You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure AD B2C IDP的SAML响应中设置AuthnContext

Azure AD B2C返回指定SAML AuthnContextClassRef的配置方案

该需求可正常实现,仅需在自定义策略中完成3处配置即可,具体操作如下:

  • 第一步:在基础策略文件(通常为TrustFrameworkBase.xml)的<ClaimsSchema>节点下新增用于存储身份验证上下文的声明:
<ClaimType Id="authenticationContext">
  <DisplayName>Authentication Context</DisplayName>
  <DataType>string</DataType>
</ClaimType>
  • 第二步:找到对应SAML SP的<RelyingParty>配置节点,在<OutputClaims>下新增输出声明,固定赋值为要求的PasswordProtectedTransport对应的标准URN:
<OutputClaim ClaimTypeReferenceId="authenticationContext" DefaultValue="urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport" AlwaysUseDefaultValue="true" />
  • 第三步:找到该SP对应的SAML签发技术配置节点(即Protocol名称为SAML2的<TechnicalProfile>节点),在其<Metadata>子节点下新增配置,指定AuthnContextClassRef的取值来源为我们新增的声明:
<Item Key="AuthenticationContextClassReference">authenticationContext</Item>

若你需要根据不同登录方式返回不同的AuthnContext值,可去掉第二步声明的固定默认值,改为在用户旅程的身份验证步骤后根据实际登录方式动态给authenticationContext声明赋值即可。

配置完成后重新上传自定义策略,再次发起登录请求时,B2C返回的SAML响应断言中<AuthnContextClassRef>值就会替换为你配置的PasswordProtectedTransport,不再返回unspecified,即可通过legacy SAML SP的校验。

内容的提问来源于stack exchange,提问作者cbeer7

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.25 10:36:04