You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在MVC应用中借助第三方ADFS元数据URL实现ADFS登录?

Hey there! Let's walk through getting ADFS authentication set up in your MVC app—since you're working with a third-party ADFS service and only have their Metadata URL right now, I'll break down what you need to know step by step.

First: Do you need more info besides the Metadata URL?

The Metadata URL does include most core config details (like ADFS endpoints, certificates, etc.), but there are a few critical pieces you’ll need to confirm with the third-party provider:

  • Relying Party Trust Identifier: Your MVC app must be registered as a relying party on their ADFS server. They’ll need to give you a unique identifier (usually a URL like https://yourapp.com/adfs)—this is non-negotiable; ADFS won’t recognize your app’s authentication requests without it.
  • Redirect URI: The exact URL where ADFS should send users after a successful login (e.g., https://yourapp.com/signin-wsfed). This has to be pre-configured in their ADFS relying party settings, otherwise you’ll get callback failures.
  • Special Claim Requirements: Does their ADFS require specific parameters to be sent with requests, or does it return unique user data fields? This could affect how you handle user information after authentication.
Second: Step-by-step implementation for MVC apps

I’ll cover both .NET Framework and .NET Core MVC, since these are the most common scenarios:

For .NET Framework MVC

  1. Install the official NuGet package: Microsoft.Owin.Security.WsFederation
  2. Configure the WsFederation middleware in Startup.Auth.cs (or Startup.cs):
using Microsoft.Owin.Security;
using Microsoft.Owin.Security.WsFederation;

public void ConfigureAuth(IAppBuilder app)
{
    // Set up cookie authentication to persist user sessions
    app.SetDefaultSignInAsAuthenticationType(CookieAuthenticationDefaults.AuthenticationType);
    app.UseCookieAuthentication(new CookieAuthenticationOptions());

    // Configure ADFS authentication
    app.UseWsFederationAuthentication(new WsFederationAuthenticationOptions
    {
        MetadataAddress = "Third-party provided Metadata URL",
        Wtrealm = "Relying Party Identifier from the provider",
        CallbackPath = new PathString("/signin-wsfed") // Must match the redirect URI they configured
    });
}
  1. Add login/logout actions to your controller:
public ActionResult Login()
{
    if (!Request.IsAuthenticated)
    {
        // Trigger ADFS authentication challenge
        HttpContext.GetOwinContext().Authentication.Challenge(
            new AuthenticationProperties { RedirectUri = "/" },
            WsFederationAuthenticationDefaults.AuthenticationType);
        return new HttpUnauthorizedResult();
    }
    return RedirectToAction("Index", "Home");
}

public ActionResult Logout()
{
    // Sign out of both the app cookie and ADFS
    HttpContext.GetOwinContext().Authentication.SignOut(
        CookieAuthenticationDefaults.AuthenticationType,
        WsFederationAuthenticationDefaults.AuthenticationType);
    return RedirectToAction("Index", "Home");
}
  1. Add login/logout buttons in your views to call these actions.

For .NET Core MVC

  1. Install the NuGet package: Microsoft.AspNetCore.Authentication.WsFederation
  2. Configure authentication in Program.cs:
var builder = WebApplication.CreateBuilder(args);

// Add MVC services
builder.Services.AddControllersWithViews();

// Configure ADFS authentication
builder.Services.AddAuthentication(WsFederationDefaults.AuthenticationScheme)
    .AddWsFederation(options =>
    {
        options.MetadataAddress = "Third-party provided Metadata URL";
        options.Wtrealm = "Relying Party Identifier from the provider";
        options.CallbackPath = "/signin-wsfed"; // Match the provider's configured redirect URI
    });

// Set default authorization policy to require authenticated users
builder.Services.AddAuthorization(options =>
{
    options.FallbackPolicy = new AuthorizationPolicyBuilder()
        .RequireAuthenticatedUser()
        .Build();
});

var app = builder.Build();

// Middleware pipeline setup
app.UseHttpsRedirection();
app.UseStaticFiles();
app.UseRouting();
app.UseAuthentication();
app.UseAuthorization();

app.MapControllerRoute(
    name: "default",
    pattern: "{controller=Home}/{action=Index}/{id?}");

app.Run();
  1. Add login/logout actions to your controller:
public async Task<IActionResult> Login()
{
    if (!User.Identity.IsAuthenticated)
    {
        await HttpContext.ChallengeAsync(WsFederationDefaults.AuthenticationScheme,
            new AuthenticationProperties { RedirectUri = "/" });
        return Unauthorized();
    }
    return RedirectToAction("Index");
}

public async Task<IActionResult> Logout()
{
    // Sign out of ADFS and the app's cookie
    await HttpContext.SignOutAsync(WsFederationDefaults.AuthenticationScheme);
    await HttpContext.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme);
    return RedirectToAction("Index");
}
Third: Common troubleshooting tips
  • "Relying party not found" error: Double-check that your Wtrealm value matches exactly what the third-party provided, and confirm they’ve registered your app as a relying party on their ADFS server.
  • Callback failures: Ensure your CallbackPath matches the redirect URI they configured (including HTTPS and case sensitivity). ADFS almost always requires HTTPS for callback URLs, so make sure your app is running over HTTPS.
  • Metadata loading issues: Verify you can access the Metadata URL directly from your app’s server—firewalls or proxies might be blocking the connection.
Reliable implementation guidance

Microsoft’s official docs are the most trustworthy resource for this. For .NET Framework, look for guides on WsFederation authentication with OWIN; they cover setting up the relying party trust on ADFS and configuring your MVC app. For .NET Core, check the ASP.NET Core WsFederation authentication docs—they include full examples, configuration details, and troubleshooting for common issues.

内容的提问来源于stack exchange,提问作者Diego Arias

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:12:55