Collect and manipulate user inputs by using Azure Active Directory B2C custom policy

Azure Active Directory B2C (Azure AD B2C) custom policies allows you to collect user inputs. You can then use inbuilt methods to manipulate the user inputs.

In this article, you learn how to write a custom policy that collects user inputs via a graphical user interface. You'll then access the inputs, process then, and finally return them as claims in a JWT token. To complete this task, you'll:

  • Declare claims. A claim provides temporary storage of data during an Azure AD B2C policy execution. It can store information about the user, such as first name, last name, or any other claim obtained from the user or other systems. You can learn more about claims in the Azure AD B2C custom policy overview.

  • Define technical profiles. A technical profile provides an interface to communicate with different types of parties. For example, it allows you to interact with the user to collect data.

  • Configure claims transformations, which you use to manipulate the claims you declare.

  • Configure content definitions. A content definition defines the user interface to load. Later you can customize the user interface by providing your own customized HTML content.

  • Configure and show user interfaces to the user by using Self-Asserted Technical Profiles and DisplayClaims.

  • Call Technical Profiles in a given sequence by using Orchestration Steps.



This article is part of the Create and run your own custom policies in Azure Active Directory B2C how-to guide series. We recommend that you start this series from the first article.

Step 1 - Declare claims

Declare additional claims alongside objectId and message:

  1. In VS Code, open the ContosoCustomPolicy.XML file.

  2. In the ClaimsSchema section, add the following ClaimType declarations:

        <ClaimType Id="givenName">
            <DisplayName>Given Name</DisplayName>
            <UserHelpText>Your given name (also known as first name).</UserHelpText>
        <ClaimType Id="surname">
            <UserHelpText>Your surname (also known as family name or last name).</UserHelpText>
        <ClaimType Id="displayName">
            <DisplayName>Display Name</DisplayName>
            <UserHelpText>Your display name.</UserHelpText>

We've declared three Claim Types, givenName, surname, and displayName. These declarations include DataType, UserInputType and DisplayName elements:

  • DataType specifies the data type of the value that the claims hold. Learn more about the data types that the DataType elements supports.
  • UserInputType specifies the UI control that appears on the user interface if you want to collect the value of the claim from the user. Learn more about the user input types that Azure AD B2C supports.
  • DisplayName specifies the label for the UI control that appears on the user interface if you want to collect the value of the claim from the user.

Step 2 - Define claims transformations

A ClaimsTransformation contains a function that you use to convert a given claim into another one. For instance, you can change a string claim from lower case to upper case. Learn more about Claims transformations supported by Azure AD B2C.

  1. In the ContosoCustomPolicy.XML file, add a <ClaimsTransformations> element as a child of the BuildingBlocks section.

  2. Add the following code inside the ClaimsTransformations element:

        <ClaimsTransformation Id="GenerateRandomObjectIdTransformation" TransformationMethod="CreateRandomString">
            <InputParameter Id="randomGeneratorType" DataType="string" Value="GUID"/>
            <OutputClaim ClaimTypeReferenceId="objectId" TransformationClaimType="outputClaim"/>
        <ClaimsTransformation Id="CreateDisplayNameTransformation" TransformationMethod="FormatStringMultipleClaims">
            <InputClaim ClaimTypeReferenceId="givenName" TransformationClaimType="inputClaim1"/>
            <InputClaim ClaimTypeReferenceId="surname" TransformationClaimType="inputClaim2"/>
            <InputParameter Id="stringFormat" DataType="string" Value="{0} {1}"/>
            <OutputClaim ClaimTypeReferenceId="displayName" TransformationClaimType="outputClaim"/>
        <ClaimsTransformation Id="CreateMessageTransformation" TransformationMethod="FormatStringClaim">
            <InputClaim ClaimTypeReferenceId="displayName" TransformationClaimType="inputClaim"/>
            <InputParameter Id="stringFormat" DataType="string" Value="Hello {0}"/>
            <OutputClaim ClaimTypeReferenceId="message" TransformationClaimType="outputClaim"/>

    We've configured three claims transformations:

    • GenerateRandomObjectIdTransformation generates a random string as specified by the CreateRandomString method. The objectId claim is updated with the generated string as specified by the OutputClaim element.

