diff --git a/policies/embedded-sign-in/policy/SignUpOrSigninEmbedded.xml b/policies/embedded-sign-in/policy/SignUpOrSigninEmbedded.xml new file mode 100644 index 00000000..837e4503 --- /dev/null +++ b/policies/embedded-sign-in/policy/SignUpOrSigninEmbedded.xml @@ -0,0 +1,39 @@ + + + + + yourtenant.onmicrosoft.com + B2C_1A_TrustFrameworkExtensions_Embedded + + + + + + + + + PolicyProfile + + + + + + + + + + + + + + + + + + diff --git a/policies/embedded-sign-in/policy/TrustFrameworkBaseEmbedded.xml b/policies/embedded-sign-in/policy/TrustFrameworkBaseEmbedded.xml new file mode 100644 index 00000000..06a5dca8 --- /dev/null +++ b/policies/embedded-sign-in/policy/TrustFrameworkBaseEmbedded.xml @@ -0,0 +1,892 @@ + + + + + + + + + + + + + Username + string + + TextBox + + + + + + + User's Object's Tenant ID + string + + + + + + Tenant identifier (ID) of the user object in Azure AD. + + + + User's Object ID + string + + + + + + Object identifier (ID) of the user object in Azure AD. + + + + + Sign in name + string + + TextBox + + + + Email Address + string + Email address to use for signing in. + TextBox + + + + Account Enabled + boolean + Specifies whether the user's account is enabled. + Specifies whether your account is enabled. + + + + Password + string + Enter password + Password + + + + + New Password + string + Enter new password + Password + + + + + + + + Confirm New Password + string + Confirm new password + Password + + + + + + + Password Policies + string + Password policies used by Azure AD to determine password strength, expiry etc. + + + + client_id + string + Special parameter passed to EvoSTS. + Special parameter passed to EvoSTS. + + + + resource_id + string + Special parameter passed to EvoSTS. + Special parameter passed to EvoSTS. + + + + Subject + string + + + + + + + + Identity Provider + string + + + + + + + + + + Display Name + string + + + + + + Your display name. + TextBox + + + + Email Address + string + + + + Email address that can be used to contact you. + TextBox + + + + + + + Alternate Email Addresses + stringCollection + Email addresses that can be used to contact the user. + + + + UserPrincipalName + string + + + + + + Your user name as stored in the Azure Active Directory. + + + + UPN User Name + string + The user name for creating user principal name. + + + + User is new + boolean + + + + + Executed-SelfAsserted-Input + string + A claim that specifies whether attributes were collected from the user. + + + + AuthenticationSource + string + Specifies whether the user was authenticated at Social IDP or local account. + + + + + + nca + string + Special parameter passed for local account authentication to login.microsoftonline.com. + + + + grant_type + string + Special parameter passed for local account authentication to login.microsoftonline.com. + + + + scope + string + Special parameter passed for local account authentication to login.microsoftonline.com. + + + + objectIdFromSession + boolean + Parameter provided by the default session management provider to indicate that the object id has been retrieved from an SSO session. + + + + isActiveMFASession + boolean + Parameter provided by the MFA session management to indicate that the user has an active MFA session. + + + + + + Given Name + string + + + + + + Your given name (also known as first name). + TextBox + + + + Surname + string + + + + + + Your surname (also known as family name or last name). + TextBox + + + + + + + + + + + + + + + + + + + + + + + + + + + + LineMarkers, MetaRefresh + + + + + + + + ~/tenant/templates/AzureBlue/exception.cshtml + ~/common/default_page_error.html + urn:com:microsoft:aad:b2c:elements:contract:globalexception:1.2.1 + + Error page + + + + + ~/tenant/templates/AzureBlue/idpSelector.cshtml + ~/common/default_page_error.html + urn:com:microsoft:aad:b2c:elements:contract:providerselection:1.2.1 + + Idp selection page + Sign in + + + + + ~/tenant/templates/AzureBlue/idpSelector.cshtml + ~/common/default_page_error.html + urn:com:microsoft:aad:b2c:elements:contract:providerselection:1.2.1 + + Idp selection page + Sign up + + + + + ~/tenant/templates/AzureBlue/unified.cshtml + ~/common/default_page_error.html + urn:com:microsoft:aad:b2c:elements:contract:unifiedssp:2.1.2 + + Signin and Signup + + + + + ~/tenant/templates/AzureBlue/selfAsserted.cshtml + ~/common/default_page_error.html + urn:com:microsoft:aad:b2c:elements:contract:selfasserted:2.1.2 + + Collect information from user page + + + + + ~/tenant/templates/AzureBlue/selfAsserted.cshtml + ~/common/default_page_error.html + urn:com:microsoft:aad:b2c:elements:contract:selfasserted:2.1.2 + + Collect information from user page + + + + + ~/tenant/templates/AzureBlue/selfAsserted.cshtml + ~/common/default_page_error.html + urn:com:microsoft:aad:b2c:elements:contract:selfasserted:2.1.2 + + Local account sign up page + + + + + ~/tenant/templates/AzureBlue/selfAsserted.cshtml + ~/common/default_page_error.html + urn:com:microsoft:aad:b2c:elements:contract:selfasserted:2.1.2 + + Local account change password page + + + + + + + + + + + Local Account SignIn + + + Local Account SignIn + + + We can't seem to find your account + Your password is incorrect + Looks like you used an old password + + https://sts.windows.net/ + https://login.microsoftonline.com/{tenant}/.well-known/openid-configuration + https://login.microsoftonline.com/{tenant}/oauth2/token + id_token + query + email openid + password + + + false + POST + + + + + + + + + + + + + + + + + + + + + + + Azure Active Directory + + + + Azure Active Directory + + + + + + + + false + + + + + + + + Write + true + + false + + + + + + + + + + + + + + + + + + + + + + + + + + + + Read + true + An account could not be found for the provided user ID. + + false + + + + + + + + + + + + + + + + + + + + + + + + Write + true + + false + + + + + + + + + + + + + + + + Write + false + true + + false + + + + + + + + + + + + + + + + + + Read + true + + false + + + + + + + + + + + + + + + + + + + + Self Asserted + + + + User ID signup + + + api.selfasserted.profileupdate + + false + + + + + + + + + + + + + + + + + + + + + + + + + Local Account + + + + Email signup + + + IpAddress + api.localaccountsignup + Create + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Local Account Signin + + + SignUpWithLogonEmailExchange + Email + api.selfasserted + + false + + + + + + + + + + + + + + + + + + Reset password using email address + + + IpAddress + api.localaccountpasswordreset + Your account has been locked. Contact your support person to unlock it, then try again. + + + + + false + + + + + + + + + + + + + + Change password (username) + + + api.localaccountpasswordreset + + + + + + + + + + + + + + + + + + + + + + Session Management + + + Noop Session Management Provider + + + + + Session Mananagement Provider + + + + + + + + + + + + + + + + + + + Trustframework Policy Engine TechnicalProfiles + + + Trustframework Policy Engine Default Technical Profile + + + {service:te} + + + + + + + Token Issuer + + + JWT Issuer + + JWT + + {service:te} + objectId + true + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + objectId + SkipThisOrchestrationStep + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/policies/embedded-sign-in/policy/TrustFrameworkExtensionsEmbedded.xml b/policies/embedded-sign-in/policy/TrustFrameworkExtensionsEmbedded.xml new file mode 100644 index 00000000..395c2d3a --- /dev/null +++ b/policies/embedded-sign-in/policy/TrustFrameworkExtensionsEmbedded.xml @@ -0,0 +1,44 @@ + + + + + yourtenant.onmicrosoft.com + B2C_1A_TrustFrameworkBase_Embedded + + + + + + + + + + + Local Account SignIn + + + + ProxyIdentityExperienceFrameworkAppId + IdentityExperienceFrameworkAppId + + + + + + + + + + + + + + diff --git a/policies/embedded-sign-in/readme.md b/policies/embedded-sign-in/readme.md new file mode 100644 index 00000000..db73c284 --- /dev/null +++ b/policies/embedded-sign-in/readme.md @@ -0,0 +1,47 @@ +# Embedded Sign-up and Sign-in with iframe + +By default when you create a sign-up or sign-in policy, it cannot be embedded in an iframe within your application. To allow your Azure AD B2C user interface to be embedded in an iframe, a content security policy `Content-Security-Policy` and frame options `X-Frame-Options` must be included in the Azure AD B2C HTTP response headers. These headers allow the Azure AD B2C user interface to run under your application domain name. + +This policy adds a JourneyFraming element inside the RelyingParty element. The UserJourneyBehaviors element must follow the DefaultUserJourney. Your UserJourneyBehaviors element should look like this example: + +```xml + + + + + +``` + +## Steps to Use the Policy + +>Note: Because Azure AD B2C session cookies within an iframe are considered third-party cookies, certain browsers (for example Safari or Chrome in incognito mode) either block or clear these cookies, resulting in an undesirable user experience. To prevent this issue, make sure your application domain name and your Azure AD B2C domain have the same origin. To use the same origin, [enable custom domains](https://docs.microsoft.com/en-us/azure/active-directory-b2c/custom-domain) for Azure AD B2C tenant, then configure your web app with the same origin. For example, an application hosted on 'https://app.contoso.com' has the same origin as Azure AD B2C running on 'https://login.contoso.com'. + +### Customizations in TrustFrameworkBaseEmbedded.xml + +- Modify the `TenantId="yourtenant.onmicrosoft.com"` element in the `` tag. +- Modify the `PublicPolicyUri="http://yourtenant.onmicrosoft.com/B2C_1A_TrustFrameworkBase_Embedded"` element in the `` tag. If you're using a custom domain, this should be similar to 'http://login.yourcustomdomain.com/policyname' rather than 'http://yourtenant.onmicrosoft.com/policyname'. + +### Customizations in TrustFrameworkExtensionsEmbedded.xml + +- Modify the `TenantId="yourtenant.onmicrosoft.com"` element in the `` tag. +- Modify the `PublicPolicyUri="http://yourtenant.onmicrosoft.com/B2C_1A_TrustFrameworkExtensions_Embedded"` element in the `` tag. If you're using a custom domain, this should be similar to 'http://login.yourcustomdomain.com/policyname' rather than 'http://yourtenant.onmicrosoft.com/policyname'. +- Modify the `yourtenant.onmicrosoft.com` tag in the ``. +- Changes all text instances of the `ProxyIdentityExperienceFrameworkAppId` and `IdentityExperienceFrameworkAppId` with the Application Client Ids of the **ProxyIdentityExperienceFramework** and the **IdentityExperienceFramework** respectively. + +### Customizations in SignUpOrSignInEmbedded.xml + +- Modify the `TenantId="yourtenant.onmicrosoft.com"` element in the `` tag. +- Modify the `PublicPolicyUri="http://yourtenant.onmicrosoft.com/B2C_1A_TrustFrameworkExtensions_Embedded"` element in the `` tag. If you're using a custom domain, this should be similar to 'http://login.yourcustomdomain.com/policyname' rather than 'http://yourtenant.onmicrosoft.com/policyname'. +- Modify the `yourtenant.onmicrosoft.com` tag in the ``. +- Modify the `Sources="https://somesite.com https://anothersite.com"` element in the `` tag. This should contain a list of origins which are allowed to load this policy in an iframe. + +## Community Help and Support + +Use [Stack Overflow](https://stackoverflow.com/questions/tagged/azure-ad-b2c) to get support from the community. Ask your questions on Stack Overflow first and browse existing issues to see if someone has asked your question before. Make sure that your questions or comments are tagged with [azure-ad-b2c]. +If you find a bug in the sample, please raise the issue on [GitHub Issues](https://github.com/azure-ad-b2c/samples/issues). +To provide product feedback, visit the Azure Active Directory B2C [Feedback page](https://feedback.azure.com/forums/169401-azure-active-directory?category_id=160596). + +> Note: This sample policy is based on [LocalAccounts starter pack](https://github.com/Azure-Samples/active-directory-b2c-custom-policy-starterpack/tree/master/LocalAccounts). diff --git a/readme.md b/readme.md index d0db0c94..86ef9829 100644 --- a/readme.md +++ b/readme.md @@ -11,6 +11,7 @@ In this repo, you will find samples for several enhanced Azure AD B2C Custom CIA - See our Custom Policy Schema reference [here](https://docs.microsoft.com/en-us/azure/active-directory-b2c/active-directory-b2c-reference-trustframeworks-defined-ief-custom). ## Prerequisites + - You can automate the pre requisites by visiting this [site](https://aka.ms/iefsetup). Some policies can be deployed directly through this app via the **Experimental** menu. - You will require to create an Azure AD B2C directory, see the guidance [here](https://docs.microsoft.com/en-us/azure/active-directory-b2c/tutorial-create-tenant). @@ -31,7 +32,6 @@ In this repo, you will find samples for several enhanced Azure AD B2C Custom CIA - [Sign Up and Sign In with dynamic 'Terms of Use' prompt](policies/sign-in-sign-up-versioned-tou) - Demonstrates how to incorporate a TOU or T&Cs into your user journey with the ability for users to be prompted to re-consent when the TOU/T&Cs change. - - [Local account change sign-in name email address](policies/change-sign-in-name) - During sign-in with a local account, a user may want to change the sign-in name (email address). This sample policy demonstrates how to allow a user to provide and validate a new email address, and store the new email address to the Azure Active Directory user account. After the user changes their email address, subsequent logins require the use of the new email address. - [Password-less sign-in with email verification](policies/passwordless-email) - Password-less authentication is a type of authentication where user doesn't need to sign-in with their password. This is commonly used in B2C scenarios where users use your application infrequently and tend to forget their password. This sample policy demonstrates how to allow user to sign-in, simply by providing and verifying the sign-in email address using OTP code (one time password). @@ -46,6 +46,8 @@ In this repo, you will find samples for several enhanced Azure AD B2C Custom CIA - [Sign-up and sign-in with embedded password reset](policies/embedded-password-reset) - This policy demonstrates how to embed the password reset flow a part of the sign-up or sign-in policy without the AADB2C90118 error message. +- [Embedded Sign-up and sign-in with iframe](policies/embedded-sign-in) - This policy demonstrates how to allow your Azure AD B2C user interface to be embedded in an iframe. + - [Force password after 90 days](policies/force-password-reset-after-90-days) - Demonstrates how to force a user to reset their password after 90 days from the last time user set their password. - [Password reset only](policies/password-reset-only) - This example policy prevents issuing an access token to the user after resetting their password. @@ -136,7 +138,6 @@ In this repo, you will find samples for several enhanced Azure AD B2C Custom CIA - [Render dynamic dropdown box](policies/selectemail) - For scenarios where you would like to fetch information during the runtime of the authentication flow, and display this data as a dropdown box dynamically for the user to make a selection. In this example, a users identifier is sent to an API, which returns a set of emails for them to select. The selected email is returned in the token. - ## Generic enhancements - [Delete my account](policies/delete-my-account) - Demonstrates how to delete a local or social account from the directory @@ -159,7 +160,7 @@ In this repo, you will find samples for several enhanced Azure AD B2C Custom CIA - [Obtain the Microsoft Graph access token for an Azure AD Federated logon](policies/B2C-Token-Includes-AzureAD-BearerToken) - For scenarios where we would like to obtain the Microsoft Graph API token for a Azure AD federated logon in the context of the logged in user. For example this could be used to read the users Exchange Online mailbox within an Azure AD B2C application. -- [AAD Authentication with REST](policies/AAD-SignIn-with-REST) - Pass through authentication to Azure AD (no user created in B2C), then calls a REST API to obtain more claims. +- [AAD Authentication with REST](policies/AAD-SignIn-with-REST) - Pass through authentication to Azure AD (no user created in B2C), then calls a REST API to obtain more claims. ## App migration