You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory-b2c/phone-factor-technical-profile.md
+28-28Lines changed: 28 additions & 28 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ manager: celestedg
9
9
ms.service: active-directory
10
10
ms.workload: identity
11
11
ms.topic: reference
12
-
ms.date: 03/26/2020
12
+
ms.date: 03/31/2020
13
13
ms.author: mimart
14
14
ms.subservice: B2C
15
15
---
@@ -20,12 +20,11 @@ ms.subservice: B2C
20
20
21
21
Azure Active Directory B2C (Azure AD B2C) provides support for enrolling and verifying phone numbers. This technical profile:
22
22
23
-
- Provides a user interface to interact with the user.
24
-
- Uses content definition to control the look and feel.
25
-
- Supports both phone calls and text messages to validate the phone number.
23
+
- Provides a user interface to interact with the user to verify, or enroll a phone number.
24
+
- Supports phone calls and text messages to validate the phone number.
26
25
- Supports multiple phone numbers. The user can select one of the phone numbers to verify.
27
-
-If a phone number is provided, the phone factor user interface asks the user to verify the phone number. If not provided, it asks the user to enroll a new phone number.
28
-
-Returns a claim indicating whether the user provided a new phone number. You can use this claim to decide whether the phone number should be persisted to the Azure AD user profile.
26
+
-Returns a claim indicating whether the user provided a new phone number. You can use this claim to decide whether the phone number should be persisted to the Azure AD B2C user profile.
27
+
-Uses a [content definition](contentdefinitions.md)to control the look and feel.
29
28
30
29
## Protocol
31
30
@@ -41,19 +40,25 @@ The following example shows a phone factor technical profile for enrollment and
41
40
</TechnicalProfile>
42
41
```
43
42
44
-
## Input claims
43
+
## Input claims transformations
45
44
46
-
The InputClaims element must contain following claims. You can also map the name of your claim to the name defined in the phone factor technical profile.
45
+
The InputClaimsTransformations element may contain a collection of input claims transformations that are used to modify the input claims, or generate new ones. The following input claims transformation generates a `UserId`claim that is used later in the input claims collection.
47
46
48
-
```XML
49
-
<InputClaims>
50
-
<!--A unique identifier of the user. The partner claim type must be set to `UserId`. -->
<!--A claim that contains the phone number. If the claim is empty, Azure AD B2C asks the user to enroll a new phone number. Otherwise, it asks the user to verify the phone number. -->
The InputClaims element must contain the following claims. You can also map the name of your claim to the name defined in the phone factor technical profile.
56
+
57
+
| Data type| Required | Description |
58
+
| --------- | -------- | ----------- |
59
+
| string| Yes | A unique identifier for the user. The claim name, or PartnerClaimType must be set to `UserId`. This claim should not contain personal identifiable information.|
60
+
| string| Yes | List of claim types. Each claim contains one phone number. If any of the input claims do not contain a phone number, the user will be asked to enroll and verify a new phone number. The validated phone number is returned as an output claim. If one of the input claims contain a phone number, the user is asked to verify it. If multiple input claims contain a phone number, the user is asked to choose and verify one of the phone numbers. |
61
+
57
62
The following example demonstrates using multiple phone numbers. For more information, see [sample policy](https://github.com/azure-ad-b2c/samples/tree/master/policies/mfa-add-secondarymfa).
58
63
59
64
```XML
@@ -64,22 +69,16 @@ The following example demonstrates using multiple phone numbers. For more inform
64
69
</InputClaims>
65
70
```
66
71
67
-
The InputClaimsTransformations element may contain a collection of InputClaimsTransformation elements that are used to modify the input claims or generate new ones before presenting them to the phone factor page.
68
-
69
72
## Output claims
70
73
71
74
The OutputClaims element contains a list of claims returned by the phone factor technical profile.
72
75
73
-
```xml
74
-
<OutputClaims>
75
-
<!-- The verified phone number. The partner claim type must be set to `Verified.OfficePhone`. -->
| boolean | Yes | Indicates whether the new phone number has been entered by the user. The claim name, or PartnerClaimType must be set to `newPhoneNumberEntered`|
79
+
| string| Yes | The verified phone number. The claim name, or PartnerClaimType must be set to `Verified.OfficePhone`.|
81
80
82
-
The OutputClaimsTransformations element may contain a collection of OutputClaimsTransformation elements that are used to modify the output claims or generate new ones.
81
+
The OutputClaimsTransformations element may contain a collection of OutputClaimsTransformation elements that are used to modify the output claims, or generate new ones.
83
82
84
83
## Cryptographic keys
85
84
@@ -91,7 +90,9 @@ The **CryptographicKeys** element is not used.
91
90
| Attribute | Required | Description |
92
91
| --------- | -------- | ----------- |
93
92
| ContentDefinitionReferenceId | Yes | The identifier of the [content definition](contentdefinitions.md) associated with this technical profile. |
94
-
| ManualPhoneNumberEntryAllowed| No | Specify whether or not a user is allowed to manually enter a phone number. Possible values: `true` or `false` (default).|
93
+
| ManualPhoneNumberEntryAllowed| No | Specify whether or not a user is allowed to manually enter a phone number. Possible values: `true`, or `false` (default).|
94
+
| setting.authenticationMode | No | The method to validate the phone number. Possible values: `sms`, `phone`, or `mixed` (default).|
95
+
| setting.autodial| No| Specify whether the technical profile should auto dial or auto send an SMS. Possible values: `true`, or `false` (default). Auto dial requires the `setting.authenticationMode` metadata be set to `sms`, or `phone`. The input claims collection must have a single phone number. |
95
96
96
97
### UI elements
97
98
@@ -100,4 +101,3 @@ The phone factor authentication page user interface elements can be [localized](
100
101
## Next steps
101
102
102
103
- Check the [social and local accounts with MFA](https://github.com/Azure-Samples/active-directory-b2c-custom-policy-starterpack/tree/master/SocialAndLocalAccountsWithMfa) starter pack.
0 commit comments