    • CreateDisplayNameTransformation concatenates givenName and surname to form displayName.

    • CreateMessageTransformation concatenates Hello and displayName to form message.

Step 3 - Configure content definitions

ContentDefinitions allow you to specify URL to HTML templates that control the layout of the web pages you show to your users. You can specify specific user interfaces for each step, such as sign-in or sign-up, password reset, or error pages.

To add content definition, add the following code in BuildingBlocks section of the ContosoCustomPolicy.XML file:

        <ContentDefinition Id="SelfAssertedContentDefinition">

Step 4 - Configure technical profiles

In a custom policy, a TechnicalProfile is the element that implements functionality. Now that you've defined Claims and Claims Transformations, you need Technical Profiles to execute your definitions. A technical profile is declared inside the ClaimsProvider elements.

Azure AD B2C provides a set of technical profiles. Each technical profile performs a specific role. For instance, you use a REST technical profile to make an HTTP call to a service endpoint. You can use a claims transformation technical profile to execute the operation you define in a Claims Transformation. Learn more about the types of technical profiles that Azure AD B2C custom policies provide.

Set values for your claims

To set values for objectId, displayName and message claims, you configure a technical profile that executes the GenerateRandomObjectIdTransformation, CreateDisplayNameTransformation, and CreateMessageTransformation claims transformations. The claims transformations are executed by the order defined in the OutputClaimsTransformations element. For example, it first creates the display name, then the message.

  1. Add the following ClaimsProvider as a child of the ClaimsProviders section.

            <DisplayName>Technical Profiles to generate claims</DisplayName>
  2. To set values for objectId, displayName and message claims, add the following code inside the ClaimsProvider element you just created:

                <TechnicalProfile Id="ClaimGenerator">
                    <DisplayName>Generate Object ID, displayName and message Claims Technical Profile.</DisplayName>
                    <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.ClaimsTransformationProtocolProvider, Web.TPEngine, Version=, Culture=neutral, PublicKeyToken=null"/>
                        <OutputClaim ClaimTypeReferenceId="objectId"/>
                        <OutputClaim ClaimTypeReferenceId="displayName"/>
                        <OutputClaim ClaimTypeReferenceId="message"/>
                        <OutputClaimsTransformation ReferenceId="GenerateRandomObjectIdTransformation"/>
                        <OutputClaimsTransformation ReferenceId="CreateDisplayNameTransformation"/>
                        <OutputClaimsTransformation ReferenceId="CreateMessageTransformation"/>

Collect user inputs

You generate the displayName claim from givenName and surname, so you need to collect then as user inputs. To collect a user input, you use a type of technical profile called Self-Asserted. When you configure a self-asserted technical profile, you need to reference the content definitions as self-asserted technical profile is responsible for displaying a user interface.

  1. Add the following ClaimsProvider as a child of the ClaimsProviders section.

            <DisplayName>Technical Profiles to collect user's details </DisplayName>
  2. Add the following code inside the ClaimsProvider element you just created:

            <TechnicalProfile Id="UserInformationCollector">
                <DisplayName>Collect User Input Technical Profile</DisplayName>
                <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=, Culture=neutral, PublicKeyToken=null"/>
                    <Item Key="ContentDefinitionReferenceId">SelfAssertedContentDefinition</Item>
                    <DisplayClaim ClaimTypeReferenceId="givenName" Required="true"/>
                    <DisplayClaim ClaimTypeReferenceId="surname" Required="true"/>
                    <OutputClaim ClaimTypeReferenceId="givenName"/>
                    <OutputClaim ClaimTypeReferenceId="surname"/>

    Notice the two display claims for the givenName and surname claims. Both of the claims are marked as required, so the user must enter the values before they submit the form displayed to them. The claims are displayed on the screen in the order defined in the DisplayClaims element such as, the Given Name and then the Surname.

Step 5 - Define user journeys

You use user journeys to define order in which the technical profiles are called. You use the OrchestrationSteps element to specify the steps in a user journey.

