如何在Azure AD B2C中添加自定义身份提供商及未列出的第三方授权
Hey there! Let's break down exactly how to add a custom identity provider like Instagram or VK to Azure AD B2C. Since these aren't in the pre-built list of providers, we'll need to use OAuth 2.0 (most social platforms support this) and Azure AD B2C's custom policies—here's a step-by-step guide that works for any unsupported third-party auth service:
First, you need to create an application in the provider's developer platform to get the credentials we'll need later:
- For Instagram: Head to the Instagram Developer Portal, create a new app, and configure the authorization callback URL to match Azure AD B2C's endpoint:
https://<your-b2c-tenant-name>.b2clogin.com/<your-b2c-tenant-name>.onmicrosoft.com/oauth2/authresp - For VK: Do the same in the VK Developer Portal, using the exact same callback URL as above.
- Save two critical values from this setup: the Client ID (your app's unique identifier) and Client Secret (a secure key for authenticating your app with the provider).
Built-in user flows don't support custom identity providers, so we'll use custom policies (XML-based configurations) to extend Azure AD B2C's capabilities.
2.1 Grab the Custom Policy Starter Pack
Download the Azure AD B2C custom policy starter pack (we recommend the SocialAndLocalAccounts pack—it's the most flexible for social logins). This gives you a base set of XML files to modify.
2.2 Add the Identity Provider to Your Policy XML
Open the TrustFrameworkExtensions.xml file from the starter pack, and add a new <ClaimsProvider> section inside the existing <ClaimsProviders> node. Here's an example for Instagram (adjust endpoints/scopes for VK):
<ClaimsProvider> <Domain>instagram.com</Domain> <DisplayName>Instagram</DisplayName> <TechnicalProfiles> <TechnicalProfile Id="Instagram-OAuth2"> <DisplayName>Instagram</DisplayName> <Protocol Name="OAuth2" /> <Metadata> <Item Key="AuthorizationEndpoint">https://api.instagram.com/oauth/authorize</Item> <Item Key="TokenEndpoint">https://api.instagram.com/oauth/access_token</Item> <Item Key="ClaimsEndpoint">https://graph.instagram.com/me?fields=id,username,email</Item> <Item Key="ClientId">YOUR_INSTAGRAM_CLIENT_ID</Item> <Item Key="ClientSecret">YOUR_INSTAGRAM_CLIENT_SECRET</Item> <Item Key="Scope">user_profile user_email</Item> <Item Key="ResponseType">code</Item> <Item Key="UsePolicyInRedirectUri">false</Item> </Metadata> <CryptographicKeys> <Key Id="client_secret" StorageReferenceId="B2C_1A_InstagramClientSecret" /> </CryptographicKeys> <OutputClaims> <OutputClaim ClaimTypeReferenceId="issuerUserId" PartnerClaimType="id" /> <OutputClaim ClaimTypeReferenceId="displayName" PartnerClaimType="username" /> <OutputClaim ClaimTypeReferenceId="email" PartnerClaimType="email" /> <OutputClaim ClaimTypeReferenceId="identityProvider" DefaultValue="instagram.com" /> <OutputClaim ClaimTypeReferenceId="authenticationSource" DefaultValue="socialIdpAuthentication" /> </OutputClaims> <OutputClaimsTransformations> <OutputClaimsTransformation ReferenceId="CreateRandomUPNUserName" /> <OutputClaimsTransformation ReferenceId="CreateUserPrincipalName" /> <OutputClaimsTransformation ReferenceId="CreateAlternativeSecurityId" /> <OutputClaimsTransformation ReferenceId="CreateSubjectClaimFromAlternativeSecurityId" /> </OutputClaimsTransformations> <UseTechnicalProfileForSessionManagement ReferenceId="SM-SocialLogin" /> </TechnicalProfile> </TechnicalProfiles> </ClaimsProvider>
For VK, update the metadata values to match VK's API endpoints:
- AuthorizationEndpoint:
https://oauth.vk.com/authorize - TokenEndpoint:
https://oauth.vk.com/access_token - ClaimsEndpoint:
https://api.vk.com/method/users.get?fields=uid,first_name,last_name,email - Scope:
email
2.3 Store the Client Secret Securely
Never hardcode secrets in XML files! Instead, add the Client Secret to Azure AD B2C's key store:
- In the Azure AD B2C portal, go to Identity Experience Framework > Policy keys.
- Create a new key with name
B2C_1A_InstagramClientSecret(orB2C_1A_VkClientSecret), typeClient Secret, and paste the provider's Client Secret as the value.
2.4 Update the User Journey to Include the New Provider
Open the SignUpOrSignin.xml file (your main user flow policy), and add the new provider to the login selection screen:
- In the
<OrchestrationSteps>section, find step 1 (the identity provider selection step) and add this line:
<ClaimsProviderSelection TargetClaimsExchangeId="InstagramExchange" />
- Then, add a corresponding
<ClaimsExchange>entry later in the same step:
<ClaimsExchange Id="InstagramExchange" TechnicalProfileReferenceId="Instagram-OAuth2" />
Repeat this for VK, changing the IDs to match your VK technical profile.
2.5 Upload the Updated Policies
Go back to the Azure AD B2C portal's Identity Experience Framework > Custom policies, and upload the modified files in this order:
TrustFrameworkExtensions.xmlSignUpOrSignin.xml
- In the Azure AD B2C portal, go to User flows and custom policies, select your custom
SignUpOrSigninpolicy, and click Run user flow. - You should see the Instagram/VK button on the login screen. Click it, authorize the app when prompted, and you'll be redirected back to Azure AD B2C to complete the sign-up/sign-in process.
- Callback URL mismatch: Double-check that the URL in your third-party app exactly matches the Azure AD B2C callback (case sensitivity and trailing slashes matter!).
- Incorrect scopes: Make sure you're requesting the right scopes to get user data (e.g., Instagram needs
user_emailto access the user's email). - Token/claims errors: Enable Application Insights for your custom policies to log detailed errors—this is the easiest way to debug issues like failed token exchanges or missing user claims.
内容的提问来源于stack exchange,提问作者Dmitry

