使用Microsoft.Identity实现多租户登录遇AADSTS50059错误求助
解决多租户应用Client Credentials模式获取Token报错AADSTS50059问题
问题场景
Web应用基于Microsoft.Identity实现多租户登录(支持任意组织用户),appsettings.json中TenantId设为"organizations",已在Entra管理门户将应用配置为允许「任何组织目录中的账户」。但使用Client Credentials模式获取Access Token时,出现错误:
AADSTS50059: No tenant-identifying information found in either the request or implied by any provided credentials
使用应用注册所在组织的具体TenantId时,代码可正常运行。
配置与请求代码如下:
appsettings.json配置
"AzureAd": { "Instance": "https://login.microsoftonline.com/", "Domain": "domain.com", "ClientId": "GUID_CLIENT_ID_FROM_ENTRA", "TenantId": "organizations", "CallbackPath": "/signin-oidc", "ClientSecret": "CLIENT_SECRET", "SkipUnrecognizedRequests": true }
获取Token的代码
RestClient _client = new RestClient("https://login.microsoftonline.com"); var request = new RestRequest("/" + _configuration["AzureAd:TenantId"] + "/oauth2/token", Method.Post); request.AddHeader("Content-Type", "application/x-www-form-urlencoded"); request.AddParameter("grant_type", "client_credentials"); request.AddParameter("client_secret", _configuration["AzureAd:ClientSecret"]); request.AddParameter("client_id", _configuration["AzureAd:ClientId"]); request.AddParameter("resource", "20e940b3-4c77-4b0b-9a53-9e16a1b010a7"); var response = await _client.ExecuteAsync(request);
错误原因
Client Credentials(客户端凭证)授权模式不支持使用"organizations"作为租户ID:
- 该模式下,应用以自身身份直接请求Token,Azure AD需要明确知道为哪个租户颁发Token;
"organizations"是用于用户交互式登录(如授权码流、隐式流)的多租户端点,这类场景有用户上下文可推导租户,但Client Credentials流无用户参与,无法自动确定目标租户,因此触发AADSTS50059错误。
解决方案
1. 指定具体目标租户ID
如果应用需要访问某个特定租户的资源,将请求URL中的租户ID替换为该目标租户的实际ID(可使用租户GUID或域名):
// 替换为目标租户的GUID或域名,例如"contoso.com"或"12345678-1234-1234-1234-1234567890ab" var targetTenantId = "your-target-tenant-id"; var request = new RestRequest($"/{targetTenantId}/oauth2/token", Method.Post);
2. 适配动态租户场景(若需支持任意租户)
如果你的场景是用户登录后,需要获取该用户所在租户的Token,则不能使用Client Credentials模式,应切换为授权码流:
- 先通过用户登录获取授权码,再用授权码请求Token,此时请求会携带用户的租户信息,可动态适配任意租户;
- 若必须使用Client Credentials模式,需在运行时获取用户登录时返回的租户ID(可从
HttpContext的Claims中提取tid字段),再用该ID发起请求。
3. 验证应用权限配置
确保应用在目标租户中已被授予对应的应用权限(而非委托权限),且已完成管理员同意,否则即使租户ID正确,仍可能出现权限不足的错误。
内容的提问来源于stack exchange,提问作者Nitesh
相关产品推荐
相关产品推荐

