Microsoft Azure Webjobs Extensions Authentication Events Dotnet

作者 microsoft354361d83247MIT收录于 2026年10月8日更新于 2026年10月8日

Microsoft Entra Authentication Events SDK for .NET. Azure Functions triggers for custom authentication extensions. Use for token enrichment, custom claims, attribute collection, and OTP customization in Entra ID. Triggers: "Authentication Events", "WebJobsAuthenticationEventsTrigger", "OnTokenIssuanceStart", "OnAttributeCollectionStart", "custom claims", "token enrichment", "Entra custom extension", "authentication extension".

AI 生成的概览

指导 .NET 开发者构建处理 Microsoft Entra ID 自定义身份验证事件的 Azure Functions。

功能
该技能介绍 Microsoft.Azure.WebJobs.Extensions.AuthenticationEvents .NET 包,并演示如何编写由 Entra ID 身份验证事件触发的 Azure Functions。内容涵盖使用自定义声明进行令牌扩充、属性收集的开始与提交处理,以及自定义 OTP 发送,并为每种事件类型提供 C# 代码示例。此外还包含 Function App 配置文件、关键类型参考、Entra ID 注册步骤和错误处理建议。
适用场景
适用于在 .NET 中实现 Entra ID 自定义身份验证扩展的场景,例如向令牌添加自定义声明、在注册过程中自定义或校验属性收集,或通过自定义渠道发送一次性密码。适合需要这些事件具体触发器和响应模式的开发者。
运行要求
需要 .NET SDK 和 Microsoft.Azure.WebJobs.Extensions.AuthenticationEvents NuGet 包,以及一个 Azure Functions 项目。部署并接入该扩展需要 Azure 订阅、具有 CustomAuthenticationExtension.Receive.Payload 范围的 Entra ID 应用注册,以及访问外部数据或 OTP 提供程序所需的网络连接。该技能不包含脚本,仅为说明文档和代码示例。

Microsoft.Azure.WebJobs.Extensions.AuthenticationEvents (.NET)

Azure Functions extension for handling Microsoft Entra ID custom authentication events.

Installation

bash
dotnet add package Microsoft.Azure.WebJobs.Extensions.AuthenticationEvents

Current Version: v1.1.0 (stable)

Supported Events

EventPurpose
OnTokenIssuanceStartAdd custom claims to tokens during issuance
OnAttributeCollectionStartCustomize attribute collection UI before display
OnAttributeCollectionSubmitValidate/modify attributes after user submission
OnOtpSendCustom OTP delivery (SMS, email, etc.)

Core Workflows

1. Token Enrichment (Add Custom Claims)

Add custom claims to access or ID tokens during sign-in.

csharp
using Microsoft.Azure.WebJobs;using Microsoft.Azure.WebJobs.Extensions.AuthenticationEvents;using Microsoft.Azure.WebJobs.Extensions.AuthenticationEvents.TokenIssuanceStart;using Microsoft.Extensions.Logging;
public static class TokenEnrichmentFunction{    [FunctionName("OnTokenIssuanceStart")]    public static WebJobsAuthenticationEventResponse Run(        [WebJobsAuthenticationEventsTrigger] WebJobsTokenIssuanceStartRequest request,        ILogger log)    {        log.LogInformation("Token issuance event for user: {UserId}",             request.Data?.AuthenticationContext?.User?.Id);
        // Create response with custom claims        var response = new WebJobsTokenIssuanceStartResponse();                // Add claims to the token        response.Actions.Add(new WebJobsProvideClaimsForToken        {            Claims = new Dictionary<string, string>            {                { "customClaim1", "customValue1" },                { "department", "Engineering" },                { "costCenter", "CC-12345" },                { "apiVersion", "v2" }            }        });
        return response;    }}

2. Token Enrichment with External Data

Fetch claims from external systems (databases, APIs).

csharp
using Microsoft.Azure.WebJobs;using Microsoft.Azure.WebJobs.Extensions.AuthenticationEvents;using Microsoft.Azure.WebJobs.Extensions.AuthenticationEvents.TokenIssuanceStart;using Microsoft.Extensions.Logging;using System.Net.Http;using System.Text.Json;
public static class TokenEnrichmentWithExternalData{    private static readonly HttpClient _httpClient = new();
    [FunctionName("OnTokenIssuanceStartExternal")]    public static async Task<WebJobsAuthenticationEventResponse> Run(        [WebJobsAuthenticationEventsTrigger] WebJobsTokenIssuanceStartRequest request,        ILogger log)    {        string? userId = request.Data?.AuthenticationContext?.User?.Id;                if (string.IsNullOrEmpty(userId))        {            log.LogWarning("No user ID in request");            return new WebJobsTokenIssuanceStartResponse();        }
        // Fetch user data from external API        var userProfile = await GetUserProfileAsync(userId);                var response = new WebJobsTokenIssuanceStartResponse();        response.Actions.Add(new WebJobsProvideClaimsForToken        {            Claims = new Dictionary<string, string>            {                { "employeeId", userProfile.EmployeeId },                { "department", userProfile.Department },                { "roles", string.Join(",", userProfile.Roles) }            }        });
        return response;    }
    private static async Task<UserProfile> GetUserProfileAsync(string userId)    {        var response = await _httpClient.GetAsync($"https://api.example.com/users/{userId}");        response.EnsureSuccessStatusCode();        var json = await response.Content.ReadAsStringAsync();        return JsonSerializer.Deserialize<UserProfile>(json)!;    }}
public record UserProfile(string EmployeeId, string Department, string[] Roles);

