You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从Azure token_id及adalService.userInfo获取memberId并验证用户组归属

Answers to Your Azure AD Group Membership Verification Questions

Let's break down your two questions clearly to help you use the isMemberOf API effectively:

1. How to retrieve memberId from an Azure ID Token (token_id)

The memberId required for the isMemberOf API is the unique Object ID of the user, which is embedded directly in the Azure AD ID Token (a JWT-formatted token). Here's how to get it:

  • Decode the ID Token: You can use a JWT parsing library in your code (like jsonwebtoken for Node.js or System.IdentityModel.Tokens.Jwt for .NET) or a tool like jwt.io for quick manual checks.
  • Once decoded, look for the oid claim in the token payload. This oid value is exactly the memberId you need to pass to the API.

Note: The oid claim is an immutable, unique identifier for the user in Azure AD, making it ideal for this membership verification scenario.

2. Which property in this.adalService.userInfo maps to memberId

After user authentication with ADAL, the userInfo object includes an objectId property that corresponds directly to the required memberId.

Your userInfo response will typically look something like this:

{
  "username": "user@contoso.com",
  "profile": {
    "name": "John Doe",
    "objectId": "ea59e4d3-a7a1-4b5b-b65f-a25fcc0c0f99",
    // additional profile fields...
  },
  // other userInfo properties...
}

Simply extract the objectId value (either from this.adalService.userInfo.profile.objectId or directly from this.adalService.userInfo.objectId, depending on your ADAL implementation) and use it as the memberId in your isMemberOf API request body.


内容的提问来源于stack exchange,提问作者Raj4MS

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:43:00