如何获取Azure AD认证域名及配置本地Web API的Azure认证
Hey there! Let me break this down clearly for you since you’re familiar with local SQL auth for your Web API but new to Azure’s identity system.
The domain you’re looking to enter is tied to your Azure Active Directory (Azure AD) tenant. It’s either the default domain Azure assigns you (like yourtenantname.onmicrosoft.com) or a custom domain you’ve added and verified (e.g., your company’s own domain like yourbusiness.com). This domain tells your Web API which Azure AD tenant to use for validating user tokens.
- Head to the Azure portal, search for "Azure Active Directory" in the top search bar.
- Click "Create tenant" and choose "Azure AD tenant" from the options. Follow the setup wizard: pick a tenant name, choose an initial domain (this will be your
onmicrosoft.comdomain), and confirm the details. - Once created, you’ll have a dedicated tenant for managing your users and authentication.
- Log into the Azure portal and navigate to your Azure AD tenant.
- Go to the Overview tab in the left menu. Look for the "Basic information" section—here you’ll see the "Domain name" field. The value here (either the default
onmicrosoft.comdomain or your verified custom domain) is exactly what you need to put in that input box. - Alternatively, if you prefer using the Azure CLI, run this command:
It’ll directly output your tenant’s default domain.az ad tenant list --query "[].defaultDomainName" -o tsv
Since you’re hosting the API locally but using Azure for auth, here’s what you’ll need to do next:
- Register an application in your Azure AD tenant to represent your Web API:
- In Azure AD, go to "App registrations" → "New registration".
- Name it something descriptive (like "Local Web API"), set the account type to "Accounts in this organizational directory only" (since you’re dealing with internal users), and leave the redirect URI blank (this is for client apps, not APIs).
- After registration, grab the Application (client) ID and Directory (tenant) ID from the app’s Overview page—you’ll need these in your API’s configuration.
- Add API permissions: Go to "API permissions" in your registered app, add a permission for
Microsoft Graph(start withUser.Readas a basic one), then click "Grant admin consent for [your tenant name]" to activate it. - In your Web API code, configure the authentication middleware to use Azure AD’s JWT bearer authentication. The critical setting here is the
Authorityparameter, which will behttps://login.microsoftonline.com/your-tenant-domain(replaceyour-tenant-domainwith the domain you found earlier). This tells the API to trust tokens issued by your Azure AD tenant.
The domain input box is essentially asking for the authoritative identifier of your Azure AD tenant. Azure uses this to route authentication requests to the right tenant and validate that incoming tokens are legitimate for your application. Either the default
onmicrosoft.comdomain or a verified custom domain will work here—just pick whichever makes sense for your use case.
内容的提问来源于stack exchange,提问作者Rhendar

