如何仅通过Azure CLI为App Service配置内置身份验证?
问题描述
Stack Overflow上《Enable azure app service authentication and create app registration in azure cli》一文仅覆盖基础应用注册创建阶段,无法完整解决我的问题。我已执行以下命令:
az webapp auth update -n my-webapp -g my-rg --enabled true --action RedirectToLoginPage --enable-token-store false az ad app create --display-name my-app-reg
但不清楚后续操作步骤。
编辑1
我的Azure CLI版本信息如下:
mark@L-R910LPKW:~$ az version { "azure-cli": "2.55.0", "azure-cli-core": "2.55.0", "azure-cli-telemetry": "1.1.0", "extensions": { "aks-preview": "0.5.173", "application-insights": "1.0.0", "authV2": "0.1.3", "azure-devops": "0.26.0", "storage-preview": "1.0.0b1", "virtual-wan": "0.3.0" } } mark@L-R910LPKW:~$
我尝试配置应用注册,进行了两次操作:
尝试1
mark@L-R910LPKW:~$ az webapp auth update -g $resourceGroupName -n $appName --enabled true --action LoginWithAzureActiveDirectory --aad-allowed-token-audiences https://$appName.azurewebsites.net/.auth/login/aad/callback --aad-client-id $appId --aad-client-secret $clientSecret --aad-token-issuer-url https://sts.windows.net/$tenantId/ az webapp auth update: 'LoginWithAzureActiveDirectory' is not a valid value for '--unauthenticated-client-action'. Allowed values: RedirectToLoginPage, AllowAnonymous, Return401, Return404, Return403. Examples from AI knowledge base: az webapp auth update -g myResourceGroup --name MyWebApp --unauthenticated-client-action AllowAnonymous Configure the app to allow unauthenticated requests to hit the app. az webapp auth update -g myResourceGroup --name MyWebApp --set identityProviders.azureActiveDirectory.registration.clientId=my-client-id Update the client ID of the AAD provider already configured az webapp auth update -g myResourceGroup --name MyWebApp --runtime-version 1.4.7 Pin the runtime version of the app to 1.4.7 https://aka.ms/cli_ref Read more about the command in reference docs mark@L-R910LPKW:~$
尝试2
mark@L-R910LPKW:~$ az webapp auth update -g $resourceGroupName -n $appName --enabled true --action RedirectToLoginPage --aad-allowed-token-audiences https://$appName.azurewebsites.net/.auth/login/aad/callback --aad-client-id $appId --aad-client-secret $clientSecret --aad-token-issuer-url https://sts.windows.net/$tenantId/ unrecognized arguments: --aad-allowed-token-audiences https://aida-chat-platform.azurewebsites.net/.auth/login/aad/callback --aad-client-id f8fe5caa-b68b-4caa-bbc2-8862bdd47c4f --aad-client-secret *** --aad-token-issuer-url https://sts.windows.net/2...b/ Examples from AI knowledge base: az webapp auth update --name myUniqueApp --resource-group myResourceGroup Update the authentication settings for the webapp. (autogenerated) az webapp auth update --resource-group myResourceGroup --name myUniqueApp --action AllowAnonymous --facebook-app-id my_fb_id --facebook-app-secret my_fb_secret --facebook-oauth-scopes public_profile email Allow Facebook authentication by setting FB-associated parameters and turning on public-profile and email scopes; allow anonymous users https://docs.microsoft.com/en-US/cli/azure/webapp/auth#az_webapp_auth_update Read more about the command in reference docs mark@L-R910LPKW:~$
编辑2
经排查,问题出在启用了authV2 Azure CLI扩展,导致az webapp auth update命令不再支持LoginWithAzureActiveDirectory操作。移除该扩展(执行az extension remove)后,成功运行了对应命令,SSO登录对话框正常弹出,但登录时出现错误。
编辑3
我执行以下命令尝试修复问题:
az ad app update --id $appId --enable-id-token-issuance true
现在登录时又出现了另一个错误。
内容的提问来源于stack exchange,提问作者mark
相关产品推荐
相关产品推荐

