Exception thrown when using /userinfo in Azure B2C custom policies

Gurpreet0101Singh-9444 70 Reputation points
2025-07-30T16:17:09.3966667+00:00

We have set up oAuth2 idp and for customendpoint we use /userinfo endpoint of the openid IDP.

We have tried various things but continue to get the exception - "AADB2C: An exception has occurred" and not much other information even in insights except the below:

We are using the following Technical Profile:


                <TechnicalProfile Id="iddataweb-OIDC-userinfo">
us/answers/questions/2247510/problem-adding-external-identity-provider-with-azu -->
                    <DisplayName>IDW Login</DisplayName>
                    <Protocol Name="OpenIdConnect" />
                    <Metadata>
                        <Item Key="issuer">https://iddatawebb2c.b2clogin.com/your-tenant-id/v2.0/</Item>
                        <Item Key="authorization_endpoint">https://preprod1.iddataweb.com/axn/oauth2/authorize</Item>
                        <Item Key="AccessTokenEndpoint">https://preprod1.iddataweb.com/axn/oauth2/token</Item>
                        <Item Key="ClaimsEndpoint">https://preprod1.iddataweb.com/axn/oauth2/userInfo</Item>

                        <Item Key="client_id">someid</Item>
                        <Item Key="response_types">code</Item>
                        <Item Key="response_mode">query</Item>
                        <Item Key="scope">openid profile</Item>
                        <Item Key="HttpBinding">POST</Item>
                        <Item Key="UsePkce">true</Item>
                        <Item Key="UsePolicyInRedirectUri">false</Item>
                    </Metadata>
                    <CryptographicKeys>
                        <Key Id="client_secret" StorageReferenceId="B2C_1A_secret" />
                    </CryptographicKeys>
                    <OutputClaims>
                        <OutputClaim ClaimTypeReferenceId="issuerUserId" PartnerClaimType="sub" />
                        <OutputClaim ClaimTypeReferenceId="displayName" PartnerClaimType="sub" />
                        <OutputClaim ClaimTypeReferenceId="givenName" PartnerClaimType="sub" />
                        <OutputClaim ClaimTypeReferenceId="surname" PartnerClaimType="sub" />
                        <OutputClaim ClaimTypeReferenceId="identityProvider" DefaultValue="cylogin" />
                        <OutputClaim ClaimTypeReferenceId="authenticationSource" DefaultValue="socialIdpAuthentication" />
                    </OutputClaims>
                    <OutputClaimsTransformations>
                        <OutputClaimsTransformation ReferenceId="CreateRandomUPNUserName" />
                        <OutputClaimsTransformation ReferenceId="CreateUserPrincipalName" />
                        <OutputClaimsTransformation ReferenceId="CreateAlternativeSecurityId" />
                        <OutputClaimsTransformation ReferenceId="CreateSubjectClaimFromAlternativeSecurityId" />
                    </OutputClaimsTransformations>
                    <UseTechnicalProfileForSessionManagement ReferenceId="SM-SocialLogin" />
                </TechnicalProfile>

and user journey as

        <UserJourney Id="SignUpOrSignInWithExternalOAuth2">
            <OrchestrationSteps>
                <!-- Step 1: Check for existing session -->
                <OrchestrationStep Order="1" Type="CombinedSignInAndSignUp" ContentDefinitionReferenceId="api.signuporsignin">
                    <ClaimsProviderSelections>
                        <ClaimsProviderSelection TargetClaimsExchangeId="ExternalOAuth2Exchange" />
                    </ClaimsProviderSelections>
                </OrchestrationStep>

                <!-- Step 2: Show error if IDP selection failed -->
                <!-- <OrchestrationStep Order="2" Type="ClaimsExchange">
                    <Preconditions>
                        <Precondition Type="ClaimsExist" ExecuteActionsIf="true">
                            <Value>objectId</Value>
                            <Action>SkipThisOrchestrationStep</Action>
                        </Precondition>
                    </Preconditions>
                    <ClaimsExchanges>
                        <ClaimsExchange Id="SelfAsserted-Unified" TechnicalProfileReferenceId="SelfAsserted-Unified" />
                    </ClaimsExchanges>
                </OrchestrationStep> -->

                <!-- Step 3: Redirect to external OAuth2 provider -->
                <OrchestrationStep Order="2" Type="ClaimsExchange">
                    <ClaimsExchanges>
                        <ClaimsExchange Id="ExternalOAuth2Exchange" TechnicalProfileReferenceId="iddataweb-OIDC-userinfo" />
                    </ClaimsExchanges>
                </OrchestrationStep>

                <!-- Step 4: Read user attributes from UserInfo endpoint -->
                <OrchestrationStep Order="3" Type="ClaimsExchange">
                    <Preconditions>
                        <Precondition Type="ClaimEquals" ExecuteActionsIf="false">
                            <Value>identityProvider</Value>
                            <Value>externalprovider.com</Value>
                            <Action>SkipThisOrchestrationStep</Action>
                        </Precondition>
                    </Preconditions>
                    <ClaimsExchanges>
                        <ClaimsExchange Id="AADUserReadWithObjectId" TechnicalProfileReferenceId="AAD-UserReadUsingObjectId" />
                    </ClaimsExchanges>
                </OrchestrationStep>

                <!-- Step 5: Create or update local account -->
                <OrchestrationStep Order="4" Type="ClaimsExchange">
                    <ClaimsExchanges>
                        <ClaimsExchange Id="AADUserWrite" TechnicalProfileReferenceId="AAD-UserWriteUsingAlternativeSecurityId" />
                    </ClaimsExchanges>
                </OrchestrationStep>

                <!-- Step 6: Enrich claims if needed -->
                <!-- <OrchestrationStep Order="5" Type="ClaimsExchange">
                    <ClaimsExchanges>
                        <ClaimsExchange Id="EnrichClaims" TechnicalProfileReferenceId="EnrichClaimsFromUserInfo" />
                    </ClaimsExchanges>
                </OrchestrationStep> -->

                <!-- Step 7: Issue tokens -->
                <OrchestrationStep Order="5" Type="SendClaims" CpimIssuerTechnicalProfileReferenceId="JwtIssuer" />

            </OrchestrationSteps>
            <ClientDefinition ReferenceId="DefaultWeb" />
        </UserJourney>

Any help would be appreciated

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
0 comments No comments

1 answer

Sort by: Newest
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.