UWP应用联邦身份认证:跳过AAD登录页直接重定向至ADFS
Great question! I’ve tackled this exact scenario before when working with UWP apps connected to a federated Azure AD (synced with on-prem AD via AD Connect). The key here is leveraging the same domain_hint parameter you used in web apps—you just need to pass it correctly through ADAL’s AcquireTokenAsync method in your UWP code.
Here’s how to modify your existing code to skip the default Azure AD login page and redirect straight to your organization’s custom ADFS login page:
AuthenticationContext ac = new AuthenticationContext("https://login.microsoftonline.com/abccompany.onmicrosoft.com"); // Create a dictionary to hold extra query parameters var extraQueryParams = new Dictionary<string, string> { // Replace with your organization's verified domain (not the .onmicrosoft.com one) {"domain_hint", "abccompany.com"} }; // Use the AcquireTokenAsync overload that accepts extra query parameters AuthenticationResult ar = await ac.AcquireTokenAsync( "resource", "clientId", new Uri("redirect url for client app"), new PlatformParameters(PromptBehavior.Always, false), UserIdentifier.AnyUser, // Convert the dictionary to a query string format ADAL expects string.Join("&", extraQueryParams.Select(kv => $"{kv.Key}={kv.Value}")) ); // Retrieve your token as before var accessToken = ar.AccessToken;
Why this works:
The domain_hint parameter tells Azure AD exactly which federated identity provider (your ADFS instance) the user belongs to. Since your Azure AD is already federated with ADFS, passing this hint skips the default Azure AD login prompt and immediately redirects the user to your organization’s custom login page—just like it did in your web app.
Important notes:
- Make sure the
domain_hintvalue is your organization’s verified domain in Azure AD (e.g.,abccompany.com, notabccompany.onmicrosoft.com). This is the domain you configured when setting up federation with ADFS. - The
PromptBehavior.Alwaysensures the login flow triggers every time (useful for testing), but you can adjust this toPromptBehavior.Autoif you want to leverage cached sessions. - This approach aligns with the OIDC protocol’s
domain_hintspecification, which is the same mechanism you used in your web app’s OpenIdConnectEvents setup.
内容的提问来源于stack exchange,提问作者SanjayD

