You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD应用认证失败:无法访问login.microsoftonline.com/{tenantId}求解决方案

Fixing Azure AD Authentication Issues for Your App

Hey Bob, it looks like you're missing a couple of critical steps beyond just creating an Azure AD instance and grabbing the tenant ID. Let's walk through what needs to be done to get your authentication working smoothly:

1. First: Register Your App in Azure AD

You can't use Azure AD auth without registering your application in your AD tenant. Here's what you need to do in the Azure Portal:

  • Go to Azure Active Directory > App registrations > click New registration
  • Fill in your app name, select the supported account types (usually "Accounts in this organizational directory only" for internal apps), and add a Redirect URI (this needs to exactly match the callback URL your app uses, e.g., https://localhost:44321/signin-oidc for local testing)
  • After registration, head to the app's Overview page and copy the Application (client) ID — this is the ClientId you'll need in your code

2. Configure OWIN Middleware in Your Application

Just having the tenant ID isn't enough; you need to set up OWIN to handle the OpenID Connect flow with Azure AD. Here's a complete example of the OWIN startup class:

using Microsoft.Owin;
using Microsoft.Owin.Security.Cookies;
using Microsoft.Owin.Security.OpenIdConnect;
using Owin;

[assembly: OwinStartup(typeof(YourAppNamespace.Startup))]
namespace YourAppNamespace
{
    public class Startup
    {
        public void Configuration(IAppBuilder app)
        {
            // Set default sign-in authentication type to cookies
            app.SetDefaultSignInAsAuthenticationType(CookieAuthenticationDefaults.AuthenticationType);
            
            // Enable cookie authentication to store user session locally
            app.UseCookieAuthentication(new CookieAuthenticationOptions());
            
            // Configure OpenID Connect to use Azure AD
            app.UseOpenIdConnectAuthentication(
                new OpenIdConnectAuthenticationOptions
                {
                    ClientId = "{Your Application (Client) ID}", // From your app registration in Azure AD
                    Authority = "https://login.microsoftonline.com/{Your Tenant ID}", // Your directory ID from Azure AD properties
                    RedirectUri = "https://localhost:44321/signin-oidc", // Must match the one in your app registration
                    ResponseType = "id_token", // For basic authentication flow
                    Scope = "openid profile User.Read" // Required scopes for user info access
                });
        }
    }
}

3. Common Mistakes to Troubleshoot

  • Wrong ClientId: Don't mix up the Azure AD directory ID with the app's client ID — they're two distinct values! The client ID comes from your app registration, not the AD tenant properties.
  • Mismatched Redirect URI: If the URI in your code doesn't exactly match what's set in the Azure Portal, Azure AD will reject the authentication request.
  • Missing Permissions: Make sure you've added at least basic permissions like User.Read to your app registration, and if it's a tenant-wide app, get admin consent for those permissions.
  • OWIN Startup Class Not Enabled: Ensure your startup class is properly decorated with the [assembly: OwinStartup] attribute so it loads when your app starts.

内容的提问来源于stack exchange,提问作者Bob

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:01:42