You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure ADB2C自定义策略:预填充邮箱设为只读遇配置报错

解决Azure AD B2C自定义策略上传报错及预填只读邮箱配置方案

问题1:TrustFrameworkExtensions.xml上传报错「引用的SelfAsserted-Email技术配置文件不存在」

原因及修复步骤

  • 若你的TrustFrameworkBase.xml中未定义SelfAsserted-Email技术配置文件,需在TrustFrameworkExtensions.xml中手动添加该配置,同时确保邮箱声明(Claim)已定义:
    1. 先在ClaimsSchema节点下添加邮箱声明:
    <ClaimsSchema>
      <ClaimType Id="email">
        <DisplayName>Email Address</DisplayName>
        <DataType>string</DataType>
        <UserHelpText>Your email address</UserHelpText>
        <UserInputType>TextBox</UserInputType>
      </ClaimType>
    </ClaimsSchema>
    
    1. 在ClaimsProviders节点下添加SelfAsserted-Email技术配置文件(实现预填+只读逻辑):
    <ClaimsProvider>
      <DisplayName>Self Asserted</DisplayName>
      <TechnicalProfiles>
        <TechnicalProfile Id="SelfAsserted-Email">
          <DisplayName>Verify Email</DisplayName>
          <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null" />
          <Metadata>
            <Item Key="ContentDefinitionReferenceId">api.selfasserted</Item>
          </Metadata>
          <!-- 从邀请链接的email参数预填,设置为只读 -->
          <InputClaims>
            <InputClaim ClaimTypeReferenceId="email" DefaultValue="{OAUTH-KV:email}" ReadOnly="true" />
          </InputClaims>
          <OutputClaims>
            <OutputClaim ClaimTypeReferenceId="email" />
          </OutputClaims>
          <UseTechnicalProfileForSessionManagement ReferenceId="SM-Noop" />
        </TechnicalProfile>
      </TechnicalProfiles>
    </ClaimsProvider>
    
  • 检查配置中引用的技术配置文件ID是否拼写错误,比如误写为SelfAsserted-Email而实际Base策略中是SelfAssertedPasswordReset,需统一ID名称。

问题2:PasswordReset.xml上传报错「PolicyProfile的SubjectNamingInfo指定的sub声明未在OutputClaims中匹配」

原因及修复步骤

该报错是因为PolicyProfile的SubjectNamingInfo指定了sub作为主体标识,但OutputClaims中未包含该声明,修复如下:
打开PasswordReset.xml中的PolicyProfile技术配置节点,在OutputClaims中添加sub声明:

<TechnicalProfile Id="PolicyProfile">
  <DisplayName>PolicyProfile</DisplayName>
  <Protocol Name="OpenIdConnect" />
  <OutputClaims>
    <OutputClaim ClaimTypeReferenceId="sub" />
    <OutputClaim ClaimTypeReferenceId="email" />
    <!-- 保留其他原有输出声明 -->
  </OutputClaims>
  <SubjectNamingInfo ClaimType="sub" />
</TechnicalProfile>

同时确保前置技术配置文件(如LocalAccountWritePasswordUsingObjectId)已输出sub声明,或直接从用户对象中映射该声明。

核心需求验证

完成上述配置后,管理员生成的邀请链接需携带email参数(格式示例:https://your-b2c-domain.com/your-reset-policy?email=user@example.com),用户点击后进入重置密码界面时,邮箱字段会自动填充且无法编辑,符合需求。

内容的提问来源于stack exchange,提问作者Tinaira

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 04:02:35