Replace the existing contents of the HelloWorldJourney User Journey with the following code:

        <OrchestrationStep Order="1" Type="ClaimsExchange">
                <ClaimsExchange Id="GetUserInformationClaimsExchange" TechnicalProfileReferenceId="UserInformationCollector"/>
        <OrchestrationStep Order="2" Type="ClaimsExchange">
                <ClaimsExchange Id="GetMessageClaimsExchange" TechnicalProfileReferenceId="ClaimGenerator"/>
        <OrchestrationStep Order="3" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer"/>

According to the orchestration steps, we collect user inputs, set values for objectId, displayName and message claims, and finally send the Jwt token.

Step 6 - Update relying party

Replace the contents of the OutputClaims element of the RelyingParty section with the following code:

    <OutputClaim ClaimTypeReferenceId="objectId" PartnerClaimType="sub"/>
    <OutputClaim ClaimTypeReferenceId="displayName"/>
    <OutputClaim ClaimTypeReferenceId="message"/>

After you complete step 6, the ContosoCustomPolicy.XML file should look similar to the following code:

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<TrustFrameworkPolicy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
    PolicySchemaVersion="" TenantId="yourtenant.onmicrosoft.com" 
            <ClaimType Id="objectId">
                <DisplayName>unique object Id for subject of the claims being returned</DisplayName>
            <ClaimType Id="message">
                <DisplayName>Will hold Hello World message</DisplayName>

            <ClaimType Id="givenName">
                <DisplayName>Given Name</DisplayName>
                <UserHelpText>Your given name (also known as first name).</UserHelpText>
            <ClaimType Id="surname">
                <UserHelpText>Your surname (also known as family name or last name).</UserHelpText>
            <ClaimType Id="displayName">
                <DisplayName>Display Name</DisplayName>
                <UserHelpText>Your display name.</UserHelpText>
            <ClaimsTransformation Id="GenerateRandomObjectIdTransformation" TransformationMethod="CreateRandomString">
                    <InputParameter Id="randomGeneratorType" DataType="string" Value="GUID"/>
                    <OutputClaim ClaimTypeReferenceId="objectId" TransformationClaimType="outputClaim"/>

            <ClaimsTransformation Id="CreateDisplayNameTransformation" TransformationMethod="FormatStringMultipleClaims">
                    <InputClaim ClaimTypeReferenceId="givenName" TransformationClaimType="inputClaim1"/>
                    <InputClaim ClaimTypeReferenceId="surname" TransformationClaimType="inputClaim2"/>
                    <InputParameter Id="stringFormat" DataType="string" Value="{0} {1}"/>
                    <OutputClaim ClaimTypeReferenceId="displayName" TransformationClaimType="outputClaim"/>

            <ClaimsTransformation Id="CreateMessageTransformation" TransformationMethod="FormatStringClaim">
                    <InputClaim ClaimTypeReferenceId="displayName" TransformationClaimType="inputClaim"/>
                    <InputParameter Id="stringFormat" DataType="string" Value="Hello {0}"/>
                    <OutputClaim ClaimTypeReferenceId="message" TransformationClaimType="outputClaim"/>
            <ContentDefinition Id="SelfAssertedContentDefinition">
    <!--Claims Providers Here-->
            <DisplayName>Token Issuer</DisplayName>
                <TechnicalProfile Id="JwtIssuer">
                    <DisplayName>JWT Issuer</DisplayName>
                    <Protocol Name="None"/>
                        <Item Key="client_id">{service:te}</Item>
                        <Item Key="issuer_refresh_token_user_identity_claim_type">objectId</Item>
                        <Item Key="SendTokenResponseBodyWithJsonNumbers">true</Item>
                        <Key Id="issuer_secret" StorageReferenceId="B2C_1A_TokenSigningKeyContainer"/>
                        <Key Id="issuer_refresh_token_key" StorageReferenceId="B2C_1A_TokenEncryptionKeyContainer"/>

            <DisplayName>Trustframework Policy Engine TechnicalProfiles</DisplayName>
                <TechnicalProfile Id="TpEngine_c3bd4fe2-1775-4013-b91d-35f16d377d13">
                    <DisplayName>Trustframework Policy Engine Default Technical Profile</DisplayName>
                    <Protocol Name="None"/>
                        <Item Key="url">{service:te}</Item>

