You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure B2C IEF应用无法配置第三方未验证域为identifierUri求助

解决Azure B2C IEF应用配置第三方域IdentifierUri的问题

核心解决方案:通过Microsoft Graph API(Beta版本)配置

Azure门户UI会强制验证域的所有权,但通过Microsoft Graph API结合设置accessTokenAcceptedVersion: 2,可以绕过这个限制,具体步骤如下:

  1. 获取目标应用的Object ID

    • 登录Azure门户,进入你的B2C租户,打开「应用注册」
    • 找到需要配置的IEF应用,复制其「对象ID」
  2. 获取Microsoft Graph访问令牌

    • 使用具有「应用程序管理员」权限的账号,通过Azure CLI获取访问令牌,命令示例:
      az account set --subscription <你的订阅ID>
      az account get-access-token --resource https://graph.microsoft.com
      
      执行后会返回包含accessToken的结果,复制该令牌备用
  3. 发送PATCH请求更新应用配置
    使用Graph API的Beta端点完成配置修改:

    • 请求地址:https://graph.microsoft.com/beta/applications/{应用Object ID}
    • 请求方法:PATCH
    • 请求头:设置Content-Type: application/json,并添加Authorization: Bearer <你的访问令牌>
    • 请求体示例(替换为实际的第三方域URI):
      {
        "identifierUris": ["https://第三方域.com/指定的IssuerUri"],
        "accessTokenAcceptedVersion": 2
      }
      

补充说明

  • 此方法符合Azure官方指导逻辑:设置accessTokenAcceptedVersion: 2后,允许应用使用未验证的第三方域作为identifierUri
  • 不要直接在Azure门户UI中修改,因为门户会触发域验证逻辑,导致报错

内容的提问来源于stack exchange,提问作者Justin Massey

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 16:53:25