You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AD B2C自定义策略新增Azure AD登录后忘记密码流程故障排查

修复AD B2C自定义策略中忘记密码流程失效问题

问题根源是你注释了登录页面触发忘记密码的核心配置,同时编排步骤的前置条件需微调,以下是具体修复方案:

1. 恢复登录页面的忘记密码触发配置

在第一步CombinedSignInAndSignUp的ClaimsProviderSelections和ClaimsExchanges中,取消注释ForgotPasswordExchange相关配置,让登录页的"忘记密码"按钮能关联到对应流程。

2. 调整忘记密码流程的前置条件

第三步需增加对isForgotPassword的判断,确保只有用户点击忘记密码时才执行该步骤,避免干扰正常登录流程。

修改后的完整OrchestrationSteps配置

<OrchestrationSteps>
    <OrchestrationStep Order="1" Type="CombinedSignInAndSignUp" ContentDefinitionReferenceId="api.signuporsignin">
      <ClaimsProviderSelections>
        <!-- <ClaimsProviderSelection TargetClaimsExchangeId="FacebookExchange"/> -->
        <ClaimsProviderSelection ValidationClaimsExchangeId="LocalAccountSigninEmailExchange" />
        <!-- External extra Ids -->
        <ClaimsProviderSelection TargetClaimsExchangeId="AzureADCommonExchange" />      
        <ClaimsProviderSelection ValidationClaimsExchangeId="ForgotPasswordExchange" />
      </ClaimsProviderSelections>
      <ClaimsExchanges>
        <ClaimsExchange Id="LocalAccountSigninEmailExchange" TechnicalProfileReferenceId="SelfAsserted-LocalAccountSignin-Email" />
        <ClaimsExchange Id="ForgotPasswordExchange" TechnicalProfileReferenceId="ForgotPassword" />
        <!-- The AADCommon TP you added per earlier steps -->
        <!--<ClaimsExchange Id="AzureADCommonExchange"  TechnicalProfileReferenceId="AADCommon-OpenIdConnect" />-->         
      </ClaimsExchanges>
    </OrchestrationStep>
    
    <!-- Step 2: run the AADCommon (this satisfies the TargetClaimsExchangeId) -->
    <OrchestrationStep Order="2" Type="ClaimsExchange">
    <Preconditions>
        <!-- Skip this step unless they came via the Work/School button -->
         <Precondition Type="ClaimsExist" ExecuteActionsIf="true">
            <Value>isForgotPassword</Value>
            <Action>SkipThisOrchestrationStep</Action>
          </Precondition>
        <Precondition Type="ClaimEquals" ExecuteActionsIf="true">
          <Value>authenticationSource</Value>
          <Value>localAccountAuthentication</Value>
          <Action>SkipThisOrchestrationStep</Action>
        </Precondition>
    </Preconditions>
      <ClaimsExchanges>
        <ClaimsExchange Id="AzureADCommonExchange" TechnicalProfileReferenceId="AADCommon-OpenIdConnect" />
      </ClaimsExchanges>
    </OrchestrationStep>

       <!-- wireup the ForgotPassword exchange -->
       <OrchestrationStep Order="3" Type="ClaimsExchange">
        <Preconditions>
          <Precondition Type="ClaimsExist" ExecuteActionsIf="true">
            <Value>objectId</Value>
            <Action>SkipThisOrchestrationStep</Action>
          </Precondition>
          <Precondition Type="ClaimsExist" ExecuteActionsIf="false">
            <Value>isForgotPassword</Value>
            <Action>SkipThisOrchestrationStep</Action>
          </Precondition>
        </Preconditions>
        <ClaimsExchanges>              
          <ClaimsExchange Id="ForgotPasswordExchange" TechnicalProfileReferenceId="ForgotPassword" />
        </ClaimsExchanges>
      </OrchestrationStep>
      <!-- run password reset flow if user clicked forgot password -->
      <OrchestrationStep Order="4" Type="InvokeSubJourney">
        <Preconditions>
          <Precondition Type="ClaimsExist" ExecuteActionsIf="false">
            <Value>isForgotPassword</Value>
            <Action>SkipThisOrchestrationStep</Action>
          </Precondition>
        </Preconditions>
        <JourneyList>
          <Candidate SubJourneyReferenceId="PasswordReset" />
        </JourneyList>
      </OrchestrationStep>
</OrchestrationSteps>

关键说明

  • 恢复ForgotPasswordExchange配置后,登录页的忘记密码按钮会正确触发流程。
  • 第三步新增的前置条件确保仅在用户触发忘记密码时执行该步骤,避免与本地账户、工作/学校账户的登录流程冲突。
  • 第二步已包含对isForgotPassword的判断,会跳过工作/学校账户的验证流程,让忘记密码流程直接进入后续步骤。

内容的提问来源于stack exchange,提问作者Sai

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 15:43:15