You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用ITfoxtec.Identity.Saml2测试示例遇AADSTS900235错误,求配置排查

解决AADSTS900235错误:SAML请求的RequestedAuthenticationContext Comparison值问题

错误原因

错误AADSTS900235的核心原因是Azure AD强制要求SAML认证请求中的RequestedAuthenticationContext节点的Comparison属性值必须为'exact',但当前ITfoxtec.Identity.Saml2库默认使用的是'Minimum',不符合Azure AD的校验规则,因此触发了该错误。

解决方案

你需要在配置中显式指定AuthenticationContextComparison为Exact,具体操作如下:

  1. 修改appsetting.json,添加authenticationContextComparison配置项:
"Issuer": "https://login.microsoftonline.com/01ec0a12-bbce-40b2-9f30-60c2bf9767c6/saml2",
"IdPMetadataFile": "XXXXXX.xml",
"SignatureAlgorithm": "http://www.w3.org/2001/04/xmldsig-more#rsa-sha256",
"CertificateValidationMode": "None",
"RevocationMode": "NoCheck",
"authnContext": "http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/windows",
"identifierFormat": null,
"authenticationContextComparison": "Exact"
  1. 在代码中将配置映射到Saml2Configuration对象(以ASP.NET Core为例):
    确保配置值正确绑定到SAML配置对象,若自动绑定不生效可手动赋值:
var saml2Configuration = new Saml2Configuration();
configuration.GetSection("Saml2").Bind(saml2Configuration);
// 手动赋值兜底
saml2Configuration.AuthenticationContextComparison = AuthenticationContextComparisonTypes.Exact;

修改完成后,SAML请求中的RequestedAuthenticationContext节点的Comparison属性会被设置为'exact',符合Azure AD的要求,即可解决该错误。

内容的提问来源于stack exchange,提问作者Alberto Puigdomenech

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 09:10:15