You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C应用创建用户令牌获取失败(已解决):parsing_wstrust_response_failed

Azure AD B2C 创建用户:IntegratedWindowsAuth令牌获取失败的解决方法

我在Linqpad 6中基于官方文档编写脚本尝试创建Azure AD B2C用户时,遇到令牌获取失败问题:抛出内部异常“系统无法联系域控制器以处理身份验证请求”,错误标识为parsing_wstrust_response_failed。最初使用IntegratedWindowsAuth认证方式,不仅触发上述错误,还因MFA验证受阻,最终改用应用注册的ClientSecretCredential方式完成了用户创建。

初始失败代码

void Main()
{
    Debug.WriteLine("yo");
    UserCreator creator = new();
    creator.CreateUser();
}

public class UserCreator
{
    public async void CreateUser()
    {
            var scopes = new[] { "User.ReadWriteAll" };
            // Multi-tenant apps can use "common",
            // single-tenant apps must use the tenant ID from the Azure portal
            var tenantId = "<MY_TENANT_ID>";

            // Value from app registration
            var clientId = "<MY_APPLICATION_ID>";

            var pca = PublicClientApplicationBuilder
                .Create(clientId)
                .WithTenantId(tenantId)
                .Build();

            // DelegateAuthenticationProvider is a simple auth provider implementation
            // that allows you to define an async function to retrieve a token
            // Alternatively, you can create a class that implements IAuthenticationProvider
            // for more complex scenarios
            var authProvider = new DelegateAuthenticationProvider(async (request) =>
            {
            // Use Microsoft.Identity.Client to retrieve token
            var result = await pca.AcquireTokenByIntegratedWindowsAuth(scopes).ExecuteAsync();

                request.Headers.Authorization =
                    new System.Net.Http.Headers.AuthenticationHeaderValue("Bearer", result.AccessToken);
            });

            GraphServiceClient graphClient = new GraphServiceClient(authProvider);
            var user = new User
            {
                AccountEnabled = true,
                DisplayName = "John",
                MailNickname = "John",
                UserPrincipalName = "john@mail.com",
                PasswordProfile = new PasswordProfile
                {
                    ForceChangePasswordNextSignIn = true,
                    Password = "xWwvJ]6NMw+bWH-d"
                }
            };

            await graphClient.Users
                .Request()
                .AddAsync(user);
    }
}

最终解决代码

改用**ClientSecretCredential(客户端凭据)**方式,通过应用权限完成认证,无需用户交互,避开了MFA和域控制器相关问题:

void Main()
{
    UserCreator creator = new();
    creator.CreateUser();
}

public class UserCreator
{
    public async void CreateUser()
    {
        var clientId = "<CLIENT_ID>";
        var scopes = new[] { "https://graph.microsoft.com/.default" };

        var tenantId = "<TENANT_ID>";

        var clientSecret = "<CLIENT_SECRET>";
        
        // using Azure.Identity;
        var options = new TokenCredentialOptions
        {
            AuthorityHost = AzureAuthorityHosts.AzurePublicCloud
        };

        var clientSecretCredential = new ClientSecretCredential(
            tenantId, clientId, clientSecret, options);

        var graphClient = new GraphServiceClient(clientSecretCredential, scopes);

        var user = new{
            Email = "test@mail.dk",
            DisplayName = "TestUser", 
            Username = "Someusername",
        };

        var invitation = new Invitation
        {
            InvitedUserEmailAddress = user.Email,
            InvitedUser = new User
            {
                AccountEnabled = true,
                DisplayName = "TestUser",
                CreationType = "LocalAccount",
                PasswordPolicies = "DisableStrongPassword",
                PasswordProfile = new PasswordProfile
                    {
                        ForceChangePasswordNextSignIn = true,
                        Password = "Test123456",
                    }
                    
            },
            InvitedUserType = "member",
            SendInvitationMessage = true,
            InviteRedirectUrl = "someurl.com"
        };

        await graphClient.Invitations
            .Request()
            .AddAsync(invitation);
            Console.Write("completed");
    }
}

内容的提问来源于stack exchange,提问作者eengstroem

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 05:25:53