如何配置ASP.NET MVC Core 6应用支持两个Azure AD租户认证
配置ASP.NET MVC Core 6支持两个Azure AD租户登录
步骤1:在两个Azure AD租户中分别注册应用
在每个目标Azure AD租户的Azure门户完成应用注册,记录每个应用的ClientId、TenantId、ClientSecret,并为每个应用配置独立的回调路径(如/signin-oidc-tenant1和/signin-oidc-tenant2),确保后续配置与该路径一致。
步骤2:配置appsettings.json
将两个租户的认证参数写入配置文件:
"AzureADTenant1": { "Instance": "https://login.microsoftonline.com/", "TenantId": "租户1的ID", "ClientId": "租户1应用的ClientId", "ClientSecret": "租户1应用的ClientSecret", "CallbackPath": "/signin-oidc-tenant1" }, "AzureADTenant2": { "Instance": "https://login.microsoftonline.com/", "TenantId": "租户2的ID", "ClientId": "租户2应用的ClientId", "ClientSecret": "租户2应用的ClientSecret", "CallbackPath": "/signin-oidc-tenant2" }
步骤3:在Program.cs中配置双租户认证方案
添加Cookie认证用于统一保存登录状态,同时为每个Azure AD租户配置独立的OpenID Connect(OIDC)认证方案:
using Microsoft.AspNetCore.Authentication.Cookies; using Microsoft.AspNetCore.Authentication.OpenIdConnect; var builder = WebApplication.CreateBuilder(args); builder.Services.AddControllersWithViews(); // 配置认证服务 builder.Services.AddAuthentication() .AddCookie() // 用Cookie统一存储登录会话 .AddOpenIdConnect("AzureAD-Tenant1", options => { builder.Configuration.Bind("AzureADTenant1", options); options.SignInScheme = CookieAuthenticationDefaults.AuthenticationScheme; // 按需添加需要获取的用户信息范围 options.Scope.Add("email"); options.Scope.Add("profile"); }) .AddOpenIdConnect("AzureAD-Tenant2", options => { builder.Configuration.Bind("AzureADTenant2", options); options.SignInScheme = CookieAuthenticationDefaults.AuthenticationScheme; options.Scope.Add("email"); options.Scope.Add("profile"); }); // 可选:配置授权策略,区分不同租户用户 builder.Services.AddAuthorization(options => { options.AddPolicy("Tenant1Only", policy => policy.RequireClaim("http://schemas.microsoft.com/identity/claims/tenantid", "租户1的ID")); options.AddPolicy("Tenant2Only", policy => policy.RequireClaim("http://schemas.microsoft.com/identity/claims/tenantid", "租户2的ID")); }); var app = builder.Build(); if (!app.Environment.IsDevelopment()) { app.UseExceptionHandler("/Home/Error"); app.UseHsts(); } app.UseHttpsRedirection(); app.UseStaticFiles(); app.UseRouting(); // 注意中间件顺序:认证、授权需在路由之后,端点之前 app.UseAuthentication(); app.UseAuthorization(); app.MapControllerRoute( name: "default", pattern: "{controller=Home}/{action=Index}/{id?}"); app.Run();
步骤4:添加登录入口和前端按钮
创建AccountController提供登录/退出动作,指定对应认证方案:
using Microsoft.AspNetCore.Authentication; using Microsoft.AspNetCore.Mvc; public class AccountController : Controller { public IActionResult Login(string scheme) { var redirectUrl = Url.Action("Index", "Home"); return Challenge(new AuthenticationProperties { RedirectUri = redirectUrl }, scheme); } public IActionResult Logout() { return SignOut(new AuthenticationProperties { RedirectUri = Url.Action("Index", "Home") }, CookieAuthenticationDefaults.AuthenticationScheme, "AzureAD-Tenant1", "AzureAD-Tenant2"); } }
在视图中添加对应租户的登录按钮:
<!-- 示例:在_Layout.cshtml或登录页中添加 --> <a asp-controller="Account" asp-action="Login" asp-route-scheme="AzureAD-Tenant1">登录租户1</a> <a asp-controller="Account" asp-action="Login" asp-route-scheme="AzureAD-Tenant2">登录租户2</a> <a asp-controller="Account" asp-action="Logout">退出登录</a>
可选:租户权限控制
若需限制页面访问范围,可在Controller或Action上添加授权策略特性:
[Authorize(Policy = "Tenant1Only")] public IActionResult Tenant1ExclusivePage() { return View(); }
内容的提问来源于stack exchange,提问作者Gregory
相关产品推荐
相关产品推荐