3. Attribute Collection - Customize UI (Start Event)

Customize the attribute collection page before it's displayed.

csharp
using Microsoft.Azure.WebJobs;using Microsoft.Azure.WebJobs.Extensions.AuthenticationEvents;using Microsoft.Azure.WebJobs.Extensions.AuthenticationEvents.Framework;using Microsoft.Extensions.Logging;
public static class AttributeCollectionStartFunction{    [FunctionName("OnAttributeCollectionStart")]    public static WebJobsAuthenticationEventResponse Run(        [WebJobsAuthenticationEventsTrigger] WebJobsAttributeCollectionStartRequest request,        ILogger log)    {        log.LogInformation("Attribute collection start for correlation: {CorrelationId}",            request.Data?.AuthenticationContext?.CorrelationId);
        var response = new WebJobsAttributeCollectionStartResponse();
        // Option 1: Continue with default behavior        response.Actions.Add(new WebJobsContinueWithDefaultBehavior());
        // Option 2: Prefill attributes        // response.Actions.Add(new WebJobsSetPrefillValues        // {        //     Attributes = new Dictionary<string, string>        //     {        //         { "city", "Seattle" },        //         { "country", "USA" }        //     }        // });
        // Option 3: Show blocking page (prevent sign-up)        // response.Actions.Add(new WebJobsShowBlockPage        // {        //     Message = "Sign-up is currently disabled."        // });
        return response;    }}

4. Attribute Collection - Validate Submission (Submit Event)

Validate and modify attributes after user submission.

csharp
using Microsoft.Azure.WebJobs;using Microsoft.Azure.WebJobs.Extensions.AuthenticationEvents;using Microsoft.Azure.WebJobs.Extensions.AuthenticationEvents.Framework;using Microsoft.Extensions.Logging;
public static class AttributeCollectionSubmitFunction{    [FunctionName("OnAttributeCollectionSubmit")]    public static WebJobsAuthenticationEventResponse Run(        [WebJobsAuthenticationEventsTrigger] WebJobsAttributeCollectionSubmitRequest request,        ILogger log)    {        var response = new WebJobsAttributeCollectionSubmitResponse();
        // Access submitted attributes        var attributes = request.Data?.UserSignUpInfo?.Attributes;                string? email = attributes?["email"]?.ToString();        string? displayName = attributes?["displayName"]?.ToString();
        // Validation example: block certain email domains        if (email?.EndsWith("@blocked.com") == true)        {            response.Actions.Add(new WebJobsShowBlockPage            {                Message = "Sign-up from this email domain is not allowed."            });            return response;        }
        // Validation example: show validation error        if (string.IsNullOrEmpty(displayName) || displayName.Length < 3)        {            response.Actions.Add(new WebJobsShowValidationError            {                Message = "Display name must be at least 3 characters.",                AttributeErrors = new Dictionary<string, string>                {                    { "displayName", "Name is too short" }                }            });            return response;        }
        // Modify attributes before saving        response.Actions.Add(new WebJobsModifyAttributeValues        {            Attributes = new Dictionary<string, string>            {                { "displayName", displayName.Trim() },                { "city", attributes?["city"]?.ToString()?.ToUpperInvariant() ?? "" }            }        });
        return response;    }}

5. Custom OTP Delivery

Send one-time passwords via custom channels (SMS, email, push notification).

csharp
using Microsoft.Azure.WebJobs;using Microsoft.Azure.WebJobs.Extensions.AuthenticationEvents;using Microsoft.Azure.WebJobs.Extensions.AuthenticationEvents.Framework;using Microsoft.Extensions.Logging;
public static class CustomOtpFunction{    [FunctionName("OnOtpSend")]    public static async Task<WebJobsAuthenticationEventResponse> Run(        [WebJobsAuthenticationEventsTrigger] WebJobsOnOtpSendRequest request,        ILogger log)    {        var response = new WebJobsOnOtpSendResponse();
        string? phoneNumber = request.Data?.OtpContext?.Identifier;        string? otp = request.Data?.OtpContext?.OneTimeCode;
        if (string.IsNullOrEmpty(phoneNumber) || string.IsNullOrEmpty(otp))        {            log.LogError("Missing phone number or OTP");            response.Actions.Add(new WebJobsOnOtpSendFailed            {                Error = "Missing required data"            });            return response;        }
        try        {            // Send OTP via your SMS provider            await SendSmsAsync(phoneNumber, $"Your verification code is: {otp}");                        response.Actions.Add(new WebJobsOnOtpSendSuccess());            log.LogInformation("OTP sent successfully to {PhoneNumber}", phoneNumber);        }        catch (Exception ex)        {            log.LogError(ex, "Failed to send OTP");            response.Actions.Add(new WebJobsOnOtpSendFailed            {                Error = "Failed to send verification code"            });        }
        return response;    }
    private static async Task SendSmsAsync(string phoneNumber, string message)    {        // Implement your SMS provider integration (Twilio, Azure Communication Services, etc.)        await Task.CompletedTask;    }}

