You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

UWP应用联邦身份认证:跳过AAD登录页直接重定向至ADFS

Skip Azure AD Login Page in UWP with ADAL for .NET (Federated ADFS Setup)

Great question! I’ve tackled this exact scenario before when working with UWP apps connected to a federated Azure AD (synced with on-prem AD via AD Connect). The key here is leveraging the same domain_hint parameter you used in web apps—you just need to pass it correctly through ADAL’s AcquireTokenAsync method in your UWP code.

Here’s how to modify your existing code to skip the default Azure AD login page and redirect straight to your organization’s custom ADFS login page:

AuthenticationContext ac = new AuthenticationContext("https://login.microsoftonline.com/abccompany.onmicrosoft.com");

// Create a dictionary to hold extra query parameters
var extraQueryParams = new Dictionary<string, string>
{
    // Replace with your organization's verified domain (not the .onmicrosoft.com one)
    {"domain_hint", "abccompany.com"}
};

// Use the AcquireTokenAsync overload that accepts extra query parameters
AuthenticationResult ar = await ac.AcquireTokenAsync(
    "resource",
    "clientId",
    new Uri("redirect url for client app"),
    new PlatformParameters(PromptBehavior.Always, false),
    UserIdentifier.AnyUser,
    // Convert the dictionary to a query string format ADAL expects
    string.Join("&", extraQueryParams.Select(kv => $"{kv.Key}={kv.Value}"))
);

// Retrieve your token as before
var accessToken = ar.AccessToken;

Why this works:

The domain_hint parameter tells Azure AD exactly which federated identity provider (your ADFS instance) the user belongs to. Since your Azure AD is already federated with ADFS, passing this hint skips the default Azure AD login prompt and immediately redirects the user to your organization’s custom login page—just like it did in your web app.

Important notes:

  • Make sure the domain_hint value is your organization’s verified domain in Azure AD (e.g., abccompany.com, not abccompany.onmicrosoft.com). This is the domain you configured when setting up federation with ADFS.
  • The PromptBehavior.Always ensures the login flow triggers every time (useful for testing), but you can adjust this to PromptBehavior.Auto if you want to leverage cached sessions.
  • This approach aligns with the OIDC protocol’s domain_hint specification, which is the same mechanism you used in your web app’s OpenIdConnectEvents setup.

内容的提问来源于stack exchange,提问作者SanjayD

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 06:35:07