AD B2C自定义策略新增Azure AD登录后忘记密码流程故障排查
修复AD B2C自定义策略中忘记密码流程失效问题
问题根源是你注释了登录页面触发忘记密码的核心配置,同时编排步骤的前置条件需微调,以下是具体修复方案:
1. 恢复登录页面的忘记密码触发配置
在第一步CombinedSignInAndSignUp的ClaimsProviderSelections和ClaimsExchanges中,取消注释ForgotPasswordExchange相关配置,让登录页的"忘记密码"按钮能关联到对应流程。
2. 调整忘记密码流程的前置条件
第三步需增加对isForgotPassword的判断,确保只有用户点击忘记密码时才执行该步骤,避免干扰正常登录流程。
修改后的完整OrchestrationSteps配置
<OrchestrationSteps> <OrchestrationStep Order="1" Type="CombinedSignInAndSignUp" ContentDefinitionReferenceId="api.signuporsignin"> <ClaimsProviderSelections> <!-- <ClaimsProviderSelection TargetClaimsExchangeId="FacebookExchange"/> --> <ClaimsProviderSelection ValidationClaimsExchangeId="LocalAccountSigninEmailExchange" /> <!-- External extra Ids --> <ClaimsProviderSelection TargetClaimsExchangeId="AzureADCommonExchange" /> <ClaimsProviderSelection ValidationClaimsExchangeId="ForgotPasswordExchange" /> </ClaimsProviderSelections> <ClaimsExchanges> <ClaimsExchange Id="LocalAccountSigninEmailExchange" TechnicalProfileReferenceId="SelfAsserted-LocalAccountSignin-Email" /> <ClaimsExchange Id="ForgotPasswordExchange" TechnicalProfileReferenceId="ForgotPassword" /> <!-- The AADCommon TP you added per earlier steps --> <!--<ClaimsExchange Id="AzureADCommonExchange" TechnicalProfileReferenceId="AADCommon-OpenIdConnect" />--> </ClaimsExchanges> </OrchestrationStep> <!-- Step 2: run the AADCommon (this satisfies the TargetClaimsExchangeId) --> <OrchestrationStep Order="2" Type="ClaimsExchange"> <Preconditions> <!-- Skip this step unless they came via the Work/School button --> <Precondition Type="ClaimsExist" ExecuteActionsIf="true"> <Value>isForgotPassword</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> <Precondition Type="ClaimEquals" ExecuteActionsIf="true"> <Value>authenticationSource</Value> <Value>localAccountAuthentication</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="AzureADCommonExchange" TechnicalProfileReferenceId="AADCommon-OpenIdConnect" /> </ClaimsExchanges> </OrchestrationStep> <!-- wireup the ForgotPassword exchange --> <OrchestrationStep Order="3" Type="ClaimsExchange"> <Preconditions> <Precondition Type="ClaimsExist" ExecuteActionsIf="true"> <Value>objectId</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> <Precondition Type="ClaimsExist" ExecuteActionsIf="false"> <Value>isForgotPassword</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <ClaimsExchanges> <ClaimsExchange Id="ForgotPasswordExchange" TechnicalProfileReferenceId="ForgotPassword" /> </ClaimsExchanges> </OrchestrationStep> <!-- run password reset flow if user clicked forgot password --> <OrchestrationStep Order="4" Type="InvokeSubJourney"> <Preconditions> <Precondition Type="ClaimsExist" ExecuteActionsIf="false"> <Value>isForgotPassword</Value> <Action>SkipThisOrchestrationStep</Action> </Precondition> </Preconditions> <JourneyList> <Candidate SubJourneyReferenceId="PasswordReset" /> </JourneyList> </OrchestrationStep> </OrchestrationSteps>
关键说明
- 恢复
ForgotPasswordExchange配置后,登录页的忘记密码按钮会正确触发流程。 - 第三步新增的前置条件确保仅在用户触发忘记密码时执行该步骤,避免与本地账户、工作/学校账户的登录流程冲突。
- 第二步已包含对
isForgotPassword的判断,会跳过工作/学校账户的验证流程,让忘记密码流程直接进入后续步骤。
内容的提问来源于stack exchange,提问作者Sai
相关产品推荐
相关产品推荐

