Azure AD应用认证失败:无法访问login.microsoftonline.com/{tenantId}求解决方案
Fixing Azure AD Authentication Issues for Your App
Hey Bob, it looks like you're missing a couple of critical steps beyond just creating an Azure AD instance and grabbing the tenant ID. Let's walk through what needs to be done to get your authentication working smoothly:
1. First: Register Your App in Azure AD
You can't use Azure AD auth without registering your application in your AD tenant. Here's what you need to do in the Azure Portal:
- Go to Azure Active Directory > App registrations > click New registration
- Fill in your app name, select the supported account types (usually "Accounts in this organizational directory only" for internal apps), and add a Redirect URI (this needs to exactly match the callback URL your app uses, e.g.,
https://localhost:44321/signin-oidcfor local testing) - After registration, head to the app's Overview page and copy the Application (client) ID — this is the
ClientIdyou'll need in your code
2. Configure OWIN Middleware in Your Application
Just having the tenant ID isn't enough; you need to set up OWIN to handle the OpenID Connect flow with Azure AD. Here's a complete example of the OWIN startup class:
using Microsoft.Owin; using Microsoft.Owin.Security.Cookies; using Microsoft.Owin.Security.OpenIdConnect; using Owin; [assembly: OwinStartup(typeof(YourAppNamespace.Startup))] namespace YourAppNamespace { public class Startup { public void Configuration(IAppBuilder app) { // Set default sign-in authentication type to cookies app.SetDefaultSignInAsAuthenticationType(CookieAuthenticationDefaults.AuthenticationType); // Enable cookie authentication to store user session locally app.UseCookieAuthentication(new CookieAuthenticationOptions()); // Configure OpenID Connect to use Azure AD app.UseOpenIdConnectAuthentication( new OpenIdConnectAuthenticationOptions { ClientId = "{Your Application (Client) ID}", // From your app registration in Azure AD Authority = "https://login.microsoftonline.com/{Your Tenant ID}", // Your directory ID from Azure AD properties RedirectUri = "https://localhost:44321/signin-oidc", // Must match the one in your app registration ResponseType = "id_token", // For basic authentication flow Scope = "openid profile User.Read" // Required scopes for user info access }); } } }
3. Common Mistakes to Troubleshoot
- Wrong ClientId: Don't mix up the Azure AD directory ID with the app's client ID — they're two distinct values! The client ID comes from your app registration, not the AD tenant properties.
- Mismatched Redirect URI: If the URI in your code doesn't exactly match what's set in the Azure Portal, Azure AD will reject the authentication request.
- Missing Permissions: Make sure you've added at least basic permissions like
User.Readto your app registration, and if it's a tenant-wide app, get admin consent for those permissions. - OWIN Startup Class Not Enabled: Ensure your startup class is properly decorated with the
[assembly: OwinStartup]attribute so it loads when your app starts.
内容的提问来源于stack exchange,提问作者Bob
相关产品推荐
相关产品推荐

