You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C Token含name字段,但User.Identity.Name为何为空?

Why is @User.Identity.Name empty when my Azure AD B2C token has a valid 'name' claim?

Great question—this is a super common gotcha when working with Azure AD B2C and ASP.NET Core. The short answer is that ASP.NET Core doesn’t automatically map the raw 'name' claim from your B2C token to the User.Identity.Name property by default. Let’s break down why this happens and how to fix it:

1. Default Claim Mapping Mismatch

By default, ASP.NET Core expects the User.Identity.Name property to be populated from the claim with the type http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name (aka ClaimTypes.Name in .NET). But Azure AD B2C returns the user’s name as a simple claim type "name" in the JWT.

To fix this, you need to explicitly map the "name" claim from your B2C token to the standard ClaimTypes.Name in your authentication configuration. Add this to your OpenID Connect setup (in Program.cs or Startup.cs):

builder.Services.AddAuthentication(OpenIdConnectDefaults.AuthenticationScheme)
    .AddMicrosoftIdentityWebApp(options =>
    {
        // Your existing B2C configuration here...
        options.Instance = "https://yourtenant.b2clogin.com/";
        options.Domain = "yourtenant.onmicrosoft.com";
        options.ClientId = "your-client-id";
        options.ClientSecret = "your-client-secret";
        options.TenantId = "your-tenant-id";
        options.SignInScheme = CookieAuthenticationDefaults.AuthenticationScheme;

        // Add this line to map the 'name' claim to ClaimTypes.Name
        options.ClaimActions.MapUniqueJsonKey(ClaimTypes.Name, "name");
    });

2. Token Validation Configuration

Another way to force the framework to use the "name" claim directly for User.Identity.Name is to set the NameClaimType in the token validation parameters:

options.TokenValidationParameters = new TokenValidationParameters
{
    NameClaimType = "name",
    // Keep other default validation parameters here...
};

This tells ASP.NET Core to use the "name" claim from the JWT as the source for User.Identity.Name, skipping the need for explicit claim mapping.

3. Verify Claims Are Present First

Before troubleshooting further, it’s a good idea to confirm the "name" claim is actually being received by your app. Add this snippet to your _Layout.cshtml to list all claims associated with the user:

<div>
    <h4>User Claims:</h4>
    @foreach (var claim in User.Claims)
    {
        <p><strong>@claim.Type:</strong> @claim.Value</p>
    }
</div>

If you see the "name" claim in this list but User.Identity.Name is still empty, that confirms the issue is the mapping mismatch we covered above. If the "name" claim isn’t present at all, double-check your B2C user flow or custom policy to ensure it’s configured to include the name attribute in the token.


内容的提问来源于stack exchange,提问作者aBlaze

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 03:38:09