能否用两个Azure AD B2C租户保护同一套Web API?
问题
- 能否使用两个不同的Azure AD B2C租户保护同一Web API,让两款不同的移动应用均可调用该API?需先确认可行性再测试,避免影响现有用户。
- 是否可通过Bicep实现该配置?该功能是否在规划路线中?
- 如何在
appsetting.json中配置第二个身份提供商?现有配置及Startup.cs代码如下,添加第二组配置后启动报错Scheme already exists: Bearer。
现有appsetting.json配置
"AzureAdB2C": { "Instance": "https://[identity url]", "ClientId": "[client id]", "CallbackPath": "/[callback path]", "Domain": "[domain]", "SignUpSignInPolicyId": "[susi flow]", "ResetPasswordPolicyId": "[reset flow]", "EditProfilePolicyId": "[edit flow]" },
现有Startup.cs配置
services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme) .AddMicrosoftIdentityWebApi(options => { Configuration.Bind("AzureAdB2C", options); options.TokenValidationParameters.NameClaimType = "name"; }, options => { Configuration.Bind("AzureAdB2C", options); });
报错信息
crit: Microsoft.AspNetCore.Hosting.Diagnostics[6] Application startup exception System.InvalidOperationException: Scheme already exists: Bearer
解答
1. 多Azure AD B2C租户保护API的可行性
完全可行。Web API可以接受来自多个B2C租户颁发的JWT令牌,只需为每个租户配置独立的身份验证方案,验证令牌的签名、受众等核心参数即可。
2. Bicep配置支持
可以通过Bicep实现该配置。Bicep支持定义Azure AD B2C的应用注册、API权限等资源,也能配置Web API的身份验证相关设置。该场景属于常规可实现的配置,不在官方明确的“未规划”范围内。
3. 多身份提供商配置及报错解决
报错原因是重复使用了默认的Bearer身份验证方案名称,每个身份提供商需要指定唯一的方案名称,具体步骤如下:
步骤1:更新appsetting.json
添加第二组B2C配置,命名为AzureAdB2C2:
"AzureAdB2C": { "Instance": "https://[identity url]", "ClientId": "[client id]", "CallbackPath": "/[callback path]", "Domain": "[domain]", "SignUpSignInPolicyId": "[susi flow]", "ResetPasswordPolicyId": "[reset flow]", "EditProfilePolicyId": "[edit flow]" }, "AzureAdB2C2": { "Instance": "https://[second identity url]", "ClientId": "[second client id]", "CallbackPath": "/[second callback path]", "Domain": "[second domain]", "SignUpSignInPolicyId": "[second susi flow]", "ResetPasswordPolicyId": "[second reset flow]", "EditProfilePolicyId": "[second edit flow]" }
步骤2:修改Startup.cs配置
注册两个独立的身份验证方案,指定不同的方案名称,并配置授权策略支持多方案验证:
// 注册第一个B2C租户的身份验证方案 services.AddAuthentication() .AddMicrosoftIdentityWebApi("B2CScheme1", options => { Configuration.Bind("AzureAdB2C", options); options.TokenValidationParameters.NameClaimType = "name"; }, options => { Configuration.Bind("AzureAdB2C", options); }) // 注册第二个B2C租户的身份验证方案 .AddMicrosoftIdentityWebApi("B2CScheme2", options => { Configuration.Bind("AzureAdB2C2", options); options.TokenValidationParameters.NameClaimType = "name"; }, options => { Configuration.Bind("AzureAdB2C2", options); }); // 设置默认授权策略,允许任一B2C租户的有效令牌通过 services.AddAuthorization(options => { var defaultPolicyBuilder = new AuthorizationPolicyBuilder( "B2CScheme1", "B2CScheme2"); defaultPolicyBuilder.RequireAuthenticatedUser(); options.DefaultPolicy = defaultPolicyBuilder.Build(); });
额外说明
- 每个
AddMicrosoftIdentityWebApi调用的第一个参数是唯一的方案名称,避免冲突。 - 若需要精细化控制(比如部分API端点仅允许特定租户访问),可创建自定义授权策略,在控制器/方法上通过
[Authorize(Policy = "SpecificTenantPolicy")]标注。
内容的提问来源于stack exchange,提问作者lcj
相关产品推荐
相关产品推荐

