Unable to pass query param to azure-ad-b2c custom policy and store values

mekbeb worku 26 Reputation points

I have a scenario where i have to pass a query parameter in the URL to my custom sign-up policy and so far all my attempts did not work. there seem to be something that i am missing following the guidelines i found in github. I am trying to pass LoyaltyNumber and i have this attribute defined in my policy as extension_LoyaltyNumber. Below is the snippet.

my custom signup policy

<DefaultUserJourney ReferenceId="SignUp" />
<Parameter Name="LoyaltyNumber">{OAUTH-KV:LoyaltyNumber}</Parameter>
<TechnicalProfile Id="PolicyProfile">
<Protocol Name="OpenIdConnect" />
<InputClaim ClaimTypeReferenceId="email" />
<InputClaim ClaimTypeReferenceId="extension_LoyaltyNumber" />
<OutputClaim ClaimTypeReferenceId="displayName" />
<OutputClaim ClaimTypeReferenceId="givenName" />
<OutputClaim ClaimTypeReferenceId="surname" />
<OutputClaim ClaimTypeReferenceId="signInNames.emailAddress" PartnerClaimType="email" />
<OutputClaim ClaimTypeReferenceId="objectId" PartnerClaimType="sub"/>
<OutputClaim ClaimTypeReferenceId="tenantId" AlwaysUseDefaultValue="true" DefaultValue="{Policy:TenantObjectId}" />
<OutputClaim ClaimTypeReferenceId="extension_ValidPassword" />
<OutputClaim ClaimTypeReferenceId="extension_LoyaltyNumber" AlwaysUseDefaultValue="true"/>
<SubjectNamingInfo ClaimType="sub" />

in my TrustFrameworkExtension.xml, i have defined it in the Local Account as follows

<DisplayName>Local Account</DisplayName>
<!--Local account sign-up page-->
<TechnicalProfile Id="LocalAccountSignUpWithLogonEmail">
<Item Key="IncludeClaimResolvingInClaimsHandling">true</Item>
<InputClaim ClaimTypeReferenceId="extension_LoyaltyNumber" AlwaysUseDefaultValue="true" DefaultValue="{OAUTH-K:LoyaltyNumber}" />
<OutputClaim ClaimTypeReferenceId="email" PartnerClaimType="Verified.Email" Required="true" />
<OutputClaim ClaimTypeReferenceId="newPassword" Required="true" />
<OutputClaim ClaimTypeReferenceId="reenterPassword" Required="true" />
<OutputClaim ClaimTypeReferenceId="displayName" />
<OutputClaim ClaimTypeReferenceId="givenName" />
<OutputClaim ClaimTypeReferenceId="surName" />

   <TechnicalProfile Id="SelfAsserted-LocalAccountSignin-Email">
        <Item Key="setting.showSignupLink">false</Item>


i also have it in the building bolocks section as...

<ClaimType Id="extension_LoyaltyNumber">
<UserHelpText>Your loyality from your membership card</UserHelpText>

i have it also to write to Azure Active Directory claims provider section as follows

<DisplayName>Azure Active Directory</DisplayName>
<TechnicalProfile Id="AAD-Common">
<!--Insert b2c-extensions-app application ID here, for example: 11111111-1111-1111-1111-111111111111-->
<Item Key="ClientId">11111111-1111-1111-1111-111111111111</Item>
<!--Insert b2c-extensions-app application ObjectId here, for example: 22222222-2222-2222-2222-222222222222-->
<Item Key="ApplicationObjectId">22222222-2222-2222-2222-222222222222</Item>

    <TechnicalProfile Id="AAD-UserWriteUsingLogonEmail">
        <PersistedClaim ClaimTypeReferenceId="extension_LoyaltyNumber" />

    <TechnicalProfile Id="AAD-UserReadUsingObjectId">
        <OutputClaim ClaimTypeReferenceId="extension_LoyaltyNumber" />


And the redirect happens from my web application using the following method

public void SignUpNewUser()
if (!Request.IsAuthenticated)
var authenticationProperties = new AuthenticationProperties();
authenticationProperties.Dictionary.Add("LoyaltyNumber", "556677");
authenticationProperties.RedirectUri = "/";
HttpContext.GetOwinContext().Authentication.Challenge(authenticationProperties, Startup.SignUpPolicyId);


The result i am getting after the user sign-up for the custom attribute extension_LoyaltyNumber is {OAUTH-K:LoyaltyNumber}

Somehow the value 556677 i pass as a query param is not getting to this custom attribute and get stored in Azure user attribute

Can you help?


Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
934 questions
Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,955 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.