ASP.NET Core 6结合独立账户与Microsoft.Identity.Web认证遇加载错误
解决ASP.NET Core 6 + Microsoft.Identity.Web + Identity 外部登录错误:Error loading external login information
核心问题原因
错误源于ASP.NET Core Identity与Microsoft.Identity.Web的认证配置冲突:
AddDefaultIdentity会默认将Cookie认证设为默认方案,用于管理本地用户会话;AddMicrosoftIdentityWebAppAuthentication会强制将OpenID Connect(OIDC)设为默认认证方案,覆盖了Identity的Cookie配置,导致外部登录回调时无法正确映射到Identity的用户流程。
同时,当前配置未正确将Azure AD注册为Identity的外部登录提供者,缺少必要的用户信息映射和回调处理逻辑。
修复步骤
1. 修改Program.cs的服务配置
替换现有认证相关代码,确保Identity的Cookie认证为默认,同时将Azure AD作为外部登录提供者添加:
using AuthTest.Data; using Microsoft.AspNetCore.Identity; using Microsoft.EntityFrameworkCore; using Microsoft.AspNetCore.Authentication.OpenIdConnect; using Microsoft.Identity.Web; var builder = WebApplication.CreateBuilder(args); var connectionString = builder.Configuration.GetConnectionString("DefaultConnection"); builder.Services.AddDbContext<ApplicationDbContext>(options => options.UseSqlServer(connectionString)); builder.Services.AddDatabaseDeveloperPageExceptionFilter(); // 配置Identity并启用默认UI(包含外部登录页面) builder.Services.AddDefaultIdentity<IdentityUser>(options => options.SignIn.RequireConfirmedAccount = true) .AddEntityFrameworkStores<ApplicationDbContext>() .AddDefaultUI(); // 新增:启用Identity默认UI,包含外部登录入口 // 配置认证:保留Cookie为默认方案,添加Azure AD作为外部OIDC提供者 builder.Services.AddAuthentication() .AddMicrosoftIdentityWebApp(builder.Configuration, OpenIdConnectDefaults.AuthenticationScheme); // 自定义OIDC参数(可选,设置名称声明) builder.Services.Configure<OpenIdConnectOptions>(OpenIdConnectDefaults.AuthenticationScheme, options => { options.TokenValidationParameters.NameClaimType = "name"; }); builder.Services.AddControllersWithViews(); var app = builder.Build(); if (app.Environment.IsDevelopment()) { app.UseMigrationsEndPoint(); } else { app.UseExceptionHandler("/Home/Error"); app.UseHsts(); } app.UseHttpsRedirection(); app.UseStaticFiles(); app.UseRouting(); app.UseAuthentication(); app.UseAuthorization(); app.MapControllerRoute( name: "default", pattern: "{controller=Home}/{action=Index}/{id?}"); app.MapRazorPages(); // 必须保留,Identity默认UI依赖Razor Pages app.Run();
2. 验证appsettings.json配置
确保AzureAd节点参数准确:
TenantId:你的Azure AD租户ID(GUID或租户域名均可)ClientId:Azure AD应用注册的客户端IDClientSecret:应用注册生成的客户端密钥(确认未过期)CallbackPath:必须与Azure AD应用注册中配置的重定向URI完全一致(本地开发格式为https://localhost:<项目端口>/signin-oidc)
3. 数据库迁移与初始化
打开Package Manager Console,执行以下命令完成Identity数据库初始化:
Add-Migration InitialCreate Update-Database
4. Azure AD应用注册配置检查
- 在Azure门户的应用注册中,添加重定向URI:
https://localhost:<你的项目端口>/signin-oidc(本地开发时需对应项目实际端口) - 确认应用注册已启用授权码流(在「认证」→「高级设置」中检查)
- 为应用注册添加
User.Read委托权限,并完成管理员同意
关键注意事项
- 不要同时使用
AddMicrosoftIdentityWebAppAuthentication和AddDefaultIdentity:前者适用于无需本地用户存储的纯AAD认证场景,后者适用于本地用户+外部登录的混合场景。 AddDefaultUI()必须添加:否则Identity不会生成外部登录相关的页面(如登录页的外部登录按钮)。- 回调URI必须严格匹配:否则Azure AD会拒绝回调请求,直接导致登录失败。
内容的提问来源于stack exchange,提问作者user7148560
相关产品推荐
相关产品推荐

