You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Blazor WebApp集成Microsoft Graph时AADSTS700025错误求助

问题解决与实现方案

一、解决AADSTS700025认证错误

你的核心问题是公共客户端类型的应用不能使用ClientSecret,但项目配置默认要求密钥,按以下步骤修复:

  1. 移除Secrets.json中的AzureAD:ClientSecret配置项
  2. 在appsettings.json或Secrets.json的AzureAD节点中添加"ClientCredentialType": "None",明确告知SDK这是公共客户端,无需凭据:
"AzureAD": {
  "Instance": "https://login.microsoftonline.com/",
  "Domain": "你的租户域名",
  "TenantId": "你的租户ID",
  "ClientId": "你的应用ID",
  "CallbackPath": "/signin-oidc",
  "ClientCredentialType": "None"
},
"MicrosoftGraph": {
  "BaseUrl": "https://graph.microsoft.com/v1.0",
  "Scopes": "Directory.Read.All"
}
  1. 调整Program.cs中的认证配置(保留你添加的3行Graph相关代码):
var builder = WebApplication.CreateBuilder(args);

builder.Services.AddRazorPages();
builder.Services.AddServerSideBlazor();

// 配置Entra ID认证+Graph API访问
builder.Services.AddAuthentication(OpenIdConnectDefaults.AuthenticationScheme)
    .AddMicrosoftIdentityWebApp(builder.Configuration.GetSection("AzureAD"))
    .EnableTokenAcquisitionToCallDownstreamApi()
    .AddMicrosoftGraph(builder.Configuration.GetSection("MicrosoftGraph"))
    .AddInMemoryTokenCaches();

builder.Services.AddAuthorization();

var app = builder.Build();

if (!app.Environment.IsDevelopment())
{
    app.UseExceptionHandler("/Error");
    app.UseHsts();
}

app.UseHttpsRedirection();
app.UseStaticFiles();
app.UseRouting();

app.UseAuthentication();
app.UseAuthorization();

app.MapBlazorHub();
app.MapFallbackToPage("/_Host");

app.Run();

二、实现基于安全组的页面授权

提供两种方案,按需选择:

方案1:利用ID令牌中的Groups声明(高效)

  1. 登录Entra ID门户,找到你的应用注册,进入Token configuration页面
  2. 点击Add groups claim,配置:
    • 组类型:选择「安全组」
    • 声明类型:选择「Group ID」(推荐用ObjectID,避免名称变更影响)
    • 可选:勾选「Emit groups as role claims」,方便授权策略配置
  3. 在Program.cs中添加自定义授权策略:
builder.Services.AddAuthorization(options =>
{
    // 替换为你的目标安全组ObjectID
    options.AddPolicy("SpecificSecurityGroupOnly", policy =>
        policy.RequireClaim("groups", "你的安全组ObjectID"));
});
  1. 在需要限制的Blazor页面/组件上添加授权特性:
@page "/restricted"
@attribute [Authorize(Policy = "SpecificSecurityGroupOnly")]

<h3>仅限特定安全组成员访问</h3>

方案2:通过Microsoft Graph API动态查询(灵活)

  1. 在应用注册的API权限页面,添加Directory.Read.All委托权限,并点击「授予管理员同意」(租户内应用需管理员操作)
  2. 在Blazor组件中注入服务并查询用户所属组:
@page "/restricted-graph"
@inject GraphServiceClient GraphClient
@inject AuthenticationStateProvider AuthStateProvider
@inject NavigationManager NavManager

<h3>仅限特定安全组成员访问(Graph动态验证)</h3>

@code {
    protected override async Task OnInitializedAsync()
    {
        var authState = await AuthStateProvider.GetAuthenticationStateAsync();
        var user = authState.User;
        
        if (!user.Identity.IsAuthenticated)
        {
            NavManager.NavigateTo("/MicrosoftIdentity/Account/SignIn");
            return;
        }

        var userId = user.FindFirstValue(System.Security.Claims.ClaimTypes.NameIdentifier);
        var targetGroupId = "你的安全组ObjectID";
        
        try
        {
            // 调用Graph API验证用户是否属于目标组
            var isMember = await GraphClient.Users[userId]
                .CheckMemberOf(targetGroupId)
                .Request()
                .PostAsync();
            
            if (!isMember.Value)
            {
                NavManager.NavigateTo("/unauthorized");
            }
        }
        catch
        {
            NavManager.NavigateTo("/unauthorized");
        }
    }
}

内容的提问来源于stack exchange,提问作者marius

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 06:27:09