Azure B2C集成Salesforce IdP遇重定向错误,存在objectId缺失
objectId in Salesforce-Azure B2C Integration Let’s break down your issue: Salesforce logs confirm a successful SSO attempt, but Azure B2C throws a generic AADB2C90037 server error and you’re encountering a missing objectId claim. Here’s how to diagnose and fix this step by step:
1. Fix the objectId Claim Mapping (Likely Root Cause)
Azure B2C relies on objectId as a unique user identifier to complete the authentication flow—its absence is almost certainly triggering the server error.
- In the Azure Portal, navigate to your B2C tenant → Identity Providers → select your Salesforce IdP.
- Go to the Claim mappings section: Ensure you’re mapping a unique identifier from Salesforce (like
userIdorNameID) directly to Azure B2C’sobjectIdclaim.- If no such mapping exists, add it: Pick the relevant Salesforce claim (e.g.,
userId) from the dropdown, then selectobjectIdas the target B2C claim.
- If no such mapping exists, add it: Pick the relevant Salesforce claim (e.g.,
- For custom policies: Open your
TrustFrameworkExtensions.xml, locate the<ClaimsProvider>block for Salesforce, and add an output claim mapping like:<OutputClaim ClaimTypeReferenceId="objectId" PartnerClaimType="userId" />
2. Inspect the SAML Assertion from Salesforce
Use a tool like SAML Tracer to capture the SAML response sent from Salesforce to Azure B2C. Verify:
- Does the assertion include a unique user identifier (e.g.,
<saml:NameID>or a custom attribute likeuserId)? - Are the claim names exactly what you’re referencing in Azure B2C’s mapping? Typos or mismatched names will break the flow silently.
3. Dig into Azure B2C’s Detailed Logs
The AADB2C90037 error is generic—you need to check B2C’s logs for the real issue:
- Enable Application Insights for your B2C tenant if you haven’t already.
- Reproduce the error, then go to Application Insights → Logs and run a query to find the failed authentication event. Look for fields like
errorDescriptionorfailureReason—this will spell out exactly why the flow failed (e.g., "Required claim 'objectId' is missing").
4. Validate User Journey Configuration (Custom Policies)
If you’re using custom policies, ensure your User Journey doesn’t depend on objectId before it’s populated:
- Check your orchestration steps: The step that calls the Salesforce IdP must run before any steps that require
objectId(like creating a local account or issuing tokens).
5. Double-Check Salesforce SAML Settings
Confirm your Salesforce IdP configuration is aligned with Azure B2C’s requirements:
- The Assertion Consumer Service (ACS) URL matches exactly what’s configured in Azure B2C (no trailing slashes, correct tenant ID and policy name).
- The SAML response is signed with a valid certificate that Azure B2C trusts.
- The NameID format matches Azure B2C’s expected format (e.g.,
urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified).
Once you fix the objectId mapping and resolve any underlying issues uncovered in the logs, the AADB2C90037 error should disappear, and the flow should redirect to your test app successfully.
内容的提问来源于stack exchange,提问作者Jussi Palo

