You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何修改Azure AD重定向URL?配置后仍遇AADSTS50011错误的问询

解决AADSTS50011错误:正确配置Azure AD重定向URL

AADSTS50011错误的核心原因是Azure AD收到的重定向URI与应用注册中配置的URI完全不匹配,结合你的代码和场景,按以下步骤修改即可解决:

1. 修正代码中的RedirectUri设置

取消注释RedirectUri行,并填入包含OWIN默认回调路径的完整URI——OWIN的OpenIdConnect中间件默认使用/signin-oidc作为回调路径,所以正确的配置如下:

public void ConfigureAuth(IAppBuilder app)
{
    System.Net.ServicePointManager.SecurityProtocol |= SecurityProtocolType.Tls12;
    app.SetDefaultSignInAsAuthenticationType(CookieAuthenticationDefaults.AuthenticationType);

    app.UseCookieAuthentication(new CookieAuthenticationOptions
    {
        CookieManager = new SystemWebCookieManager()
    });

    app.UseOpenIdConnectAuthentication(
        new OpenIdConnectAuthenticationOptions
        {
            ClientId = myclientId,
            Authority = authority,
            PostLogoutRedirectUri = mypostLogoutRedirectUri,
            // 关键:填入完整的重定向URI,包含/signin-oidc路径
            RedirectUri = "http://localhost:43999/signin-oidc",

            Notifications = new OpenIdConnectAuthenticationNotifications
            {
                AuthenticationFailed = (context) =>
                {
                    context.HandleResponse();
                    context.OwinContext.Response.Redirect("/Home/auth_error");
                    return Task.FromResult(0);
                },
                SecurityTokenValidated = (context) =>
                {
                    string name = context.AuthenticationTicket.Identity.Name;
                    context.AuthenticationTicket.Identity.AddClaim(new Claim(ClaimTypes.Name, name, string.Empty));
                    return System.Threading.Tasks.Task.FromResult(0);
                }
            }
        });
}

注:如果你的应用使用自定义回调路径,替换为对应路径即可,绝大多数场景下使用默认的/signin-oidc即可。

2. 在Azure AD应用注册中同步配置重定向URI

  1. 登录Azure门户,找到对应的Azure AD应用注册
  2. 进入身份验证页面
  3. 在重定向URI区域,点击「添加URI」,填入和代码中完全一致的URI(比如http://localhost:43999/signin-oidc),类型选择「Web」
  4. 点击「保存」按钮(务必保存,否则配置不会生效)

3. 排查常见坑点

  • 端口一致性:确保代码中的端口和Azure配置的端口完全一致,若VS使用随机端口,可在项目属性的「Web」选项卡中固定端口,避免每次启动端口变化
  • 协议匹配:如果使用HTTPS,代码和Azure配置的URI都要以https://开头,不能混合HTTP和HTTPS
  • 清除浏览器缓存:旧的认证Cookie可能导致重定向异常,清除缓存后重新测试
  • Authority正确性:确认authority参数格式正确,比如V1端点为https://login.microsoftonline.com/{你的租户ID},V2端点为https://login.microsoftonline.com/{你的租户ID}/v2.0

内容的提问来源于stack exchange,提问作者Leventogenna

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 18:03:10