You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C密码重置流程能否使用UserName替代Email进行验证

Azure AD B2C 用户名重置密码实现方案

可以通过用户名实现密码重置需求,你当前仅修改了用户读取技术配置文件,未调整前端表单绑定的自断言技术配置文件,所以表单仍然显示邮箱输入项,按以下步骤修改即可:

  • 第一步:调整密码重置首步的自断言技术配置文件
    密码重置流程的输入表单默认绑定LocalAccountDiscoveryUsingEmailAddress自断言技术配置文件,你需要修改它的输入声明,将邮箱替换为用户名:
<TechnicalProfile Id="LocalAccountDiscoveryUsingUserName">
  <Metadata>
    <Item Key="ContentDefinitionReferenceId">api.localaccountpasswordreset</Item>
    <Item Key="UserMessageIfClaimsPrincipalAlreadyExists">该用户名对应的账号已存在</Item>
  </Metadata>
  <InputClaims>
    <InputClaim ClaimTypeReferenceId="signInName" Required="true" />
  </InputClaims>
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="signInName" Required="true" />
    <OutputClaim ClaimTypeReferenceId="objectId" />
    <OutputClaim ClaimTypeReferenceId="userPrincipalName" />
  </OutputClaims>
  <ValidationTechnicalProfiles>
    <ValidationTechnicalProfile ReferenceId="AAD-UserReadUsingUserName" />
  </ValidationTechnicalProfiles>
</TechnicalProfile>
  • 第二步:规范用户读取技术配置文件
    你当前修改的AAD-UserReadUsingEmailAddress逻辑是正确的,建议重命名为AAD-UserReadUsingUserName避免和原有邮箱读取逻辑冲突,配置和你贴出的代码一致即可。

  • 第三步:调整声明类型校验规则
    检查基础策略中signInName声明类型的定义,确保UserInputType设置为TextBox而非EmailBox,避免前端强制校验邮箱格式:

<ClaimType Id="signInName">
  <DisplayName>用户名</DisplayName>
  <DataType>string</DataType>
  <UserInputType>TextBox</UserInputType>
</ClaimType>
  • 第四步:更新用户旅程引用
    找到密码重置对应的用户旅程,将原引用LocalAccountDiscoveryUsingEmailAddress的节点替换为你修改后的LocalAccountDiscoveryUsingUserName即可生效。

内容的提问来源于stack exchange,提问作者Pedro

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.24 02:24:06