Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Important
Effective May 1, 2025, Azure AD B2C will no longer be available to purchase for new customers. Learn more in our FAQ.
Before you begin, use the Choose a policy type selector at the top of this page to choose the type of policy you’re setting up. Azure Active Directory B2C offers two methods to define how users interact with your applications: through predefined user flows or through fully configurable custom policies. The steps required in this article are different for each method.
Prerequisites
- Create a user flow so users can sign up and sign in to your application.
- Register a web application.
- Complete the steps in Get started with custom policies in Active Directory B2C. This tutorial guides you how to update custom policy files to use your Azure AD B2C tenant configuration.
- Register a web application.
Create a PingOne application
To enable sign-in for users with a PingOne (Ping Identity) account in Azure Active Directory B2C (Azure AD B2C), you need to create an application in the Ping Identity Administrator Console. If you don't already have a PingOne account, you can sign up at https://admin.pingone.com/web-portal/register.
- Sign in to the Ping Identity Administrator Console with your PingOne account credentials.
- In the left menu of the page, select Connections, then next to Applications, select +.
- On the New Application page, select web app, then under OIDC, select Configure.
- Enter an Application name, and select Next.
- For the Redirect URLs, enter https://your-tenant-name.b2clogin.com/your-tenant-name.onmicrosoft.com/oauth2/authresp. If you use a custom domain, enterhttps://your-domain-name/your-tenant-name.onmicrosoft.com/oauth2/authresp. Replaceyour-domain-namewith your custom domain, andyour-tenant-namewith the name of your tenant. Use all lowercase letters when entering your tenant name even if the tenant is defined with uppercase letters in Azure AD B2C.
- Select Save and Continue.
- Under SCOPES select email, and profile, then select Save and Continue.
- Under OIDC attributes page, select Save and Close.
- From the list of applications, select the application you created.
- In the application Profile page, do the following:
- Next to the application name enable the app using the switch button.
- Copy the values of Client ID.
 
- Select the Configuration tab, and do the following:
- Copy the OIDC discovery endpoint.
- Show and copy the Client secret.
- Change the mode to edit. Then, under the Token endpoint authentication method change the value to Client Secret Post, and select Save
 
Configure PingOne as an identity provider
- If you have access to multiple tenants, select the Settings icon in the top menu to switch to your Azure AD B2C tenant from the Directories + subscriptions menu. 
- Choose All services in the top-left corner of the Azure portal, and then search for and select Azure AD B2C. 
- Select Identity providers, and then select New OpenID Connect provider. 
- Enter a Name. For example, enter PingOne. 
- For Metadata url, enter the OIDC DISCOVERY ENDPOINT that you previously recorded. For example: - https://auth.pingone.eu/00000000-0000-0000-0000-000000000000/as/.well-known/openid-configuration
- For Client ID, enter the client ID that you previously recorded. 
- For Client secret, enter the client secret that you previously recorded. 
- For Scope, enter - openid email profile.
- Leave the default values for Response type, and Response mode. 
- (Optional) For the Domain hint, enter - pingone.com. For more information, see Set up direct sign-in using Azure Active Directory B2C.
- Under Identity provider claims mapping, select the following claims: - User ID: sub
- Display name: name
- Given name: given_name
- Surname: family_name
- Email: email
 
