You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

运行Azure AD B2C WebApp示例时遇Microsoft.IdentityModel及重定向URI错误

问题与解决方案

错误1:IDX40002: Microsoft.IdentityModel does not support a B2C issuer with 'tfp' in the URI

该错误源于未适配Azure AD B2C的tfp格式issuer,使用了旧版身份验证库的配置方式。解决步骤:

  • 确保项目引用Microsoft.Identity.Web NuGet包(不能仅依赖Microsoft.IdentityModel)。
  • 在appsettings.json中按标准Azure AD B2C格式配置参数:
    "AzureAdB2C": {
      "Instance": "https://{你的租户名称}.b2clogin.com/",
      "Domain": "{你的租户域名}.onmicrosoft.com",
      "ClientId": "{你的应用Client ID}",
      "SignedOutCallbackPath": "/signout/B2C_1_{你的用户流ID}",
      "SignUpSignInPolicyId": "B2C_1_{你的用户流ID}"
    }
    
  • 在Program.cs(或Startup.cs)中使用Microsoft.IdentityWeb的扩展方法配置认证,自动处理issuer格式问题:
    builder.Services.AddAuthentication(OpenIdConnectDefaults.AuthenticationScheme)
        .AddMicrosoftIdentityWebApp(builder.Configuration.GetSection("AzureAdB2C"));
    

错误2:AADSTS50011: 重定向URI不匹配

你请求中的重定向URIhttps://myHost.b2clogin.com/1c2009bb-7e35-4a0e-9f22-xxxxxxxxx/oauth2/authresp与应用注册里配置的https://localhost:44316/signin-oidc不匹配,是手动修改Instance导致的配置异常。解决步骤:

  • 恢复appsettings.json中的Instance为标准格式(需包含租户路径,如https://你的租户名称.b2clogin.com/),不能仅设置为https://myHost.b2clogin.com。
  • 不要手动指定错误的RedirectUri,让Microsoft.IdentityWeb自动使用WebApp默认的/signin-oidc回调路径。
  • 确认项目运行的端口与应用注册中配置的重定向URI端口一致(截图中为44316)。

内容的提问来源于stack exchange,提问作者Emaborsa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 20:05:23