExist">无法找到你的账户</Item>
  </Metadata>
  <InputClaims>
    <!-- 同时通过mail和strongAuthenticationEmailAddress查找用户 -->
    <InputClaim ClaimTypeReferenceId="email" PartnerClaimType="mail" />
    <InputClaim ClaimTypeReferenceId="email" PartnerClaimType="strongAuthenticationEmailAddress" />
  </InputClaims>
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="objectId" />
    <OutputClaim ClaimTypeReferenceId="userPrincipalName" />
    <OutputClaim ClaimTypeReferenceId="displayName" />
  </OutputClaims>
  <IncludeTechnicalProfile ReferenceId="AAD-Common" />
</TechnicalProfile>

额外检查

确认ResetPassword.xml中的<DefaultUserJourney ReferenceId="PasswordChange" />对应的用户旅程已正确定义,且包含调用PasswordReset子旅程的步骤(你当前的配置已包含该步骤,可无需修改)。

内容的提问来源于stack exchange,提问作者Juan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.24 09:03:19