Home

Issues in Azure B2C Active directory custom policies customization for Local account

%3CLINGO-SUB%20id%3D%22lingo-sub-707158%22%20slang%3D%22en-US%22%3EIssues%20in%20Azure%20B2C%20Active%20directory%20custom%20policies%20customization%20for%20Local%20account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-707158%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EWe%20are%20having%20few%20issues%20or%20not%20able%20to%20find%20solution%20with%20respect%20to%20below%20requirement%20Azure%20B2C%20AD%20custom%20policies%20customization%20for%20Local%20Account.%3C%2FP%3E%3CP%3EBackground%3A%20We%20are%20using%20B2C%20AD%20local%20accounts%20to%20implement%20SSO%20for%20our%20one%20web%20application.%20We%20are%20trying%20to%20achieve%20JIT%20user%20migration%20and%20for%20that%20we%20have%20implemented%20custom%20policies%20user%20flows%20for%20sign%20in%20and%20sign%20up.%20We%20are%20having%20two%20different%20domains%20for%20which%20we%20are%20having%20some%20unique%20properties%20which%20needs%20to%20saved%20as%20collection%20against%20same%20local%20Identity.%3C%2FP%3E%3CP%3EWe%20have%20identified%20useridentities%20attribute%20of%20User%20account%20where%20we%20can%20store%20information%20as%20below%3A%3C%2FP%3E%3CP%3E%22userIdentities%22%3A%7B%3C%2FP%3E%3CP%3E%7B%3C%2FP%3E%3CP%3E%22issuer%22%3A%20%22CLIENT_ID1%22%3C%2FP%3E%3CP%3E%22%C3%AFssuerUserId%22%3A%20%22shopper_Id1%22%3C%2FP%3E%3CP%3E%7D%2C%3C%2FP%3E%3CP%3E%7B%3C%2FP%3E%3CP%3E%22issuer%22%3A%20%22CLIENT_ID2%22%3C%2FP%3E%3CP%3E%22%C3%AFssuerUserId%22%3A%20%22shopper_Id2%22%3C%2FP%3E%3CP%3E%7D%3C%2FP%3E%3CP%3E%7D%3C%2FP%3E%3CP%3EWe%20wanted%20to%20retrieve%20useridentity%20from%20above%20collection%20based%20on%20issuer%20value.%3C%2FP%3E%3CP%3E%3CSPAN%3E1.%20Do%20we%20have%20any%20claim%20transformation%20method%20which%20can%20be%20used%20to%20get%20useridentity%20based%20on%20issuer%20value%20for%20e.g.%20%E2%80%9CClient_ID1%E2%80%9D%20as%20input%20claim%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EAlso%20we%20have%20noticed%20while%20storing%20issuerUserID%20its%20converting%20actual%20value%20in%20binary%20and%20then%20storing%20in%20user%20account.%20PFA%20screenshot.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E2.%20Do%20we%20have%20any%20claim%20transformation%20method%20which%20can%20be%20used%20to%20transform%20issuerUserID%E2%80%99s%20binary%20value%20to%20string%3F%3CBR%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E3.%3CSPAN%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3C%2FSPAN%3EAs%20per%20the%20document%20we%20can%20retrieve%20Client%20Id%20value%20from%20querystring%20in%20custom%20policies%20using%20%22%7BOIDC%3AClientId%7D%22%20but%20when%20we%20actually%20implemented%20it%20in%20custom%20policy%20it%20is%20not%20returning%20actual%20GUID%2C%20it%20is%20storing%20value%20in%20string%20as%20is%20%22%7BOIDC%3AClientId%7D%22.%20We%20want%20solution%20for%20this%3C%2FSPAN%3E%3C%2FP%3E%3CDIV%3E%3CDIV%3E%3CDIV%3E%3CDIV%3E%3CSPAN%3E%22%3CINPUTCLAIMS%3E%3C%2FINPUTCLAIMS%3E%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%3CINPUTCLAIM%3E%3C%2FINPUTCLAIM%3E%3C%2FSPAN%3E%20%3CSPAN%3EClaimTypeReferenceId%3C%2FSPAN%3E%3CSPAN%3E%3D%3C%2FSPAN%3E%3CSPAN%3E%22clientId%22%3C%2FSPAN%3E%20%3CSPAN%3EDefaultValue%3C%2FSPAN%3E%3CSPAN%3E%3D%3C%2FSPAN%3E%3CSPAN%3E%22%7BOIDC%3AClientId%7D%22%3C%2FSPAN%3E%20%3CSPAN%3E%2F%26gt%3B%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%3C%2FSPAN%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%22%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CP%3E%3CSPAN%3EThanks%20in%20advance.%20Please%20help%20us%20ASAP%20we%20stuck%20in%20our%20implementation%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3ERegards%2C%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3ESameer%20Salunke%3C%2FSPAN%3E%3C%2FP%3E%3CLINGO-LABS%20id%3D%22lingo-labs-707158%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20B2C%20AD%20Custom%20policies%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Sameer Salunke
Occasional Contributor

Hi,

We are having few issues or not able to find solution with respect to below requirement Azure B2C AD custom policies customization for Local Account.

Background: We are using B2C AD local accounts to implement SSO for our one web application. We are trying to achieve JIT user migration and for that we have implemented custom policies user flows for sign in and sign up. We are having two different domains for which we are having some unique properties which needs to saved as collection against same local Identity.

We have identified useridentities attribute of User account where we can store information as below:

"userIdentities":{

{

"issuer": "CLIENT_ID1"

"ïssuerUserId": "shopper_Id1"

},

{

"issuer": "CLIENT_ID2"

"ïssuerUserId": "shopper_Id2"

}

}

We wanted to retrieve useridentity from above collection based on issuer value.

1. Do we have any claim transformation method which can be used to get useridentity based on issuer value for e.g. “Client_ID1” as input claim?

Also we have noticed while storing issuerUserID its converting actual value in binary and then storing in user account. PFA screenshot.

2. Do we have any claim transformation method which can be used to transform issuerUserID’s binary value to string?

3.      As per the document we can retrieve Client Id value from querystring in custom policies using "{OIDC:ClientId}" but when we actually implemented it in custom policy it is not returning actual GUID, it is storing value in string as is "{OIDC:ClientId}". We want solution for this

"<InputClaims>
<InputClaim ClaimTypeReferenceId="clientId" DefaultValue="{OIDC:ClientId}" />
</InputClaims>"
 

Thanks in advance. Please help us ASAP we stuck in our implementation

 

Regards,

Sameer Salunke

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
ChirmyRam in Discussions on
3 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies