You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure B2C重置策略异常:未授权用户访问受保护资源跳转重置页

Troubleshooting Unexpected Password Reset Redirect in Azure AD B2C MVC Apps

Yep, I’ve seen this exact issue pop up a few times with Azure AD B2C + MVC setups. Let’s break down the most common causes and fixes to get you sorted:

  • Check your authentication middleware configuration
    The most frequent culprit is misconfigured authentication middleware in Startup.cs (or Program.cs for .NET 6+). If your app accidentally sets the password reset policy as the default challenge scheme instead of your sign-up/sign-in policy, unauthenticated users will be redirected to the reset flow instead of the login page.

    For example, in .NET 6+, make sure your configuration explicitly targets the sign-up/sign-in policy as the default challenge:

    builder.Services.AddAuthentication(AzureADB2CDefaults.AuthenticationScheme)
        .AddAzureADB2C(options => builder.Configuration.Bind("AzureAdB2C", options));
    
    // Ensure the default challenge uses your sign-up/sign-in policy
    builder.Services.Configure<OpenIdConnectOptions>(AzureADB2CDefaults.OpenIdScheme, options =>
    {
        options.DefaultChallengeScheme = AzureADB2CDefaults.AuthenticationScheme;
        // Alternatively, directly specify your policy ID:
        // options.DefaultChallengeScheme = "B2C_1_SignUpSignIn";
    });
    
  • Verify policy route parameters
    Double-check if your app’s routing or redirect logic is incorrectly appending the password reset policy ID to authentication requests when users hit protected resources. Look for custom [Authorize] attributes, global authorization filters, or redirect URL parameters where the p (policy) parameter might be set to your reset policy instead of the login policy.

  • Inspect custom error handling/redirect logic
    If you’ve implemented custom event handlers (like OnRedirectToIdentityProvider in OpenIdConnectEvents), ensure you aren’t overriding the default challenge behavior to force a redirect to the password reset policy. Accidental logic here can override the intended flow for unauthenticated users.

  • Validate B2C policy settings
    While less likely, confirm your sign-up/sign-in policy isn’t misconfigured to route users to the reset flow by default. The login template’s "Forgot Password" link should trigger the reset policy explicitly, but a misconfigured policy entry point could cause unexpected behavior.

Once you share more details (like your middleware code snippets or policy setup), we can drill down further. But these initial checks usually resolve this specific issue.

内容的提问来源于stack exchange,提问作者Jim Taliadoros

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 09:19:22