You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OneLogin + Dynamics 365 代码认证报错问题咨询

Fixing "The authentication endpoint Username was not found" Error When Calling Dynamics 365 Web Service with Static Credentials

Hey there, let's work through this authentication issue you're hitting. First, let's unpack what's happening: your browser works smoothly via OneLogin's interactive SAML/OIDC auth, but when you try to pass static credentials via code, you get that truncated error about the username not being found. Here's why that's happening and how to fix it:

Why This Error Happens

That partial error is almost certainly The authentication endpoint Username was not found in the context of your tenant (or a similar variation). It usually boils down to one of two core issues:

  • You're using an authentication flow that's either blocked by your OneLogin/Dynamics 365 setup or doesn't fit the non-interactive code scenario.
  • Your credential request is targeting the wrong endpoint, or you're passing invalid/missing parameters.

Dynamics 365 and enterprise identity providers like OneLogin strongly recommend using service principals for code-based, non-interactive authentication. This is more secure and avoids the pitfalls of static user credentials. Here's how to set it up:

  1. Create a Service Principal in Your Identity Platform

    • If you're using Azure AD linked to OneLogin: Create a service principal, then assign it the necessary Dynamics 365 permissions (e.g., Dynamics CRM User or system admin roles, depending on your needs).
    • If you're using OneLogin directly as your IDP: Set up an API client in OneLogin, configure it with client credentials (client ID + client secret), and grant it access to your Dynamics 365 instance.
  2. Authenticate with the Service Principal
    Use the service principal's credentials to fetch a bearer token, then use that token to call the Dynamics 365 web service. Here's a straightforward C# example:

    using Microsoft.IdentityModel.Clients.ActiveDirectory;
    using System.Net.Http;
    using System.Net.Http.Headers;
    using System.Threading.Tasks;
    
    public async Task CallDynamicsService()
    {
        // Replace these with your actual values
        var clientId = "your-service-principal-client-id";
        var clientSecret = "your-service-principal-client-secret";
        var tenantId = "your-tenant-id"; // Or your OneLogin domain for OIDC endpoints
        var dynamicsResource = "https://ourcompany.api.crm.dynamics.com";
        var dynamicsEndpoint = $"{dynamicsResource}/.../Organization.svc";
    
        // Fetch access token
        var authContext = new AuthenticationContext($"https://login.microsoftonline.com/{tenantId}");
        var credential = new ClientCredential(clientId, clientSecret);
        var authResult = await authContext.AcquireTokenAsync(dynamicsResource, credential);
    
        // Call the Dynamics 365 web service
        using var httpClient = new HttpClient();
        httpClient.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", authResult.AccessToken);
        var response = await httpClient.GetAsync(dynamicsEndpoint);
        response.EnsureSuccessStatusCode(); // Throws an exception if the request fails
    }
    

If you absolutely need to use a specific user's static credentials (note: this is less secure and often blocked by enterprise IDPs like OneLogin), here's what to check:

  1. Confirm the Authentication Flow is Enabled

    • Make sure your tenant (Azure AD/OneLogin) allows the Resource Owner Password Credentials (ROPC) flow. Most organizations disable this by default due to security risks.
    • For OneLogin: Ensure the user account doesn't enforce MFA (which breaks ROPC) and allows password-based authentication.
  2. Fix Your Request Parameters
    Double-check that you're targeting the correct token endpoint and passing all required parameters. For example, an HTTP POST to Azure AD's token endpoint would look like this:

    POST https://login.microsoftonline.com/{tenantId}/oauth2/token
    Content-Type: application/x-www-form-urlencoded
    
    grant_type=password&username=your-static-user@yourcompany.com&password=your-static-password&client_id=your-app-client-id&resource=https://ourcompany.api.crm.dynamics.com
    
    • Critical: Use the full user principal name (UPN) for the username parameter (not just the local username part).
    • If using OneLogin's OIDC endpoint, adjust the URL to https://your-onelogin-domain.onelogin.com/oidc/token and follow OneLogin's specific OIDC parameter requirements.

Quick Troubleshooting Tips

  • Get the full error message: Log the complete error text instead of just the truncated version—it will tell you exactly if the issue is with the tenant, username format, or endpoint.
  • Validate permissions: Ensure whatever identity you're using (service principal or user) has explicit access to the Dynamics 365 instance and the specific web service operations you're trying to call.

内容的提问来源于stack exchange,提问作者Michael

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:13:26