You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否用两个Azure AD B2C租户保护同一套Web API?

问题
  • 能否使用两个不同的Azure AD B2C租户保护同一Web API,让两款不同的移动应用均可调用该API?需先确认可行性再测试,避免影响现有用户。
  • 是否可通过Bicep实现该配置?该功能是否在规划路线中?
  • 如何在appsetting.json中配置第二个身份提供商?现有配置及Startup.cs代码如下,添加第二组配置后启动报错Scheme already exists: Bearer。

现有appsetting.json配置

"AzureAdB2C": {
    "Instance": "https://[identity url]",
    "ClientId": "[client id]",
    "CallbackPath": "/[callback path]",
    "Domain": "[domain]",
    "SignUpSignInPolicyId": "[susi flow]",
    "ResetPasswordPolicyId": "[reset flow]",
    "EditProfilePolicyId": "[edit flow]"
  },

现有Startup.cs配置

services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
                .AddMicrosoftIdentityWebApi(options => 
            {
                Configuration.Bind("AzureAdB2C", options);
                options.TokenValidationParameters.NameClaimType = "name";
            },
            options => { Configuration.Bind("AzureAdB2C", options); });

报错信息

crit: Microsoft.AspNetCore.Hosting.Diagnostics[6]
      Application startup exception
      System.InvalidOperationException: Scheme already exists: Bearer

解答

1. 多Azure AD B2C租户保护API的可行性

完全可行。Web API可以接受来自多个B2C租户颁发的JWT令牌,只需为每个租户配置独立的身份验证方案,验证令牌的签名、受众等核心参数即可。

2. Bicep配置支持

可以通过Bicep实现该配置。Bicep支持定义Azure AD B2C的应用注册、API权限等资源,也能配置Web API的身份验证相关设置。该场景属于常规可实现的配置,不在官方明确的“未规划”范围内。

3. 多身份提供商配置及报错解决

报错原因是重复使用了默认的Bearer身份验证方案名称,每个身份提供商需要指定唯一的方案名称,具体步骤如下:

步骤1:更新appsetting.json

添加第二组B2C配置,命名为AzureAdB2C2:

"AzureAdB2C": {
    "Instance": "https://[identity url]",
    "ClientId": "[client id]",
    "CallbackPath": "/[callback path]",
    "Domain": "[domain]",
    "SignUpSignInPolicyId": "[susi flow]",
    "ResetPasswordPolicyId": "[reset flow]",
    "EditProfilePolicyId": "[edit flow]"
  },
  "AzureAdB2C2": {
    "Instance": "https://[second identity url]",
    "ClientId": "[second client id]",
    "CallbackPath": "/[second callback path]",
    "Domain": "[second domain]",
    "SignUpSignInPolicyId": "[second susi flow]",
    "ResetPasswordPolicyId": "[second reset flow]",
    "EditProfilePolicyId": "[second edit flow]"
  }

步骤2:修改Startup.cs配置

注册两个独立的身份验证方案,指定不同的方案名称,并配置授权策略支持多方案验证:

// 注册第一个B2C租户的身份验证方案
services.AddAuthentication()
        .AddMicrosoftIdentityWebApi("B2CScheme1", options =>
        {
            Configuration.Bind("AzureAdB2C", options);
            options.TokenValidationParameters.NameClaimType = "name";
        }, options =>
        {
            Configuration.Bind("AzureAdB2C", options);
        })
        // 注册第二个B2C租户的身份验证方案
        .AddMicrosoftIdentityWebApi("B2CScheme2", options =>
        {
            Configuration.Bind("AzureAdB2C2", options);
            options.TokenValidationParameters.NameClaimType = "name";
        }, options =>
        {
            Configuration.Bind("AzureAdB2C2", options);
        });

// 设置默认授权策略,允许任一B2C租户的有效令牌通过
services.AddAuthorization(options =>
{
    var defaultPolicyBuilder = new AuthorizationPolicyBuilder(
        "B2CScheme1", "B2CScheme2");
    defaultPolicyBuilder.RequireAuthenticatedUser();
    options.DefaultPolicy = defaultPolicyBuilder.Build();
});

额外说明

  • 每个AddMicrosoftIdentityWebApi调用的第一个参数是唯一的方案名称,避免冲突。
  • 若需要精细化控制(比如部分API端点仅允许特定租户访问),可创建自定义授权策略,在控制器/方法上通过[Authorize(Policy = "SpecificTenantPolicy")]标注。

内容的提问来源于stack exchange,提问作者lcj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 06:35:56