如何从Azure AD B2C UserJourney获取Azure AD组及用户组成员身份
Alright, let's pick up where you left off to get those Azure AD group memberships pulled in when users log into your B2C app. Here's the step-by-step breakdown to finish this integration:
1. Double-Check Your Azure AD App Manifest Configuration
Since you already modified the app manifest, just confirm you set the groupMembershipClaims property correctly:
- Set it to
"SecurityGroup"if you only want security groups returned, or"All"if you need both security and distribution groups. - Example manifest snippet:
"groupMembershipClaims": "SecurityGroup"
2. Add a Groups Claim to Your Custom Policy's Schema
You need to define a claim to store the group data in your policy. Open your base custom policy and add this to the <ClaimsSchema> section:
<ClaimType Id="groups"> <DisplayName>User Groups</DisplayName> <DataType>stringCollection</DataType> <UserHelpText>Lists the Azure AD groups the user is a member of.</UserHelpText> </ClaimType>
3. Update the Azure AD Identity Provider Technical Profile
Find the technical profile that connects to your Azure AD tenant (typically named something like AAD-Common or AAD-UserReadUsingObjectId). Add an output claim to capture the group data from Azure AD:
<OutputClaim ClaimTypeReferenceId="groups" PartnerClaimType="groups" />
Note: By default, Azure AD returns only group IDs in this claim. If you need group display names instead, you'll have to add a REST API call or use a claims transformation to look up names via the Graph API using the group IDs.
4. Include the Groups Claim in Your Relying Party Policy
In your relying party (RP) policy (the one end-users use to initiate login), add the groups claim to the <OutputClaims> section so it's included in the token sent back to your application:
<OutputClaim ClaimTypeReferenceId="groups" />
5. Test the Login Flow
- Trigger your B2C login policy and sign in with a user who's part of Azure AD groups.
- After authentication, inspect the ID token returned to your app—you should see the
groupsclaim populated with the relevant group IDs.
Quick Troubleshooting Tips
- If groups aren't appearing: Confirm the user is a member of security groups (distribution groups won't show if you set
groupMembershipClaimsto"SecurityGroup"). - Permissions check: Basic group claims don't require extra permissions, but if you're using Graph API for additional group details, you'll need to grant your app
Group.Read.All(or similar) permissions. - Policy validation: Make sure the technical profile is correctly passing the
groupsclaim through to the relying party policy—double-check for typos in claim IDs.
内容的提问来源于stack exchange,提问作者Chad_C

