Azure AD B2C登录策略:SSO与保持登录状态功能异常求助
Troubleshooting Azure AD B2C SSO and Keep-Me-Signed-In Issues
Hey there, let's break down the key areas to check for your SSO and persistent login problems. It sounds like both cross-app SSO and the keep-me-signed-in feature are failing even with default or custom policies, so let's start with the most common culprits:
1. Verify App Registration & Policy Consistency
- Confirm identical policy usage: Both apps must reference the exact same B2C policy (either the default
B2C_1_signinorsignupor your customB2C_1A_keepmesignedinpolicy). Double-check theAuthorityvalue in each app'sweb.configto ensure it points to the same tenant and policy ID. - Check redirect URIs: Make sure both apps' redirect URIs are registered in the same Azure AD B2C tenant, and that they're marked as valid for the policy you're using. Mismatched or unregistered redirect URIs can break session sharing.
- Front-channel logout setup: Ensure both apps have a valid front-channel logout URI configured in their B2C app registrations. Incorrect logout settings can corrupt session cookies and prevent SSO from working across app restarts.
2. Validate Keep-Me-Signed-In (KMSI) Configuration
For Custom KMSI Policies
- Confirm policy declarations: Check that your custom policy includes the
KeepMeSignedInclaim and references aSessionManagementtechnical profile with theKeepAliveInDaysparameter set (e.g.,<KeepAliveInDays>7</KeepAliveInDays>). Without this, the persistent login cookie won't be issued. - App cookie settings: In your
web.config, verify that:openid.connect.cookie.expireTimeSpanis set to a value matching your policy's KMSI durationopenid.connect.cookie.slidingExpirationis set totrueopenid.connect.promptis not set tologin(this forces a fresh login every time, ignoring SSO)
For Default signinorsignup Policy
- Portal setting check: Head to your Azure AD B2C portal, navigate to the default sign-in/sign-up policy, and confirm the "Keep me signed in" option is enabled with a valid expiration period (e.g., 7 days).
3. Cookie & Domain Configuration Checks
- Shared domain requirement: Azure AD B2C SSO relies on shared cookies. If you're testing locally, ensure both apps run on
localhostwith different ports (e.g.,https://localhost:44310andhttps://localhost:44320)—browsers share cookies for the same base domain. For production, use a shared parent domain (e.g.,app1.yourdomain.comandapp2.yourdomain.com). - Browser privacy settings: Disable "Block third-party cookies" in your browser temporarily. B2C's SSO cookies are stored on the B2C domain, which is treated as third-party if your apps use a different domain. For production, configure a custom B2C domain to make cookies first-party.
- Inspect cookies in dev tools: After logging into App 1, open your browser's dev tools (Application > Cookies) and look for B2C-specific cookies (e.g.,
b2c_<your-tenant-id>). When you open App 2, check if these cookies are present—if not, the browser isn't sharing them, which breaks SSO.
4. Debug with Logs & Authentication Middleware
- Enable App Insights logs: Turn on Azure AD B2C diagnostic logs in App Insights. Look for authentication requests from both apps—check if they share the same
sid(session ID). A differentsidmeans B2C isn't recognizing the session as valid across apps. - Check middleware configuration: Ensure both apps'
AddOpenIdConnectsetup includes theoffline_accessscope (required for refresh tokens, which power KMSI). Also confirmResponseTypeis set tocode id_token(or the appropriate value for your flow). - Avoid forced login prompts: Make sure neither app has
prompt=loginin their authentication requests—this overrides SSO and forces a new login every time. Useprompt=select_accountinstead if you want users to choose an account, or leave it blank for automatic SSO.
5. Double-Check Web.Config Values
Since you only modified tenant and client ID values, confirm these are correct for each app:
ida:Tenantshould be your B2C tenant name (e.g.,yourtenant.onmicrosoft.com)ida:ClientIdshould match each app's unique registration ID in B2Cida:PolicyIdis identical across both apps
内容的提问来源于stack exchange,提问作者C. Brindle
相关产品推荐
相关产品推荐

