You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C登录策略:SSO与保持登录状态功能异常求助

Troubleshooting Azure AD B2C SSO and Keep-Me-Signed-In Issues

Hey there, let's break down the key areas to check for your SSO and persistent login problems. It sounds like both cross-app SSO and the keep-me-signed-in feature are failing even with default or custom policies, so let's start with the most common culprits:

1. Verify App Registration & Policy Consistency

  • Confirm identical policy usage: Both apps must reference the exact same B2C policy (either the default B2C_1_signinorsignup or your custom B2C_1A_keepmesignedin policy). Double-check the Authority value in each app's web.config to ensure it points to the same tenant and policy ID.
  • Check redirect URIs: Make sure both apps' redirect URIs are registered in the same Azure AD B2C tenant, and that they're marked as valid for the policy you're using. Mismatched or unregistered redirect URIs can break session sharing.
  • Front-channel logout setup: Ensure both apps have a valid front-channel logout URI configured in their B2C app registrations. Incorrect logout settings can corrupt session cookies and prevent SSO from working across app restarts.

2. Validate Keep-Me-Signed-In (KMSI) Configuration

For Custom KMSI Policies

  • Confirm policy declarations: Check that your custom policy includes the KeepMeSignedIn claim and references a SessionManagement technical profile with the KeepAliveInDays parameter set (e.g., <KeepAliveInDays>7</KeepAliveInDays>). Without this, the persistent login cookie won't be issued.
  • App cookie settings: In your web.config, verify that:
    • openid.connect.cookie.expireTimeSpan is set to a value matching your policy's KMSI duration
    • openid.connect.cookie.slidingExpiration is set to true
    • openid.connect.prompt is not set to login (this forces a fresh login every time, ignoring SSO)

For Default signinorsignup Policy

  • Portal setting check: Head to your Azure AD B2C portal, navigate to the default sign-in/sign-up policy, and confirm the "Keep me signed in" option is enabled with a valid expiration period (e.g., 7 days).
  • Shared domain requirement: Azure AD B2C SSO relies on shared cookies. If you're testing locally, ensure both apps run on localhost with different ports (e.g., https://localhost:44310 and https://localhost:44320)—browsers share cookies for the same base domain. For production, use a shared parent domain (e.g., app1.yourdomain.com and app2.yourdomain.com).
  • Browser privacy settings: Disable "Block third-party cookies" in your browser temporarily. B2C's SSO cookies are stored on the B2C domain, which is treated as third-party if your apps use a different domain. For production, configure a custom B2C domain to make cookies first-party.
  • Inspect cookies in dev tools: After logging into App 1, open your browser's dev tools (Application > Cookies) and look for B2C-specific cookies (e.g., b2c_<your-tenant-id>). When you open App 2, check if these cookies are present—if not, the browser isn't sharing them, which breaks SSO.

4. Debug with Logs & Authentication Middleware

  • Enable App Insights logs: Turn on Azure AD B2C diagnostic logs in App Insights. Look for authentication requests from both apps—check if they share the same sid (session ID). A different sid means B2C isn't recognizing the session as valid across apps.
  • Check middleware configuration: Ensure both apps' AddOpenIdConnect setup includes the offline_access scope (required for refresh tokens, which power KMSI). Also confirm ResponseType is set to code id_token (or the appropriate value for your flow).
  • Avoid forced login prompts: Make sure neither app has prompt=login in their authentication requests—this overrides SSO and forces a new login every time. Use prompt=select_account instead if you want users to choose an account, or leave it blank for automatic SSO.

5. Double-Check Web.Config Values

Since you only modified tenant and client ID values, confirm these are correct for each app:

  • ida:Tenant should be your B2C tenant name (e.g., yourtenant.onmicrosoft.com)
  • ida:ClientId should match each app's unique registration ID in B2C
  • ida:PolicyId is identical across both apps

内容的提问来源于stack exchange,提问作者C. Brindle

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:20:45