ADFS自定义声明规则需求:依据邮箱SMTP域切换NameID取值
实现ADFS条件性NameID声明规则:替换外部域邮箱为UPN
当然可以实现这个需求!ADFS的声明规则语言支持灵活的条件逻辑和字符串处理,我们只需要调整现有规则,加入域判断的逻辑就能动态选择NameID的取值。
核心思路
我们需要先提取邮箱地址的SMTP域名,然后判断该域名是否属于外部域:
- 如果是外部域(比如@microsoft.com),就用用户的UPN作为NameID的值
- 如果是内部域,继续使用原邮箱地址作为NameID
具体实现方案
这里提供两种写法,你可以根据习惯选择:
方案1:拆分规则(更易理解和维护)
首先添加一条提取邮箱域名的规则,把邮箱的域名部分存到临时声明里:
c:[Type == "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"] => issue(Type = "temp:emaildomain", Value = RegExReplace(c.Value, "^.*@(.*)$", "$1"));
然后添加两条条件性发声明的规则:
// 匹配外部域,发送UPN作为NameID c1:[Type == "temp:emaildomain", Value =~ "^(microsoft\.com|external\.com)$"] && c2:[Type == "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn"] => issue(Type = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier", Issuer = c2.Issuer, OriginalIssuer = c2.OriginalIssuer, Value = c2.Value, ValueType = c2.ValueType, Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/format"] = "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"); // 匹配内部域,发送原邮箱作为NameID c1:[Type == "temp:emaildomain", Value !~ "^(microsoft\.com|external\.com)$"] && c2:[Type == "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"] => issue(Type = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier", Issuer = c2.Issuer, OriginalIssuer = c2.OriginalIssuer, Value = c2.Value, ValueType = c2.ValueType, Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/format"] = "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress");
方案2:复合规则(更简洁)
如果你喜欢紧凑的写法,可以把逻辑合并到一条规则里,用If函数直接做判断:
c:[Type == "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"] && c2:[Type == "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn"] => issue( Type = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier", Issuer = c.Issuer, OriginalIssuer = c.OriginalIssuer, Value = If(RegExMatch(c.Value, "^.*@(microsoft\.com|external\.com)$"), c2.Value, c.Value), ValueType = c.ValueType, Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/format"] = "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" );
注意事项
- 确保ADFS能读取到用户的UPN声明:默认情况下ADFS会从Active Directory中提取用户的UPN属性,只要用户对象有合法的UPN值就没问题
- 调整正则表达式中的域名列表:把
microsoft\.com|external\.com替换成你实际需要识别的外部域,多个域用|分隔,注意点号要转义成\. - 测试验证:可以用ADFS的测试工具模拟用户请求,或者用
Get-AdfsClaimRuleSet命令查看规则配置,确认声明生成符合预期
内容的提问来源于stack exchange,提问作者a b
相关产品推荐
相关产品推荐

