使用ITfoxtec.Identity.Saml2测试示例遇AADSTS900235错误,求配置排查
解决AADSTS900235错误:SAML请求的RequestedAuthenticationContext Comparison值问题
错误原因
错误AADSTS900235的核心原因是Azure AD强制要求SAML认证请求中的RequestedAuthenticationContext节点的Comparison属性值必须为'exact',但当前ITfoxtec.Identity.Saml2库默认使用的是'Minimum',不符合Azure AD的校验规则,因此触发了该错误。
解决方案
你需要在配置中显式指定AuthenticationContextComparison为Exact,具体操作如下:
- 修改appsetting.json,添加
authenticationContextComparison配置项:
"Issuer": "https://login.microsoftonline.com/01ec0a12-bbce-40b2-9f30-60c2bf9767c6/saml2", "IdPMetadataFile": "XXXXXX.xml", "SignatureAlgorithm": "http://www.w3.org/2001/04/xmldsig-more#rsa-sha256", "CertificateValidationMode": "None", "RevocationMode": "NoCheck", "authnContext": "http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/windows", "identifierFormat": null, "authenticationContextComparison": "Exact"
- 在代码中将配置映射到Saml2Configuration对象(以ASP.NET Core为例):
确保配置值正确绑定到SAML配置对象,若自动绑定不生效可手动赋值:
var saml2Configuration = new Saml2Configuration(); configuration.GetSection("Saml2").Bind(saml2Configuration); // 手动赋值兜底 saml2Configuration.AuthenticationContextComparison = AuthenticationContextComparisonTypes.Exact;
修改完成后,SAML请求中的RequestedAuthenticationContext节点的Comparison属性会被设置为'exact',符合Azure AD的要求,即可解决该错误。
内容的提问来源于stack exchange,提问作者Alberto Puigdomenech
相关产品推荐
相关产品推荐

