You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure应用代理与ASP.NET Core应用配合失效问题排查

ASP.NET Core MVC应用经Azure应用代理部署后认证跳转异常及重定向URI不匹配问题

背景与问题

  • 使用Visual Studio 2022创建基于C#的ASP.NET Core MVC Web应用,Azure应用注册已完成,本地及部署到开发IIS服务器(地址https://DEVSERVERNAME:2212/)时认证均正常运行
  • 部署到生产IIS服务器(绑定地址http://PRODSERVERNAME:2212/)并配置Azure应用代理(代理URLhttps://appproxydotnetcoretest-companyname.msappproxy.net/,内部URLhttp://PRODSERVERNAME:2212/)后:
    • 访问代理URL会重定向到微软认证页面,但认证完成后跳转至http://PRODSERVERNAME:2212/而非代理URL
    • 此前使用.NET Framework环境时无此问题,ASP.NET Core环境下无法正常工作

当前配置

appsettings.json内容

{
  "AzureAd": {
    "Instance": "https://login.microsoftonline.com/",
    "Domain": "CompanyName.onmicrosoft.com",
    "TenantId": "2bxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxx65",
    "ClientId": "cfxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxx35",
    "CallbackPath": "/signin-oidc",
    "ClientSecret": "vDxxxxxxxxxxxxxxxxxxxxxxxxxxnm"
  },
  "Logging": {
    "LogLevel": {
      "Default": "Information",
      "Microsoft.AspNetCore": "Warning"
    }
  },
  "AllowedHosts": "*",
  "MicrosoftGraph": {
    "BaseUrl": "https://graph.microsoft.com/v1.0",
    "Scopes": "user.read"
  }
}
  • Program.cs为项目创建时生成的默认内容

更新:访问代理URL时的错误提示

AADSTS50011: 请求中指定的重定向URI 'http://PRODSERVERNAME:2212/signin-oidc' 与为应用 'cf77c6a2-1ec8-4b55-8b27-6d9dc196c735' 配置的重定向URI不匹配。请确保请求中发送的重定向URI与Azure门户中添加到应用的URI一致。

Azure应用注册已配置的认证重定向URI

http://localhost:5239/signin-oidc
https://localhost:7090/signin-oidc
https://localhost:44372/signin-oidc 
http://localhost:52128/signin-oidc
https://DEVSERVERNAME:2212/signin-oidc
https://appproxydotnetcoretest-companyname.msappproxy.net/

内容的提问来源于stack exchange,提问作者Jeff Craft

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 00:06:01