You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为仅支持Basic Authentication的应用配置Azure SSO/MFA前置认证?

Hey there, let's walk through how to set up Azure SSO/MFA for your scenario and explore better alternatives that fit industry best practices.

Option 1: Build Your Custom Pre-Authentication App (Your Original Plan)

If you want to go ahead with developing a custom front-end auth app, here's a step-by-step breakdown to integrate Azure SSO/MFA:

Core Workflow & Configuration

  • Register your pre-auth app in Azure AD: Create a new "Web app/API" registration. Enable the OAuth 2.0 Authorization Code Flow—this is ideal for user-facing auth flows with redirects.
  • Enforce MFA via Conditional Access: Create a Conditional Access policy targeting your pre-auth app, and set the grant control to "Require multi-factor authentication". This ensures every user must complete MFA before proceeding.
  • Handle Azure AD Auth in Your App: When a user lands on your pre-auth app, redirect them to Azure AD's authorization endpoint. Once they complete SSO/MFA, Azure AD will send an authorization code back to your app's configured redirect URI.
  • Generate Basic Auth Credentials Securely: Use the authorization code to fetch an access token, then call Microsoft Graph API to retrieve the user's necessary attributes (like UPN). Never expose plaintext credentials—on your backend, encode the username and corresponding password (store this securely in Azure Key Vault, not hardcoded) into a Basic auth header.
  • Auto-Forward to Target App: Redirect the user to the target app's login page, and either auto-submit the Basic auth credentials via a server-side POST request (avoid URL parameters—they're insecure) or pre-fill the login form fields (if it's a web UI).

Critical Security Notes

  • Never store or transmit Basic auth credentials in client-side code (JavaScript, cookies, etc.). All credential handling must happen on your backend.
  • Use Azure AD refresh tokens to maintain user sessions and avoid frequent re-authentication.

Instead of building custom code, Azure AD Application Proxy is a native, enterprise-grade solution designed exactly for this scenario—adding SSO/MFA to legacy apps that only support Basic Auth:

  • Publish the target app via Application Proxy: In the Azure Portal, add a new Application Proxy application. Point it to your target app's internal URL.
  • Pre-Authentication Setup: Set pre-authentication to "Azure Active Directory"—this forces users to authenticate with Azure AD (including MFA, if enforced via Conditional Access) before reaching the target app.
  • Credential Mapping: Configure "Password Single Sign-On" for the app. You can map Azure AD user attributes (like UPN) to the target app's username, and store the corresponding password in Azure AD (or use Azure Key Vault for better security). Application Proxy will automatically inject the Basic auth header when forwarding requests to the target app.
  • Bonus Benefits: You get built-in session management, conditional access controls, and no need to maintain custom code. This is the go-to approach for most enterprise teams dealing with legacy auth apps.
Option 3: Azure API Management (For API-Based Apps)

If the target software is an API service (not a web UI), Azure API Management (APIM) works perfectly as an auth gateway:

  • Add APIM as a Frontend: Configure APIM to route traffic to your target Basic Auth API.
  • Enforce Azure AD Auth: Add an authentication policy to APIM that requires users to present a valid Azure AD access token (obtained via SSO/MFA).
  • Inject Basic Auth Header: Add a "Set HTTP header" policy to APIM that converts the authenticated user's info (from the Azure AD token) into a valid Basic auth header, which is then forwarded to the backend API.
  • Extra Perks: APIM also gives you traffic throttling, logging, monitoring, and API versioning capabilities—great for managing API access at scale.
Long-Term Optimal Solution: Modernize the Target App

If possible, push for updating the target software to support modern authentication:

  • Reach out to the vendor to ask about Azure AD SSO integration (most enterprise tools now support SAML 2.0 or OAuth 2.0).
  • If it's a custom-built app, integrate the Microsoft Identity Web SDK to replace Basic Auth with Azure AD SSO/MFA directly. This eliminates the need for middle layers entirely and aligns with your company's AD authentication requirements long-term.

内容的提问来源于stack exchange,提问作者Nintox

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 11:47:43