如何在MVC应用中借助第三方ADFS元数据URL实现ADFS登录?
Hey there! Let's walk through getting ADFS authentication set up in your MVC app—since you're working with a third-party ADFS service and only have their Metadata URL right now, I'll break down what you need to know step by step.
The Metadata URL does include most core config details (like ADFS endpoints, certificates, etc.), but there are a few critical pieces you’ll need to confirm with the third-party provider:
- Relying Party Trust Identifier: Your MVC app must be registered as a relying party on their ADFS server. They’ll need to give you a unique identifier (usually a URL like
https://yourapp.com/adfs)—this is non-negotiable; ADFS won’t recognize your app’s authentication requests without it. - Redirect URI: The exact URL where ADFS should send users after a successful login (e.g.,
https://yourapp.com/signin-wsfed). This has to be pre-configured in their ADFS relying party settings, otherwise you’ll get callback failures. - Special Claim Requirements: Does their ADFS require specific parameters to be sent with requests, or does it return unique user data fields? This could affect how you handle user information after authentication.
I’ll cover both .NET Framework and .NET Core MVC, since these are the most common scenarios:
For .NET Framework MVC
- Install the official NuGet package:
Microsoft.Owin.Security.WsFederation - Configure the WsFederation middleware in
Startup.Auth.cs(orStartup.cs):
using Microsoft.Owin.Security; using Microsoft.Owin.Security.WsFederation; public void ConfigureAuth(IAppBuilder app) { // Set up cookie authentication to persist user sessions app.SetDefaultSignInAsAuthenticationType(CookieAuthenticationDefaults.AuthenticationType); app.UseCookieAuthentication(new CookieAuthenticationOptions()); // Configure ADFS authentication app.UseWsFederationAuthentication(new WsFederationAuthenticationOptions { MetadataAddress = "Third-party provided Metadata URL", Wtrealm = "Relying Party Identifier from the provider", CallbackPath = new PathString("/signin-wsfed") // Must match the redirect URI they configured }); }
- Add login/logout actions to your controller:
public ActionResult Login() { if (!Request.IsAuthenticated) { // Trigger ADFS authentication challenge HttpContext.GetOwinContext().Authentication.Challenge( new AuthenticationProperties { RedirectUri = "/" }, WsFederationAuthenticationDefaults.AuthenticationType); return new HttpUnauthorizedResult(); } return RedirectToAction("Index", "Home"); } public ActionResult Logout() { // Sign out of both the app cookie and ADFS HttpContext.GetOwinContext().Authentication.SignOut( CookieAuthenticationDefaults.AuthenticationType, WsFederationAuthenticationDefaults.AuthenticationType); return RedirectToAction("Index", "Home"); }
- Add login/logout buttons in your views to call these actions.
For .NET Core MVC
- Install the NuGet package:
Microsoft.AspNetCore.Authentication.WsFederation - Configure authentication in
Program.cs:
var builder = WebApplication.CreateBuilder(args); // Add MVC services builder.Services.AddControllersWithViews(); // Configure ADFS authentication builder.Services.AddAuthentication(WsFederationDefaults.AuthenticationScheme) .AddWsFederation(options => { options.MetadataAddress = "Third-party provided Metadata URL"; options.Wtrealm = "Relying Party Identifier from the provider"; options.CallbackPath = "/signin-wsfed"; // Match the provider's configured redirect URI }); // Set default authorization policy to require authenticated users builder.Services.AddAuthorization(options => { options.FallbackPolicy = new AuthorizationPolicyBuilder() .RequireAuthenticatedUser() .Build(); }); var app = builder.Build(); // Middleware pipeline setup app.UseHttpsRedirection(); app.UseStaticFiles(); app.UseRouting(); app.UseAuthentication(); app.UseAuthorization(); app.MapControllerRoute( name: "default", pattern: "{controller=Home}/{action=Index}/{id?}"); app.Run();
- Add login/logout actions to your controller:
public async Task<IActionResult> Login() { if (!User.Identity.IsAuthenticated) { await HttpContext.ChallengeAsync(WsFederationDefaults.AuthenticationScheme, new AuthenticationProperties { RedirectUri = "/" }); return Unauthorized(); } return RedirectToAction("Index"); } public async Task<IActionResult> Logout() { // Sign out of ADFS and the app's cookie await HttpContext.SignOutAsync(WsFederationDefaults.AuthenticationScheme); await HttpContext.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme); return RedirectToAction("Index"); }
- "Relying party not found" error: Double-check that your
Wtrealmvalue matches exactly what the third-party provided, and confirm they’ve registered your app as a relying party on their ADFS server. - Callback failures: Ensure your
CallbackPathmatches the redirect URI they configured (including HTTPS and case sensitivity). ADFS almost always requires HTTPS for callback URLs, so make sure your app is running over HTTPS. - Metadata loading issues: Verify you can access the Metadata URL directly from your app’s server—firewalls or proxies might be blocking the connection.
Microsoft’s official docs are the most trustworthy resource for this. For .NET Framework, look for guides on WsFederation authentication with OWIN; they cover setting up the relying party trust on ADFS and configuring your MVC app. For .NET Core, check the ASP.NET Core WsFederation authentication docs—they include full examples, configuration details, and troubleshooting for common issues.
内容的提问来源于stack exchange,提问作者Diego Arias

