You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure B2C多因素认证(MFA)各步骤能否配置独立URI?

在Azure B2C中为MFA各步骤配置独立URI的实现方案

好问题!在Azure AD B2C里,完全可以为多因素认证(MFA)的每个步骤配置独立的自定义页面URI,不用依赖监听Ajax请求这种临时方案。核心就是通过扩展phonefactor技术配置文件来实现,下面给你详细拆解具体操作:

核心思路

Azure B2C的MFA流程主要分为两个关键步骤:

  • 选择验证方式(比如你提到的“致电我”和“发送验证码”选项)
  • 输入验证码完成验证

这两个步骤分别对应策略中的Phonefactor-Input和Phonefactor-Verify技术配置文件,我们可以为每个配置文件绑定独立的自定义内容定义,从而指定不同的页面URI。

具体配置步骤

1. 扩展phonefactor技术配置文件

在你的自定义策略XML中,找到(或添加)Phonefactor-Input和Phonefactor-Verify技术配置文件,为每个文件添加ContentDefinitionReferenceId元数据,关联到你自定义的内容标识:

<!-- 对应“选择验证方式”步骤的技术配置文件 -->
<TechnicalProfile Id="Phonefactor-Input">
  <DisplayName>Phone Verification Method Selection</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.PhoneFactorProtocolProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <!-- 保留原有元数据,比如AllowAlternativePhoneNumber等 -->
    <Item Key="ContentDefinitionReferenceId">custom.phonefactor.selectmethod</Item>
  </Metadata>
  <!-- 其他输入输出声明、加密配置保持不变 -->
</TechnicalProfile>

<!-- 对应“输入验证码”步骤的技术配置文件 -->
<TechnicalProfile Id="Phonefactor-Verify">
  <DisplayName>Phone Verification Code Input</DisplayName>
  <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.PhoneFactorProtocolProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
  <Metadata>
    <!-- 保留原有元数据 -->
    <Item Key="ContentDefinitionReferenceId">custom.phonefactor.entercode</Item>
  </Metadata>
  <!-- 其他配置保持不变 -->
</TechnicalProfile>

2. 定义对应内容的URI

在策略的ContentDefinitions节点下,添加你刚才指定的内容标识,分别绑定到你的独立页面URI(比如你提到的zzz.com/A,以及验证码输入页面zzz.com/B):

<ContentDefinitions>
  <!-- 其他默认内容定义保留 -->
  
  <!-- 选择验证方式的自定义页面 -->
  <ContentDefinition Id="custom.phonefactor.selectmethod">
    <LoadUri>https://zzz.com/A</LoadUri>
    <RecoveryUri>~/common/default_page_error.html</RecoveryUri>
    <DataUri>urn:com:microsoft:aad:b2c:elements:contract:phonefactor:1.0.0</DataUri>
    <Metadata>
      <Item Key="DisplayName">Select Phone Verification Method</Item>
    </Metadata>
  </ContentDefinition>

  <!-- 输入验证码的自定义页面 -->
  <ContentDefinition Id="custom.phonefactor.entercode">
    <LoadUri>https://zzz.com/B</LoadUri>
    <RecoveryUri>~/common/default_page_error.html</RecoveryUri>
    <DataUri>urn:com:microsoft:aad:b2c:elements:contract:phonefactor:1.0.0</DataUri>
    <Metadata>
      <Item Key="DisplayName">Enter Verification Code</Item>
    </Metadata>
  </ContentDefinition>
</ContentDefinitions>

3. 自定义页面的必要配置

确保你的自定义页面(比如zzz.com/A)包含Azure B2C所需的核心控件和脚本,比如:

  • 渲染验证方式选项的元素:<div data-b2c-element="phoneVerificationType"></div>
  • 触发验证流程的按钮:<button data-b2c-element="verifyButton">确认</button>
  • 官方提供的B2C页面脚本,保证页面能和B2C服务正常交互

这样配置完成后,当MFA流程走到对应步骤时,Azure B2C会直接跳转到你指定的独立页面,完全不需要依赖监听Ajax请求的临时方案,每个步骤都能实现独特的用户体验。

内容的提问来源于stack exchange,提问作者Justin Kofford

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 08:18:35