You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ADFS自定义声明规则需求:依据邮箱SMTP域切换NameID取值

实现ADFS条件性NameID声明规则:替换外部域邮箱为UPN

当然可以实现这个需求!ADFS的声明规则语言支持灵活的条件逻辑和字符串处理,我们只需要调整现有规则,加入域判断的逻辑就能动态选择NameID的取值。

核心思路

我们需要先提取邮箱地址的SMTP域名,然后判断该域名是否属于外部域:

  • 如果是外部域(比如@microsoft.com),就用用户的UPN作为NameID的值
  • 如果是内部域,继续使用原邮箱地址作为NameID

具体实现方案

这里提供两种写法,你可以根据习惯选择:

方案1:拆分规则(更易理解和维护)

首先添加一条提取邮箱域名的规则,把邮箱的域名部分存到临时声明里:

c:[Type == "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"] 
=> issue(Type = "temp:emaildomain", Value = RegExReplace(c.Value, "^.*@(.*)$", "$1"));

然后添加两条条件性发声明的规则:

// 匹配外部域,发送UPN作为NameID
c1:[Type == "temp:emaildomain", Value =~ "^(microsoft\.com|external\.com)$"] && c2:[Type == "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn"]
=> issue(Type = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier", Issuer = c2.Issuer, OriginalIssuer = c2.OriginalIssuer, Value = c2.Value, ValueType = c2.ValueType, Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/format"] = "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress");

// 匹配内部域,发送原邮箱作为NameID
c1:[Type == "temp:emaildomain", Value !~ "^(microsoft\.com|external\.com)$"] && c2:[Type == "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"]
=> issue(Type = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier", Issuer = c2.Issuer, OriginalIssuer = c2.OriginalIssuer, Value = c2.Value, ValueType = c2.ValueType, Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/format"] = "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress");

方案2:复合规则(更简洁)

如果你喜欢紧凑的写法,可以把逻辑合并到一条规则里,用If函数直接做判断:

c:[Type == "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"] && c2:[Type == "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn"]
=> issue(
    Type = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier", 
    Issuer = c.Issuer, 
    OriginalIssuer = c.OriginalIssuer, 
    Value = If(RegExMatch(c.Value, "^.*@(microsoft\.com|external\.com)$"), c2.Value, c.Value), 
    ValueType = c.ValueType, 
    Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/format"] = "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"
);

注意事项

  • 确保ADFS能读取到用户的UPN声明:默认情况下ADFS会从Active Directory中提取用户的UPN属性,只要用户对象有合法的UPN值就没问题
  • 调整正则表达式中的域名列表:把microsoft\.com|external\.com替换成你实际需要识别的外部域,多个域用|分隔,注意点号要转义成\.
  • 测试验证:可以用ADFS的测试工具模拟用户请求,或者用Get-AdfsClaimRuleSet命令查看规则配置,确认声明生成符合预期

内容的提问来源于stack exchange,提问作者a b

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 06:15:32