You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Microsoft.Identity实现多租户登录遇AADSTS50059错误求助

解决多租户应用Client Credentials模式获取Token报错AADSTS50059问题

问题场景

Web应用基于Microsoft.Identity实现多租户登录(支持任意组织用户),appsettings.json中TenantId设为"organizations",已在Entra管理门户将应用配置为允许「任何组织目录中的账户」。但使用Client Credentials模式获取Access Token时,出现错误:

AADSTS50059: No tenant-identifying information found in either the request or implied by any provided credentials

使用应用注册所在组织的具体TenantId时,代码可正常运行。

配置与请求代码如下:

appsettings.json配置

"AzureAd": {
  "Instance": "https://login.microsoftonline.com/",
  "Domain": "domain.com",
  "ClientId": "GUID_CLIENT_ID_FROM_ENTRA",
  "TenantId": "organizations",
  "CallbackPath": "/signin-oidc",
  "ClientSecret": "CLIENT_SECRET",
  "SkipUnrecognizedRequests": true
}

获取Token的代码

RestClient _client = new RestClient("https://login.microsoftonline.com");
var request = new RestRequest("/" + _configuration["AzureAd:TenantId"] + "/oauth2/token", Method.Post);
request.AddHeader("Content-Type", "application/x-www-form-urlencoded");
request.AddParameter("grant_type", "client_credentials");
request.AddParameter("client_secret", _configuration["AzureAd:ClientSecret"]);
request.AddParameter("client_id", _configuration["AzureAd:ClientId"]);
request.AddParameter("resource", "20e940b3-4c77-4b0b-9a53-9e16a1b010a7");
 
var response = await _client.ExecuteAsync(request);

错误原因

Client Credentials(客户端凭证)授权模式不支持使用"organizations"作为租户ID:

  • 该模式下,应用以自身身份直接请求Token,Azure AD需要明确知道为哪个租户颁发Token;
  • "organizations"是用于用户交互式登录(如授权码流、隐式流)的多租户端点,这类场景有用户上下文可推导租户,但Client Credentials流无用户参与,无法自动确定目标租户,因此触发AADSTS50059错误。

解决方案

1. 指定具体目标租户ID

如果应用需要访问某个特定租户的资源,将请求URL中的租户ID替换为该目标租户的实际ID(可使用租户GUID或域名):

// 替换为目标租户的GUID或域名,例如"contoso.com"或"12345678-1234-1234-1234-1234567890ab"
var targetTenantId = "your-target-tenant-id";
var request = new RestRequest($"/{targetTenantId}/oauth2/token", Method.Post);

2. 适配动态租户场景(若需支持任意租户)

如果你的场景是用户登录后,需要获取该用户所在租户的Token,则不能使用Client Credentials模式,应切换为授权码流:

  • 先通过用户登录获取授权码,再用授权码请求Token,此时请求会携带用户的租户信息,可动态适配任意租户;
  • 若必须使用Client Credentials模式,需在运行时获取用户登录时返回的租户ID(可从HttpContext的Claims中提取tid字段),再用该ID发起请求。

3. 验证应用权限配置

确保应用在目标租户中已被授予对应的应用权限(而非委托权限),且已完成管理员同意,否则即使租户ID正确,仍可能出现权限不足的错误。

内容的提问来源于stack exchange,提问作者Nitesh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 19:57:01