My API needs three types of users and I want to manage it with custom role definitions. Is it possible to create roles on Azure B2c then assign these roles to the users by Microsoft Graph API?
My API needs three types of users and I want to manage it with custom role definitions. Is it possible to create roles on Azure B2c then assign these roles to the users by Microsoft Graph API?
You could create an extension attribute called extension_role, and use Graph API to write the role name to this attribute.
Example on how to create and write to the extension attribute here.
Then in AAD B2C custom policy, read the extension attribute and insert it into the token.
Eg, read the attribute on sign in/up:
<TechnicalProfile Id="AAD-UserReadUsingObjectId">
<Metadata>
<Item Key="Operation">Read</Item>
<Item Key="RaiseErrorIfClaimsPrincipalDoesNotExist">true</Item>
</Metadata>
<IncludeInSso>false</IncludeInSso>
<InputClaims>
<InputClaim ClaimTypeReferenceId="objectId" Required="true" />
</InputClaims>
<OutputClaims>
<OutputClaim ClaimTypeReferenceId="extension_role" />
</OutputClaims>
<IncludeTechnicalProfile ReferenceId="AAD-Common" />
</TechnicalProfile>
Insert into token:
<RelyingParty>
<DefaultUserJourney ReferenceId="SignUpOrSignIn" />
<TechnicalProfile Id="PolicyProfile">
<DisplayName>PolicyProfile</DisplayName>
<Protocol Name="OpenIdConnect" />
<OutputClaims>
<OutputClaim ClaimTypeReferenceId="extension_role" />
<OutputClaim ClaimTypeReferenceId="displayName" />
<OutputClaim ClaimTypeReferenceId="givenName" />
<OutputClaim ClaimTypeReferenceId="surname" />
<OutputClaim ClaimTypeReferenceId="email" />
<OutputClaim ClaimTypeReferenceId="objectId" PartnerClaimType="sub"/>
<OutputClaim ClaimTypeReferenceId="tenantId" AlwaysUseDefaultValue="true" DefaultValue="{Policy:TenantObjectId}" />
</OutputClaims>
<SubjectNamingInfo ClaimType="sub" />
</TechnicalProfile>
</RelyingParty>
Am working toward the same goal , so here is what I found until this moment:
Didn' find anything related to managing users access with roles , so if you found any , do not hesitate to share . Thanks