You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure B2C集成Salesforce IdP遇重定向错误,存在objectId缺失

Troubleshooting AADB2C90037 Error & Missing objectId in Salesforce-Azure B2C Integration

Let’s break down your issue: Salesforce logs confirm a successful SSO attempt, but Azure B2C throws a generic AADB2C90037 server error and you’re encountering a missing objectId claim. Here’s how to diagnose and fix this step by step:

1. Fix the objectId Claim Mapping (Likely Root Cause)

Azure B2C relies on objectId as a unique user identifier to complete the authentication flow—its absence is almost certainly triggering the server error.

  • In the Azure Portal, navigate to your B2C tenant → Identity Providers → select your Salesforce IdP.
  • Go to the Claim mappings section: Ensure you’re mapping a unique identifier from Salesforce (like userId or NameID) directly to Azure B2C’s objectId claim.
    • If no such mapping exists, add it: Pick the relevant Salesforce claim (e.g., userId) from the dropdown, then select objectId as the target B2C claim.
  • For custom policies: Open your TrustFrameworkExtensions.xml, locate the <ClaimsProvider> block for Salesforce, and add an output claim mapping like:
    <OutputClaim ClaimTypeReferenceId="objectId" PartnerClaimType="userId" />
    

2. Inspect the SAML Assertion from Salesforce

Use a tool like SAML Tracer to capture the SAML response sent from Salesforce to Azure B2C. Verify:

  • Does the assertion include a unique user identifier (e.g., <saml:NameID> or a custom attribute like userId)?
  • Are the claim names exactly what you’re referencing in Azure B2C’s mapping? Typos or mismatched names will break the flow silently.

3. Dig into Azure B2C’s Detailed Logs

The AADB2C90037 error is generic—you need to check B2C’s logs for the real issue:

  • Enable Application Insights for your B2C tenant if you haven’t already.
  • Reproduce the error, then go to Application Insights → Logs and run a query to find the failed authentication event. Look for fields like errorDescription or failureReason—this will spell out exactly why the flow failed (e.g., "Required claim 'objectId' is missing").

4. Validate User Journey Configuration (Custom Policies)

If you’re using custom policies, ensure your User Journey doesn’t depend on objectId before it’s populated:

  • Check your orchestration steps: The step that calls the Salesforce IdP must run before any steps that require objectId (like creating a local account or issuing tokens).

5. Double-Check Salesforce SAML Settings

Confirm your Salesforce IdP configuration is aligned with Azure B2C’s requirements:

  • The Assertion Consumer Service (ACS) URL matches exactly what’s configured in Azure B2C (no trailing slashes, correct tenant ID and policy name).
  • The SAML response is signed with a valid certificate that Azure B2C trusts.
  • The NameID format matches Azure B2C’s expected format (e.g., urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified).

Once you fix the objectId mapping and resolve any underlying issues uncovered in the logs, the AADB2C90037 error should disappear, and the flow should redirect to your test app successfully.

内容的提问来源于stack exchange,提问作者Jussi Palo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:12:21