You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Office365与ASP.NET MVC应用共享Cookie引发错误,如何禁止共享?

解决方案:禁止复用Office365会话Cookie,强制独立认证流程

要解决这个问题,你可以通过配置OpenIdConnect中间件,强制认证流程忽略浏览器中已有的Microsoft身份会话,避免触发禁用应用的错误。具体实现如下:

1. 修改OpenIdConnect认证配置

在你的Startup.cs文件的ConfigureAuth方法中,调整OpenIdConnectAuthenticationOptions的参数:

app.UseOpenIdConnectAuthentication(new OpenIdConnectAuthenticationOptions
{
    ClientId = "你的应用ClientId",
    Authority = "https://login.microsoftonline.com/你的租户ID/v2.0",
    RedirectUri = "你的回调地址",
    PostLogoutRedirectUri = "你的登出回调地址",
    // 强制用户选择账号,忽略已有Office365会话
    Prompt = "select_account", 
    // 若需严格强制重新输入凭据,可替换为:
    // Prompt = "login",

    Notifications = new OpenIdConnectAuthenticationNotifications
    {
        AuthenticationFailed = context =>
        {
            context.HandleResponse();
            context.Response.Redirect("/Error?message=" + context.Exception.Message);
            return Task.FromResult(0);
        }
    }
});

参数说明:

  • Prompt = "select_account":弹出账号选择界面,让用户重新选择登录当前应用的账号,不会复用浏览器中已有的Office365会话。
  • Prompt = "login":强制用户重新输入账号密码,完全跳过已有会话复用,适合需要严格隔离登录状态的场景。

2. 额外优化:自定义应用认证Cookie名称

为进一步隔离应用与Office365的Cookie,可修改应用自身的认证Cookie名称,避免混淆:

app.UseCookieAuthentication(new CookieAuthenticationOptions
{
    AuthenticationType = DefaultAuthenticationTypes.ApplicationCookie,
    LoginPath = new PathString("/Account/Login"),
    // 自定义Cookie名称,替换为你的应用专属标识
    CookieName = "YourAppAuthCookie"
});

完成以上配置后,用户访问你的应用时,即使浏览器中已有Office365登录会话,也会触发独立的认证流程,不会因复用会话触发AAD中禁用应用的错误。


内容的提问来源于stack exchange,提问作者andreasperelli

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 19:50:03