Azure AD B2C自定义属性无法保存 已做排查求后续检查方向
我来帮你梳理下还能排查的几个关键方向,都是我之前碰到类似问题时踩过的坑:
检查声明映射的完整性
确认你的JWT声明名称和B2C策略中使用的声明名称完全匹配,包括大小写(B2C对声明大小写敏感)。比如JWT里是customAttribute,策略里别写成CustomAttribute。另外,要确保在ClaimsTransformation或者InputClaims环节,已经把JWT中的声明正确映射到要存储的AD属性对应的声明上(比如AD属性是extension_myCustomAttr,得把JWT声明转成这个名称)。验证Technical Profile的执行顺序
注册策略的用户旅程中,存储AD的Technical Profile(通常是AAD-UserWriteUsingAlternativeSecurityId或者AAD-UserWriteProfileUsingObjectId)必须在获取JWT声明的步骤之后执行——如果顺序反了,那时候还没拿到JWT属性,自然存不进去。同时要检查这个存储Profile的PersistedClaims节点,有没有明确包含你要保存的自定义属性声明,比如:<PersistedClaims> <PersistedClaim ClaimTypeReferenceId="extension_myCustomAttr" /> </PersistedClaims>检查AD属性的配置权限
确认你在AD中创建的自定义扩展属性(extension_*开头的),对应的B2C应用程序有写权限。另外,新创建的扩展属性可能需要15-30分钟的权限同步时间,别刚创建完就着急排查,先等一等再测试。启用策略的调试日志
开启B2C的Application Insights日志,走完注册流程后查看日志里的声明流转:- 搜索
InboundClaims相关条目,确认JWT的声明是否成功被策略接收; - 查看
EventName为ClaimsExchange的条目,检查存储AD的步骤中PersistedClaims是否包含目标属性,有没有权限不足、声明为空之类的报错。
- 搜索
检查声明的空值处理
有时候JWT里的声明看起来有值,但实际可能是空字符串或null。你可以在注册页面临时显示声明值,或者在ClaimsTransformation里添加默认值逻辑,确保属性不会因为空值被跳过存储,比如:<ClaimsTransformation Id="SetDefaultCustomAttr" TransformationMethod="AddItemToStringCollection"> <InputClaims> <InputClaim ClaimTypeReferenceId="customAttr" TransformationClaimType="inputClaim" /> </InputClaims> <InputParameters> <InputParameter Id="item" DataType="string" Value="default_value" /> </InputParameters> <OutputClaims> <OutputClaim ClaimTypeReferenceId="extension_myCustomAttr" TransformationClaimType="outputClaim" /> </OutputClaims> </ClaimsTransformation>确认用户创建/更新的逻辑
新用户注册用的是AAD-UserWriteUsingAlternativeSecurityId,已有用户更新则可能用AAD-UserWriteProfileUsingObjectId,要确保你用对了对应的Technical Profile,并且该Profile的Metadata节点里的Operation属性是正确的(比如Operation="Write"或Operation="Create")。
内容的提问来源于stack exchange,提问作者spottedmahn

