如何在登录时通过 JWT 令牌从 Azure Active Directory 传递自定义扩展属性?

Nor*_*ler 6 jwt azure-active-directory openid-connect

我在 Azure Active Directory 中有自定义扩展属性(通过 Azure AD Connect 映射)。Azure AD 上的扩展属性采用以下形式extension_<uniqueid>_<attributename>。

当用户通过 Open ID Connect 登录时,我想向应用程序公开多个扩展属性。这些属性应包含在 JWT 令牌中。

我尝试使用Microsoft 页面中的方法创建策略并将其分配给想要在登录时接收令牌的应用程序的服务主体 ID。

这些是我使用的 powershell 命令。

Connect-AzureAD -Confirm

New-AzureADPolicy -Definition @('{"ClaimsMappingPolicy":{"Version":1,"IncludeBasicClaimSet":"true","ClaimsSchema":[{"Source":"user","ID":"extension_uniqueidretracted_extensionAttribute13","SamlClaimType":"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/extensionAttribute13","JwtClaimType":"MyCustomClaim1"},{"Source":"user","ID":"extension_uniqueidretracted_extensionAttribute14","SamlClaimType":"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/extensionAttribute14","JwtClaimType":"MyCustomClaim2"}]}}') -DisplayName "ExtensionAttributeMapping" -Type "ClaimsMappingPolicy"

Add-AzureADServicePrincipalPolicy -Id <ObjectId of the ServicePrincipal> -RefObjectId <ObjectId of the Policy>
Run Code Online (Sandbox Code Playgroud)

创建和分配策略可以工作,但属性仍然不包含在令牌中。

我需要做什么才能使这项工作成功?

Kal*_*hna 1

您需要使用可选的声明功能来获取访问令牌中可用的扩展属性中的信息。

请阅读文档配置目录扩展可选声明,它解释了如何实现这一点。