You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过LDAP对接企业AD实现SSO:仍需Azure AD吗?

核心问题结论

不需要保留Azure AD。客户要求用自身存储用户数据的企业Active Directory(AD)实现认证与SSO,完全可以直接对接本地企业AD,无需通过Azure AD中转。如果客户后续有混合云资源访问需求,可再考虑Azure AD Connect同步本地AD数据,但当前场景下直接对接本地AD即可满足需求。

方案一:ASP.NET Web Forms 对接本地AD(LDAP认证)

适合单应用的用户认证场景,若需多应用SSO,可结合Kerberos或ADFS。

步骤1:配置AD连接字符串

在Web.config中添加企业AD连接信息,替换占位符:

<connectionStrings>
  <add name="ADConnectionString" 
       connectionString="LDAP://你的企业域名/DC=你的企业域名,DC=com" />
</connectionStrings>

步骤2:编写LDAP认证逻辑

创建工具类封装AD身份验证,示例代码:

using System.DirectoryServices;

public class ADAuthHelper
{
    public static bool IsValidUser(string username, string password)
    {
        bool isValid = false;
        string domain = "你的企业域名";
        string ldapPath = System.Configuration.ConfigurationManager.ConnectionStrings["ADConnectionString"].ConnectionString;

        try
        {
            string userIdentity = $"{username}@{domain}";
            using (var entry = new DirectoryEntry(ldapPath, userIdentity, password))
            {
                using (var searcher = new DirectorySearcher(entry))
                {
                    searcher.Filter = $"(&(objectCategory=user)(sAMAccountName={username}))";
                    searcher.PropertiesToLoad.Add("cn");
                    var result = searcher.FindOne();
                    isValid = result != null;
                }
            }
        }
        catch (Exception ex)
        {
            // 添加日志记录异常信息,便于排查登录失败问题
        }
        return isValid;
    }
}

步骤3:集成到登录页面

在Login.aspx.cs后台代码中调用认证方法:

protected void btnLogin_Click(object sender, EventArgs e)
{
    string username = txtUsername.Text.Trim();
    string password = txtPassword.Text.Trim();

    if (ADAuthHelper.IsValidUser(username, password))
    {
        FormsAuthentication.SetAuthCookie(username, chkRememberMe.Checked);
        Response.Redirect("~/Default.aspx");
    }
    else
    {
        lblError.Text = "用户名或密码错误,请重试";
    }
}

步骤4:配置Forms认证规则

在Web.config中启用Forms认证并限制匿名访问:

<system.web>
  <authentication mode="Forms">
    <forms loginUrl="~/Login.aspx" timeout="2880" />
  </authentication>
  <authorization>
    <deny users="?" /> <!-- 禁止匿名用户访问所有页面 -->
  </authorization>
</system.web>

方案二:通过ADFS实现企业级SAML SSO

如果客户需要多应用间的单点登录,推荐使用ADFS(Active Directory Federation Services)——它基于本地AD提供SAML 2.0协议的SSO能力,ASP.NET应用作为服务提供商(SP)对接即可。

步骤1:部署配置ADFS服务器

  • 在客户的企业Windows Server上安装ADFS角色
  • 配置ADFS,将本地AD设置为身份提供商(IdP)
  • 为Web应用创建信赖方信任,指定SP的断言消费者服务(ACS)URL(例如https://你的应用域名/Account/AssertionConsumerService)

步骤2:在Web应用中配置SAML认证

使用微软System.IdentityModel库简化集成,Web.config配置示例:

<system.identityModel>
  <identityConfiguration>
    <audienceUris>
      <add value="https://你的应用域名" />
    </audienceUris>
    <issuerNameRegistry type="System.IdentityModel.Tokens.ConfigurationBasedIssuerNameRegistry, System.IdentityModel">
      <trustedIssuers>
        <add thumbprint="ADFS服务器证书指纹" name="http://adfs.你的企业域名/adfs/services/trust" />
      </trustedIssuers>
    </issuerNameRegistry>
    <certificateValidation certificateValidationMode="None" />
  </identityConfiguration>
</system.identityModel>
<system.identityModel.services>
  <federationConfiguration>
    <cookieHandler requireSsl="true" />
    <wsFederation passiveRedirectEnabled="true" 
                  issuer="https://adfs.你的企业域名/adfs/ls/" 
                  realm="https://你的应用域名" 
                  requireHttps="true" />
  </federationConfiguration>
</system.identityModel.services>

步骤3:处理SAML断言回调

创建AssertionConsumerService.aspx页面,处理ADFS返回的认证断言:

using System.IdentityModel.Services;

public partial class AssertionConsumerService : System.Web.UI.Page
{
    protected void Page_Load(object sender, EventArgs e)
    {
        FederatedAuthentication.WSFederationAuthenticationModule.SignInWithResponseMessage(Request);
        Response.Redirect("~/Default.aspx");
    }
}

步骤4:设置应用授权

在Web.config中限制匿名访问,确保只有ADFS认证用户可访问:

<system.web>
  <authorization>
    <deny users="?" />
  </authorization>
</system.web>

参考文档

  • 《ASP.NET Web Forms LDAP 认证集成指南》(微软官方文档)
  • 《ADFS 部署与信赖方信任配置手册》(微软官方文档)
  • 《SAML 2.0 与ASP.NET Web Forms 集成最佳实践》(微软官方文档)

内容的提问来源于stack exchange,提问作者Snooper_A

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 21:50:28