            <DisplayName>Claim Generator Technical Profiles</DisplayName>
                <TechnicalProfile Id="ClaimGenerator">
                    <DisplayName>Generate Object ID, displayName and  message Claims Technical Profile.</DisplayName>
                    <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.ClaimsTransformationProtocolProvider, Web.TPEngine, Version=, Culture=neutral, PublicKeyToken=null"/>
                        <OutputClaim ClaimTypeReferenceId="objectId"/>
                        <OutputClaim ClaimTypeReferenceId="displayName"/>
                        <OutputClaim ClaimTypeReferenceId="message"/>
                        <OutputClaimsTransformation ReferenceId="GenerateRandomObjectIdTransformation"/>
                        <OutputClaimsTransformation ReferenceId="CreateDisplayNameTransformation"/>
                        <OutputClaimsTransformation ReferenceId="CreateMessageTransformation"/>

            <DisplayName>Technical Profiles to collect user's details</DisplayName>
                <TechnicalProfile Id="UserInformationCollector">
                    <DisplayName>Collect User Input Technical Profile</DisplayName>
                    <Protocol Name="Proprietary" Handler="Web.TPEngine.Providers.SelfAssertedAttributeProvider, Web.TPEngine, Version=, Culture=neutral, PublicKeyToken=null"/>
                        <Item Key="ContentDefinitionReferenceId">SelfAssertedContentDefinition</Item>
                        <DisplayClaim ClaimTypeReferenceId="givenName" Required="true"/>
                        <DisplayClaim ClaimTypeReferenceId="surname" Required="true"/>
                        <OutputClaim ClaimTypeReferenceId="givenName"/>
                        <OutputClaim ClaimTypeReferenceId="surname"/>

        <UserJourney Id="HelloWorldJourney">
                <OrchestrationStep Order="1" Type="ClaimsExchange">
                        <ClaimsExchange Id="GetUserInformationClaimsExchange" TechnicalProfileReferenceId="UserInformationCollector"/>
                <OrchestrationStep Order="2" Type="ClaimsExchange">
                        <ClaimsExchange Id="GetMessageClaimsExchange" TechnicalProfileReferenceId="ClaimGenerator"/>
                <OrchestrationStep Order="3" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer"/>

            Relying Party Here that's your policy’s entry point
            Specify the User Journey to execute 
            Specify the claims to include in the token that is returned when the policy runs
        <DefaultUserJourney ReferenceId="HelloWorldJourney"/>
        <TechnicalProfile Id="HelloWorldPolicyProfile">
            <DisplayName>Hello World Policy Profile</DisplayName>
            <Protocol Name="OpenIdConnect"/>
                <OutputClaim ClaimTypeReferenceId="objectId" PartnerClaimType="sub"/>
                <OutputClaim ClaimTypeReferenceId="displayName"/>
                <OutputClaim ClaimTypeReferenceId="message"/>
            <SubjectNamingInfo ClaimType="sub"/>

If you haven't already done so, replace yourtenant with the subdomain part of your tenant name, such as contoso. Learn how to Get your tenant name.

Step 7 - Upload custom policy file

Follow the steps in Upload custom policy file. If you're uploading a file with same name as the one already in the portal, make sure you select Overwrite the custom policy if it already exists.

Step 8 - Test the custom policy

  1. Under Custom policies, select B2C_1A_CONTOSOCUSTOMPOLICY.

  2. For Select application on the overview page of the custom policy, select the web application such as webapp1 that you previously registered. Make sure that the Select reply URL value is set tohttps://jwt.ms.

  3. Select Run now button.

  4. Enter Given Name and Surname, and then select Continue.

    screenshot of accepting user inputs in custom policy.

After the policy finishes execution, you're redirected to https://jwt.ms, and you see a decoded JWT token. It looks similar to the following JWT token snippet:

      "typ": "JWT",
      "alg": "RS256",
      "kid": "pxLOMWFg...."
      "sub": "c7ae4515-f7a7....",
      "acr": "b2c_1a_contosocustompolicy",
      "name": "Maurice Paulet",
      "message": "Hello Maurice Paulet"

Next steps

