如何将自定义身份提供商集成到Azure AD B2C中?
Absolutely! You can absolutely integrate your existing WCF-based authentication system with Azure AD B2C—this is precisely the scenario that custom policies (formerly known as Identity Experience Framework policies) were built to handle. Let me break down how this works and the steps you’ll need to take:
Core Concept
Azure AD B2C’s built-in user flows are great for out-of-the-box scenarios, but when you need to hook into a custom authentication system (like your WCF service that validates against a SQL database), you’ll need to use custom policies. These policies let you extend B2C’s behavior to call external REST/SOAP services during the authentication journey.
Step-by-Step Implementation
1. Prepare Your WCF Service
First, make sure your WCF service is set up to:
- Accept user credentials (username/password) from Azure AD B2C
- Return a clear success/failure status (plus any user attributes you want to pass back, like display name or email)
- Use HTTPS for secure communication (critical for protecting credentials in transit)
If your WCF service uses SOAP, you can either:
- Directly configure B2C to call the SOAP endpoint (custom policies support this with some extra metadata), or
- Wrap the WCF service in a REST API (using tools like Azure API Management or a simple ASP.NET wrapper) for easier integration with B2C’s RESTful provider.
2. Set Up Azure AD B2C Custom Policies
Start with the base custom policy templates (you can grab these from Microsoft’s starter packs—look for the SocialAndLocalAccounts template as a starting point). Then, extend it to include your custom authentication step:
a. Add a REST/SOAP Technical Profile
Define a technical profile in your policy that points to your WCF service. Here’s an example of a REST-focused setup (adjust for SOAP if needed):
<ClaimsProviders> <ClaimsProvider> <DisplayName>Custom WCF Auth Service</DisplayName> <TechnicalProfiles> <TechnicalProfile Id="Restful-WCF-Authentication"> <DisplayName>Validate Credentials via WCF</DisplayName> <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.RestfulProvider, Web.TPEngine" /> <Metadata> <Item Key="ServiceUrl">https://your-wcf-service-domain/ValidateUserCredentials</Item> <Item Key="SendClaimsIn">Body</Item> <Item Key="AuthenticationType">None</Item> <!-- Use ClientCertificate/ApiKey if securing the service --> </Metadata> <InputClaims> <!-- Pass the user's input credentials to the WCF service --> <InputClaim ClaimTypeReferenceId="signInName" PartnerClaimType="username" /> <InputClaim ClaimTypeReferenceId="password" PartnerClaimType="password" /> </InputClaims> <OutputClaims> <!-- Capture the response from the WCF service --> <OutputClaim ClaimTypeReferenceId="authenticationSource" DefaultValue="customWcfAuth" /> <OutputClaim ClaimTypeReferenceId="displayName" PartnerClaimType="userDisplayName" /> </OutputClaims> <!-- No session management needed for this step --> <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" /> </TechnicalProfile> </TechnicalProfiles> </ClaimsProvider> </ClaimsProviders>
b. Update the User Journey
Modify your user journey to include this technical profile right after collecting the user’s credentials. For example, in the SignIn journey, add a step that calls your WCF validation service:
<UserJourney Id="SignIn"> <OrchestrationSteps> <!-- ... existing steps for collecting credentials ... --> <OrchestrationStep Order="3" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="ValidateCredentials" TechnicalProfileReferenceId="Restful-WCF-Authentication" /> </ClaimsExchanges> </OrchestrationStep> <!-- ... existing steps for issuing tokens ... --> </OrchestrationSteps> </UserJourney>
3. Handle Validation Results
- Success: If your WCF service confirms the credentials are valid, B2C will proceed with issuing an access/id token as usual, including any user attributes you passed back in the response.
- Failure: Configure the technical profile to return an error message when validation fails. B2C will display this error to the user (you can customize the error page via the policy).
4. Secure the Integration
- Encrypt Communication: Ensure your WCF service uses HTTPS to prevent credential snooping.
- Protect the WCF Service: Restrict access to your service using client certificates, API keys, or IP whitelisting (Azure AD B2C’s outbound IPs are documented if you need to whitelist them).
- Avoid Plaintext Passwords: Always transmit passwords over HTTPS, and ensure your WCF service handles them securely (e.g., hash them before comparing to your SQL database).
Final Notes
This approach lets you reuse your existing user database and authentication logic without migrating users to Azure AD B2C. You can even combine this with B2C’s built-in support for Facebook/Google logins—users can choose to sign in with their social accounts or your custom credentials, all through the same B2C flow.
内容的提问来源于stack exchange,提问作者CactusJack

