You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security对接Azure OIDC OAuth2:授权端点仅返回id_token问题

Why does Azure OIDC OAuth2 authorization endpoint only return id_token?

Hey there, I’ve run into a similar issue before—let’s break down the possible reasons and fixes step by step:

Common Causes & Solutions

1. Your request only includes the openid scope

Per the OIDC specification, the openid scope is required to trigger an OIDC flow, but it only tells the authorization server to return an id_token (for user identity verification). If you need an access_token (to call APIs) or refresh_token (to get new tokens without re-authenticating), you need to add additional scopes to your authorization request.

For example:

  • Add standard OIDC scopes like profile or email to get more user profile data in the id_token
  • Add Azure AD-specific resource scopes like User.Read to get an access_token for Microsoft Graph

Double-check that your Spring Security configuration is including these extra scopes in the authorization request.

2. You’re using the Implicit Flow

If your Azure AD app registration has "Implicit grant and hybrid flows" enabled (under Authentication > Advanced settings), this flow is designed to return id_token directly to the frontend browser. While you can enable access token return in implicit flow, it’s not recommended for production (tokens are exposed in URL/frontend storage).

The fix here is to switch to the Authorization Code Flow—this is the default, secure flow recommended by both Spring Security OAuth2 Login and Azure AD. Make sure implicit flow is disabled in your Azure app settings unless you have a specific, valid reason to use it.

3. Spring Security configuration gaps

Since you’ve referenced Spring Security 5.7’s OAuth2 Login docs, let’s verify a few key config points:

  • Ensure your SecurityFilterChain is set up for authorization code flow (no accidental implicit flow overrides)
  • Confirm you’re specifying the required scopes in the OAuth2 login configuration. Here’s a quick snippet example:
@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
    http
        .authorizeHttpRequests(auth -> auth.anyRequest().authenticated())
        .oauth2Login(oauth2 -> oauth2
            .authorizationEndpoint(authz -> authz
                .authorizationRequestResolver(resolver -> 
                    resolver.additionalParameters(Map.of("scope", "openid User.Read"))
                )
            )
        );
    return http.build();
}

Also, don’t forget to check that your Azure AD app registration has the required API permissions added, and that admin consent is granted if needed (for tenant-wide permissions).

4. Residual custom policy configuration

You mentioned you initially looked into custom policies but decided they weren’t necessary. Double-check that there are no leftover custom configurations (like a custom OAuth2AuthorizationRequestResolver) that might be overriding the default scope parameters or flow settings in your Spring app.

Quick Troubleshooting Tip

You can capture the authorization request URL sent to Azure AD (use browser dev tools to inspect the redirect) to verify:

  • The scope parameter includes more than just openid
  • The response_type is code (for authorization code flow) instead of id_token (implicit flow)

内容的提问来源于stack exchange,提问作者evh69

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 06:48:54