- Select Save. 
Add PingOne identity provider to a user flow
At this point, the PingOne identity provider has been set up, but it's not yet available in any of the sign-in pages. To add the PingOne identity provider to a user flow:
- In your Azure AD B2C tenant, select User flows.
- Click the user flow that you want to add the PingOne identity provider.
- Under the Social identity providers, select PingOne.
- Select Save.
- To test your policy, select Run user flow.
- For Application, select the web application named testapp1 that you previously registered. The Reply URL should show https://jwt.ms.
- Select the Run user flow button.
- From the sign-up or sign-in page, select PingOne to sign in with PingOne account.
If the sign-in process is successful, your browser is redirected to https://jwt.ms, which displays the contents of the token returned by Azure AD B2C.
Create a policy key
You need to store the client secret that you previously recorded in your Azure AD B2C tenant.
- Sign in to the Azure portal.
- If you have access to multiple tenants, select the Settings icon in the top menu to switch to your Azure AD B2C tenant from the Directories + subscriptions menu.
- Choose All services in the top-left corner of the Azure portal, and then search for and select Azure AD B2C.
- On the Overview page, select Identity Experience Framework.
- Select Policy Keys and then select Add.
- For Options, choose Manual.
- Enter a Name for the policy key. For example, PingOneSecret. The prefixB2C_1A_is added automatically to the name of your key.
- In Secret, enter your client secret that you previously recorded.
- For Key usage, select Signature.
- Click Create.
Configure PingOne as an identity provider
To enable users to sign in using a PingOne account, you need to define the account as a claims provider that Azure AD B2C can communicate with through an endpoint. The endpoint provides a set of claims that are used by Azure AD B2C to verify that a specific user has authenticated.
You can define a PingOne account as a claims provider by adding it to the ClaimsProviders element in the extension file of your policy.
- Open the TrustFrameworkExtensions.xml. 
- Find the ClaimsProviders element. If it does not exist, add it under the root element. 
- Add a new ClaimsProvider as follows: - <ClaimsProvider> <Domain>pingone.com</Domain> <DisplayName>PingOne</DisplayName> <TechnicalProfiles> <TechnicalProfile Id="PingOne-OpenIdConnect"> <DisplayName>Ping Identity</DisplayName> <Protocol Name="OpenIdConnect" /> <Metadata> <Item Key="METADATA">Your PingOne OIDC discovery endpoint</Item> <Item Key="client_id">Your PingOne client ID</Item> <Item Key="response_types">code</Item> <Item Key="scope">openid email profile</Item> <Item Key="HttpBinding">POST</Item> <Item Key="UsePolicyInRedirectUri">0</Item> </Metadata> <CryptographicKeys> <Key Id="client_secret" StorageReferenceId="B2C_1A_PingOneSecret" /> </CryptographicKeys> <OutputClaims> <OutputClaim ClaimTypeReferenceId="issuerUserId" PartnerClaimType="sub" /> <OutputClaim ClaimTypeReferenceId="email" PartnerClaimType="email" /> <OutputClaim ClaimTypeReferenceId="givenName" PartnerClaimType="given_name" /> <OutputClaim ClaimTypeReferenceId="surname" PartnerClaimType="family_name" /> <OutputClaim ClaimTypeReferenceId="displayName" PartnerClaimType="name" /> <OutputClaim ClaimTypeReferenceId="identityProvider" PartnerClaimType="iss" /> <OutputClaim ClaimTypeReferenceId="authenticationSource" DefaultValue="socialIdpAuthentication" /> </OutputClaims> <OutputClaimsTransformations> <OutputClaimsTransformation ReferenceId="CreateRandomUPNUserName" /> <OutputClaimsTransformation ReferenceId="CreateUserPrincipalName" /> <OutputClaimsTransformation ReferenceId="CreateAlternativeSecurityId" /> <OutputClaimsTransformation ReferenceId="CreateSubjectClaimFromAlternativeSecurityId" /> </OutputClaimsTransformations> <UseTechnicalProfileForSessionManagement ReferenceId="SM-SocialLogin" /> </TechnicalProfile> </TechnicalProfiles> </ClaimsProvider>
- Set the - METADATAmetadata to your PingOne OIDC discovery endpoint.
- Set - client_idmetadata to your PingOne client ID.
- Save the file. 
Add a user journey
At this point, the identity provider has been set up, but it's not yet available in any of the sign-in pages. If you don't have your own custom user journey, create a duplicate of an existing template user journey, otherwise continue to the next step.
- Open the TrustFrameworkBase.xml file from the starter pack.
- Find and copy the entire contents of the UserJourney element that includes Id="SignUpOrSignIn".
- Open the TrustFrameworkExtensions.xml and find the UserJourneys element. If the element doesn't exist, add one.
- Paste the entire content of the UserJourney element that you copied as a child of the UserJourneys element.
- Rename the Id of the user journey. For example, Id="CustomSignUpSignIn".
Add the identity provider to a user journey
Now that you have a user journey, add the new identity provider to the user journey. You first add a sign-in button, then link the button to an action. The action is the technical profile you created earlier.
- Find the orchestration step element that includes - Type="CombinedSignInAndSignUp", or- Type="ClaimsProviderSelection"in the user journey. It's usually the first orchestration step. The ClaimsProviderSelections element contains a list of identity providers that a user can sign in with. The order of the elements controls the order of the sign-in buttons presented to the user. Add a ClaimsProviderSelection XML element. Set the value of TargetClaimsExchangeId to a friendly name.
- In the next orchestration step, add a ClaimsExchange element. Set the Id to the value of the target claims exchange Id. Update the value of TechnicalProfileReferenceId to the Id of the technical profile you created earlier. 
The following XML demonstrates the first two orchestration steps of a user journey with the identity provider:
<OrchestrationStep Order="1" Type="CombinedSignInAndSignUp" ContentDefinitionReferenceId="api.signuporsignin">
  <ClaimsProviderSelections>
    ...
    <ClaimsProviderSelection TargetClaimsExchangeId="PingOneExchange" />
  </ClaimsProviderSelections>
  ...
</OrchestrationStep>
<OrchestrationStep Order="2" Type="ClaimsExchange">
  ...
  <ClaimsExchanges>
    <ClaimsExchange Id="PingOneExchange" TechnicalProfileReferenceId="PingOne-OpenIdConnect" />
  </ClaimsExchanges>
</OrchestrationStep>
Configure the relying party policy
The relying party policy, for example SignUpSignIn.xml, specifies the user journey which Azure AD B2C will execute. Find the DefaultUserJourney element within relying party. Update the ReferenceId to match the user journey ID, in which you added the identity provider.
In the following example, for the CustomSignUpSignIn user journey, the ReferenceId is set to CustomSignUpSignIn:
<RelyingParty>
  <DefaultUserJourney ReferenceId="CustomSignUpSignIn" />
  ...
</RelyingParty>
Upload the custom policy
- Sign in to the Azure portal.
- Select the Directory + Subscription icon in the portal toolbar, and then select the directory that contains your Azure AD B2C tenant.
- In the Azure portal, search for and select Azure AD B2C.
- Under Policies, select Identity Experience Framework.
- Select Upload Custom Policy, and then upload the two policy files that you changed, in the following order: the extension policy, for example TrustFrameworkExtensions.xml, then the relying party policy, such asSignUpSignIn.xml.
Test your custom policy
- Select your relying party policy, for example B2C_1A_signup_signin.
- For Application, select a web application that you previously registered. The Reply URL should show https://jwt.ms.
- Select the Run now button.
- From the sign-up or sign-in page, select PingOne to sign in with PingOne account.
If the sign-in process is successful, your browser is redirected to https://jwt.ms, which displays the contents of the token returned by Azure AD B2C.
Next steps
Learn how to pass a PingOne token to your application.