You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

上传策略失败:ClaimType元素含无效子元素,上传Claim报错求助

Fix for "ClaimType contains invalid child element" Error in B2C Custom Policies

Looks like you're hitting a common schema validation issue with Azure AD B2C custom policies. The error pops up because you're directly including a <Restriction> element inside your <ClaimType>—this structure isn't allowed in newer policy versions. Instead, validation rules need to be defined separately and referenced via <InputValidationReference> or <PredicateValidationReference>, which matches what the error message says it expects.

Here's how to fix your claim definition step-by-step:

1. Define Reusable Validation Rules

First, add these sections to your policy (usually placed inside the <BuildingBlocks> node, right next to <ClaimsSchema>):

<Predicates>
  <!-- Define the email regex check as a reusable predicate -->
  <Predicate Id="ValidEmailRegex" Method="MatchesRegex" HelpText="Please enter a valid email address.">
    <Parameters>
      <Parameter Id="RegularExpression">^[a-zA-Z0-9.!#$%&'^_`{}~-]+@[a-zA-Z0-9-]+(?:\.[a-zA-Z0-9-]+)*$</Parameter>
    </Parameters>
  </Predicate>
</Predicates>

<InputValidations>
  <!-- Wrap the predicate into an input validation set -->
  <InputValidation Id="EmailValidationSet">
    <PredicateValidations>
      <PredicateValidation ReferenceId="ValidEmailRegex" />
    </PredicateValidations>
  </InputValidation>
</InputValidations>

2. Update Your ClaimType to Use the Validation Reference

Replace your original <ClaimType> with this version—remove the <Restriction> element and add the validation reference instead:

<ClaimType Id="my-claim">
  <DisplayName>My Claim</DisplayName>
  <DataType>string</DataType>
  <UserHelpText>some text</UserHelpText>
  <UserInputType>TextBox</UserInputType>
  <!-- Link to the validation set we created -->
  <InputValidationReference Id="EmailValidationSet" />
  <!-- Keep your existing DefaultPartnerClaimTypes section here -->
  <DefaultPartnerClaimTypes>
    <Protocol Name="OAuth2" PartnerClaimType="email" />
    <!-- Add any other protocol mappings you need -->
  </DefaultPartnerClaimTypes>
</ClaimType>

Why This Fixes the Error

  • Predicates: These are single, reusable validation rules (like regex matches or length checks) that you can apply to multiple claims.
  • InputValidations: These group predicates into a logical set of rules tailored to a specific claim.
  • InputValidationReference: This connects your claim type to the validation set, which aligns perfectly with the schema requirements the error message outlined.

Once you update your policy to follow this structure, the upload should go through without that validation error.

内容的提问来源于stack exchange,提问作者spottedmahn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 07:02:07