You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AzureAD B2C SAML注销请求未签名致ADFS注销失败排查

问题根源与解决方案

你的问题出在Azure AD B2C的Claims Provider元数据配置缺少强制签名注销请求的项:

  • 当前配置里的WantsSignedRequests是声明ADFS期望接收的登录请求必须签名,这也是登录流程正常的原因(B2C会对登录请求签名)。
  • 但ADFS要求注销请求(HTTP Redirect/POST绑定)也必须签名,而你未配置B2C对注销请求执行签名操作,导致请求缺少Signature参数,触发MSIS7084错误。

修复步骤

在你的Claims Provider的<Metadata>节点中添加以下配置项:

<Item Key="SignOutRequestsSigned">true</Item>

修改后的完整Metadata配置如下:

<Metadata>
  <Item Key="IssuerUri">https://ourissuer</Item>
  <Item Key="PartnerEntity">metadata removed for brevity</Item>
  <Item Key="XmlSignatureAlgorithm">Sha256</Item>
  <Item Key="ResponsesSigned">true</Item>
  <Item Key="WantsSignedRequests">true</Item>
  <Item Key="WantsSignedAssertions">true</Item>
  <Item Key="WantsEncryptedAssertions">false</Item>
  <Item Key="IdpInitiatedProfileEnabled">true</Item>
  <Item Key="IncludeClaimResolvingInClaimsHandling">true</Item>
  <Item Key="SingleLogoutEnabled">true</Item>
  <Item Key="SignOutRequestsSigned">true</Item> <!-- 新增项 -->
</Metadata>

额外验证点

  1. 确保Azure AD B2C用于签名的证书有效且未过期
  2. 确认该证书已被导入到ADFS的信任证书列表中,ADFS需要验证注销请求的签名合法性

内容的提问来源于stack exchange,提问作者solidstore

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 07:50:31