SAML与Azure AD认证成功,但AuthenticationManager.SignIn无法完成系统认证
SignIn方法参数配置问题
调用AuthenticationManager.SignIn()时,要确认是否正确传入AuthenticationProperties并指定匹配本地系统的认证类型。比如是否设置了IsPersistent属性,以及认证类型是否和Startup中配置的Cookie认证scheme一致。示例代码参考:var authProps = new AuthenticationProperties { IsPersistent = rememberMe }; AuthenticationManager.SignIn(authProps, new ClaimsIdentity(claims, DefaultAuthenticationTypes.ApplicationCookie));ClaimsIdentity认证类型缺失
创建ClaimsIdentity时,第二个参数(认证类型)不能留空或填错。必须指定本地Cookie认证对应的类型(比如DefaultAuthenticationTypes.ApplicationCookie),否则Identity.IsAuthenticated会返回false。别写成new ClaimsIdentity(claims)这种不带认证类型的形式。AuthenticationManager上下文异常
在ExternalLoginCallback里,要确保拿到的是当前请求的正确AuthenticationManager实例。可以直接用HttpContext.GetOwinContext().Authentication获取,避免因上下文传递问题导致SignIn操作不生效。Cookie认证中间件配置不匹配
检查Startup类里的Cookie认证配置,确认AuthenticationType和SignIn时用的完全一致。比如配置代码要类似:app.UseCookieAuthentication(new CookieAuthenticationOptions { AuthenticationType = DefaultAuthenticationTypes.ApplicationCookie, LoginPath = new PathString("/Account/Login") });类型不匹配的话,本地认证会话根本建不起来。
请求未正确结束
调用SignIn()之后,一定要立即做重定向(比如RedirectToAction),不能继续执行后续代码或者直接返回视图。否则Cookie可能没被正确写入响应,客户端收不到认证凭证。
内容的提问来源于stack exchange,提问作者Rakesh Guranani

