You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在MVC应用中配置Azure AD 2FA的Entity ID与ACS URL?

配置MVC应用的Microsoft 2FA Entity ID与ACS URL

1. Entity ID 配置

  • Entity ID是你的应用在Microsoft身份系统中的唯一标识,对应Azure AD应用注册里的**Application ID URI**。
  • 根据MVC版本的不同,配置方式如下:
    • ASP.NET MVC 5(OWIN):在Startup.Auth.cs的UseOpenIdConnectAuthentication配置块中,通过TokenValidationParameters指定ValidAudience为你的Entity ID:
      app.UseOpenIdConnectAuthentication(new OpenIdConnectAuthenticationOptions
      {
          // 保留其他已有配置
          TokenValidationParameters = new TokenValidationParameters
          {
              ValidAudience = "https://your-domain.com/your-app-unique-id", // 替换为你的Entity ID
              // 其他验证参数
          }
      });
      
    • ASP.NET Core MVC:在Program.cs或Startup.cs的身份验证配置里,给OpenID Connect设置Audience:
      builder.Services.AddAuthentication(options =>
      {
          options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
          options.DefaultChallengeScheme = OpenIdConnectDefaults.AuthenticationScheme;
      })
      .AddCookie()
      .AddOpenIdConnect(options =>
      {
          options.ClientId = "your-client-id";
          options.Authority = "https://login.microsoftonline.com/your-tenant-id/v2.0";
          options.Audience = "https://your-domain.com/your-app-unique-id"; // 替换为你的Entity ID
          // 其他配置项
      });
      

2. ACS URL 配置

  • ACS URL是应用接收Microsoft身份验证响应的回调地址,必须和Azure AD应用注册中配置的重定向URI完全一致。
  • 配置方式:
    • ASP.NET MVC 5(OWIN):在OpenIdConnectAuthenticationOptions中设置RedirectUri为你的应用部署后的回调地址(比如https://your-app-deploy-url/signin-oidc):
      app.UseOpenIdConnectAuthentication(new OpenIdConnectAuthenticationOptions
      {
          RedirectUri = "https://your-app-deploy-url/signin-oidc", // 替换为你的ACS URL
          // 其他已有配置
      });
      
    • ASP.NET Core MVC:可以通过CallbackPath设置相对路径(部署后会自动拼接成完整ACS URL),或者直接指定完整URL:
      .AddOpenIdConnect(options =>
      {
          // 其他配置
          options.CallbackPath = "/signin-oidc"; // 相对路径,对应完整ACS URL为部署域名+该路径
          // 或者直接写完整URL:
          // options.RedirectUri = "https://your-app-deploy-url/signin-oidc";
      });
      
  • 关键提醒:ACS URL必须提前在Azure AD应用注册的“重定向URI”列表中添加并验证,否则身份验证请求会被拒绝。

注意点

  • Entity ID必须和Azure AD应用注册里的Application ID URI完全匹配,包括大小写、路径等细节。
  • 如果是本地测试环境,ACS URL需要是公开可访问的地址(可以用ngrok工具把本地端口映射到公网),否则Microsoft身份服务无法回调。

内容的提问来源于stack exchange,提问作者raj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 00:43:09