创建含不同userType值的B2C账户后登录仅识别用户名的问题咨询
Hey there! Let's break down what's going on here first—there's a common property mix-up we should clarify right off the bat: In Azure AD B2C, the userType field is actually meant to distinguish between member and guest accounts. It sounds like you're referring to sign-in identifiers (the signInNames property), where you've set two entries: one of type userName and another of type emailAddress with different values.
Now, let's walk through why only the username works for login, and whether this is a bug or a configuration gap:
1. Check your user flow/custom policy login settings
This is almost certainly not a B2C bug—most often, the issue lies in how your login flow is configured:
- If you're using built-in user flows: Make sure you created a flow that supports both username and email login, not just one or the other. Head to your user flow's "Properties" tab, and verify the "Sign-in identifier" option has both "Username" and "Email address" checked.
- If you're using custom policies: Double-check your sign-in technical profile (like
SelfAsserted-LocalAccountSignin-Email) to ensure it accepts both username and email inputs. You also need to confirm yourClaimsProviderincludes validation logic for bothLocalAccountSigninUsernameandLocalAccountSigninEmail.
2. Verify the user account's actual properties
You'll want to confirm the dual sign-in identifiers are properly attached to the user account:
- Use the Azure portal or Microsoft Graph API to fetch the user details. With Graph API, call
GET https://graph.microsoft.com/v1.0/users/{user-id}and check thesignInNamesarray in the response. It should look like this:"signInNames": [ { "type": "userName", "value": "your-custom-username" }, { "type": "emailAddress", "value": "your-email@example.com" } ]
If one entry is missing, or the type is misspelled (e.g., Email instead of emailAddress), that's why that sign-in method won't work.
3. Rule out front-end template restrictions
If your user flow is configured correctly but the login page only shows a username input, check if you've customized the page layout template to restrict input types. Try switching back to the default template temporarily to see if both sign-in options appear.
When could this be a bug?
If all the above checks pass—your flow is set up for dual sign-ins, the user's signInNames has valid entries for both types, and the login page shows both options—but you still can't log in with the email, then it might be a B2C service issue. In that case, enable and download login failure logs from your user flow's "Logs" tab, note the error code and details, and submit a support ticket to Azure for further investigation.
内容的提问来源于stack exchange,提问作者radders

