You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET MVC应用中Microsoft SSO登录无法跳转至微软登录页

ASP.NET MVC添加Microsoft登录无法跳转至登录页问题

我正尝试为ASP.NET MVC项目添加Microsoft登录功能,已在Azure中创建应用并严格按照Azure提供的示例代码完成配置,但点击Microsoft登录按钮后,页面无法跳转至微软登录页,始终停留在当前登录页。

Startup.cs代码

public class Startup
{         
    string clientId = System.Configuration.ConfigurationManager.AppSettings["ClientId"];

    string redirectUri = System.Configuration.ConfigurationManager.AppSettings["RedirectUri"];

    static string tenant = System.Configuration.ConfigurationManager.AppSettings["Tenant"];

    string authority = String.Format(System.Globalization.CultureInfo.InvariantCulture, System.Configuration.ConfigurationManager.AppSettings["Authority"], tenant);

    public void Configuration(IAppBuilder app)
    {
       app.CreatePerOwinContext(ApplicationDbContext.Create);
       app.CreatePerOwinContext<ApplicationUserManager>(ApplicationUserManager.Create);
       app.CreatePerOwinContext<ApplicationSignInManager>(ApplicationSignInManager.Create);
      app.SetDefaultSignInAsAuthenticationType(CookieAuthenticationDefaults.AuthenticationType);

      app.UseCookieAuthentication(new CookieAuthenticationOptions { });

         app.UseExternalSignInCookie(DefaultAuthenticationTypes.ExternalCookie);
        
        app.UseOpenIdConnectAuthentication(
            new OpenIdConnectAuthenticationOptions
            {
               // AuthenticationMode = AuthenticationMode.Passive,
                ClientId = clientId,
                Authority = authority,
                RedirectUri = redirectUri,
                PostLogoutRedirectUri = redirectUri,
                Scope = OpenIdConnectScope.OpenIdProfile,
                ResponseType = OpenIdConnectResponseType.CodeIdToken,
                TokenValidationParameters = new TokenValidationParameters()
                {
                    ValidateIssuer = false // This is a simplification
                },
                Notifications = new OpenIdConnectAuthenticationNotifications
                {
                    AuthenticationFailed = OnAuthenticationFailed
                }
            }
        );
    }

    private Task OnAuthenticationFailed(AuthenticationFailedNotification<OpenIdConnectMessage, OpenIdConnectAuthenticationOptions> context)
    {
        context.HandleResponse();
        context.Response.Redirect("/?errormessage=" + context.Exception.Message);
        return Task.FromResult(0);
    }
}

Web.config配置部分

<add key="ClientId" value=" our app client id " />
<add key="Tenant" value="organizations" />
<add key="Authority" 
 value="https://login.microsoftonline.com/{0}/v2.0" />
<add key="redirectUri" value="https://localhost:44300/"/>

排查建议

  • 清理ClientId空格:Web.config中ClientId的值前后存在空格,需删除空格,确保与Azure应用注册页面的ClientId完全一致。
  • 匹配重定向URI:Azure应用注册里配置的重定向URI必须和Web.config中的redirectUri完全匹配,包括HTTPS协议、端口号及结尾的斜杠。
  • 启用Passive认证模式:取消注释AuthenticationMode = AuthenticationMode.Passive,外部登录场景下该模式更适配主动触发的登录请求。
  • 检查API权限:在Azure应用注册中添加User.Read等必要权限,若为组织租户需确认已授予管理员同意。
  • 查看错误详情:访问项目根路径(https://localhost:44300/),通过errormessage参数获取具体异常信息,定位失败原因。
  • 验证Authority地址:调试确认拼接后的Authority为https://login.microsoftonline.com/organizations/v2.0,格式无错误。
  • 确认中间件顺序:确保Cookie认证、外部登录Cookie中间件在OpenIdConnect认证中间件之前,当前代码顺序符合要求,但需排除其他自定义中间件的干扰。

内容的提问来源于stack exchange,提问作者Afi .M

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 17:03:02