Azure AD B2C自定义策略配置SAML IdP时声明缺失问题咨询
我之前帮客户处理过完全相同的B2C自定义策略作为SAML IdP对接ADFS的场景,针对你遇到的声明缺失问题,给你几个核心的排查和修复方向:
检查自定义策略的ClaimSchema与OutputClaims配置
必须确保在RelyingParty节点的OutputClaims中明确列出要发送给ADFS的所有声明,同时要保证这些声明已经在ClaimSchema中定义,并且配置正确的PartnerClaimType(匹配ADFS RP期望的声明URI)。示例片段:<RelyingParty> <DefaultUserJourney ReferenceId="SignUpOrSignIn" /> <TechnicalProfile Id="PolicyProfile"> <DisplayName>PolicyProfile</DisplayName> <Protocol Name="SAML2" /> <OutputClaims> <OutputClaim ClaimTypeReferenceId="email" PartnerClaimType="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress" /> <OutputClaim ClaimTypeReferenceId="givenName" PartnerClaimType="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname" /> <OutputClaim ClaimTypeReferenceId="surname" PartnerClaimType="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname" /> <OutputClaim ClaimTypeReferenceId="objectId" PartnerClaimType="http://schemas.microsoft.com/identity/claims/objectidentifier" /> </OutputClaims> <SubjectNamingInfo ClaimType="email" /> </TechnicalProfile> </RelyingParty>验证UserJourney是否正确收集声明
确保在用户登录后的编排步骤中,调用了读取用户属性的技术Profile(比如AAD-UserReadUsingObjectId),否则B2C无法获取用户的属性声明。示例编排步骤:<OrchestrationStep Order="2" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="AADUserReadWithObjectId" TechnicalProfileReferenceId="AAD-UserReadUsingObjectId" /> </ClaimsExchanges> </OrchestrationStep>检查SAML断言生成的技术Profile配置
在负责生成SAML断言的技术Profile(通常命名为Saml2AssertionIssuer)中,确认Subject和AttributeStatements正确引用了要发送的声明。示例片段:<TechnicalProfile Id="Saml2AssertionIssuer"> <DisplayName>SAML Assertion Issuer</DisplayName> <Protocol Name="SAML2" /> <OutputTokenFormat>SAML2</OutputTokenFormat> <Metadata> <Item Key="IssuerUri">https://your-b2c-tenant.b2clogin.com/your-b2c-tenant.onmicrosoft.com/B2C_1A_custom_saml_idp</Item> </Metadata> <CryptographicKeys> <Key Id="MetadataSigning" StorageReferenceId="B2C_1A_SamlIdpCert" /> <Key Id="SamlAssertionSigning" StorageReferenceId="B2C_1A_SamlIdpCert" /> </CryptographicKeys> <InputClaims /> <OutputClaims> <OutputClaim ClaimTypeReferenceId="email" /> <OutputClaim ClaimTypeReferenceId="givenName" /> <OutputClaim ClaimTypeReferenceId="surname" /> <OutputClaim ClaimTypeReferenceId="objectId" /> </OutputClaims> <Subject> <NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</NameIDFormat> <SubjectClaimTypeReferenceId="email" /> </Subject> <AttributeStatements> <AttributeStatement> <Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname"> <AttributeValue ClaimTypeReferenceId="givenName" /> </Attribute> <Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname"> <AttributeValue ClaimTypeReferenceId="surname" /> </Attribute> </AttributeStatement> </AttributeStatements> </TechnicalProfile>排查ADFS RP的信任配置
确保ADFS的信赖方信任中,声明规则正确映射了B2C发送的声明。比如,如果B2C发送email声明,ADFS需要创建规则将其映射到ADFS内部的Email Address声明。同时检查ADFS是否有过滤掉某些声明的配置。启用B2C日志进行精准排查
通过Application Insights启用B2C的日志记录,查看ClaimsIssued事件,就能看到B2C实际生成的SAML断言中包含的声明列表,从而定位是声明未收集到还是未正确发送。
如果以上步骤仍未解决问题,可以提供自定义策略中RelyingParty、UserJourney和SAML断言技术Profile的相关代码片段,以便更精准地定位问题。
内容的提问来源于stack exchange,提问作者Brady