6. Function App Configuration

Configure the Function App for authentication events.

csharp
// Program.cs (Isolated worker model)using Microsoft.Extensions.Hosting;
var host = new HostBuilder()    .ConfigureFunctionsWorkerDefaults()    .Build();
host.Run();
json
// host.json{  "version": "2.0",  "logging": {    "applicationInsights": {      "samplingSettings": {        "isEnabled": true      }    }  },  "extensions": {    "http": {      "routePrefix": ""    }  }}
json
// local.settings.json{  "IsEncrypted": false,  "Values": {    "AzureWebJobsStorage": "UseDevelopmentStorage=true",    "FUNCTIONS_WORKER_RUNTIME": "dotnet"  }}

Key Types Reference

TypePurpose
WebJobsAuthenticationEventsTriggerAttributeFunction trigger attribute
WebJobsTokenIssuanceStartRequestToken issuance event request
WebJobsTokenIssuanceStartResponseToken issuance event response
WebJobsProvideClaimsForTokenAction to add claims
WebJobsAttributeCollectionStartRequestAttribute collection start request
WebJobsAttributeCollectionStartResponseAttribute collection start response
WebJobsAttributeCollectionSubmitRequestAttribute submission request
WebJobsAttributeCollectionSubmitResponseAttribute submission response
WebJobsSetPrefillValuesPrefill form values
WebJobsShowBlockPageBlock user with message
WebJobsShowValidationErrorShow validation errors
WebJobsModifyAttributeValuesModify submitted values
WebJobsOnOtpSendRequestOTP send event request
WebJobsOnOtpSendResponseOTP send event response
WebJobsOnOtpSendSuccessOTP sent successfully
WebJobsOnOtpSendFailedOTP send failed
WebJobsContinueWithDefaultBehaviorContinue with default flow

Entra ID Configuration

After deploying your Function App, configure the custom extension in Entra ID:

  1. Register the API in Entra ID → App registrations
  2. Create Custom Authentication Extension in Entra ID → External Identities → Custom authentication extensions
  3. Link to User Flow in Entra ID → External Identities → User flows

Required App Registration Settings

Expose an API:  - Application ID URI: api://<your-function-app-name>.azurewebsites.net  - Scope: CustomAuthenticationExtension.Receive.Payload
API Permissions:  - Microsoft Graph: User.Read (delegated)

Best Practices

  1. Validate all inputs — Never trust request data; validate before processing
  2. Handle errors gracefully — Return appropriate error responses
  3. Log correlation IDs — Use CorrelationId for troubleshooting
  4. Keep functions fast — Authentication events have timeout limits
  5. Use managed identity — Access Azure resources securely
  6. Cache external data — Avoid slow lookups on every request
  7. Test locally — Use Azure Functions Core Tools with sample payloads
  8. Monitor with App Insights — Track function execution and errors

Error Handling

csharp
[FunctionName("OnTokenIssuanceStart")]public static WebJobsAuthenticationEventResponse Run(    [WebJobsAuthenticationEventsTrigger] WebJobsTokenIssuanceStartRequest request,    ILogger log){    try    {        // Your logic here        var response = new WebJobsTokenIssuanceStartResponse();        response.Actions.Add(new WebJobsProvideClaimsForToken        {            Claims = new Dictionary<string, string> { { "claim", "value" } }        });        return response;    }    catch (Exception ex)    {        log.LogError(ex, "Error processing token issuance event");                // Return empty response - authentication continues without custom claims        // Do NOT throw - this would fail the authentication        return new WebJobsTokenIssuanceStartResponse();    }}

Related SDKs

SDKPurposeInstall
Microsoft.Azure.WebJobs.Extensions.AuthenticationEventsAuth events (this SDK)dotnet add package Microsoft.Azure.WebJobs.Extensions.AuthenticationEvents
Microsoft.Identity.WebWeb app authenticationdotnet add package Microsoft.Identity.Web
Azure.IdentityAzure authenticationdotnet add package Azure.Identity

Reference Links

来源与署名

来源:microsoft/skills位于.github/plugins/azure-sdk-dotnet/skills/microsoft-azure-webjobs-extensions-authentication-events-dotnet提交354361d

许可证: MIT

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架