You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Sitecore 9中如何实现基于声明的Active Directory授权

关于Sitecore 9中AD原生授权与ADFS声明式授权的区别及配置方案

1. 仅用Active Directory vs 结合ADFS的声明式AD授权的核心区别

咱先把这俩的差异掰透,避免后续配置踩坑:

  • 认证机制本质不同:
    • 原生AD授权用的是NTLM/Kerberos这类传统域内认证协议,依赖域控制器的直接信任,用户身份是通过域令牌验证的,只能在域内网环境用。
    • ADFS是基于声明式认证(SAML 2.0/OAuth 2.0),把AD的身份信息打包成“声明”(比如用户名、角色、邮箱),通过安全令牌传递给Sitecore,支持跨域、跨平台(比如外网访问、非Windows客户端)。
  • 信任模型范围不同:
    • 原生AD的信任仅限域内或已建立域信任的环境,扩展性差。
    • ADFS支持联邦信任,可以对接多个外部系统(比如Sitecore、Office 365、自定义应用),甚至和其他组织的ADFS建立信任,实现跨企业身份共享。
  • 权限传递方式不同:
    • 原生AD是直接传递域用户的安全组信息,Sitecore直接读取AD组来授权,灵活性低。
    • ADFS可以自定义声明规则,比如把AD里的memberOf映射成Sitecore需要的角色声明,或者添加自定义属性(比如员工ID)作为声明,权限控制更灵活。
  • 安全与合规性不同:
    • 原生AD依赖域内网络安全,缺乏细粒度的认证策略(比如MFA、条件访问)。
    • ADFS支持多因素认证(MFA)、基于IP/设备的条件访问,更符合企业级安全合规要求。

2. 已有ADFS/ADDS/Sitecore 9环境下,配置声明式AD授权的实战步骤

假设你已经部署好ADFS服务器(已配置AD作为身份提供商)、ADDS域,且Sitecore 9已正常运行,分两大块配置:

第一步:ADFS端配置依赖方信任(Relying Party Trust)

  1. 打开ADFS管理控制台,右键Relying Party Trusts → Add Relying Party Trust,选择Claims aware,点击下一步。
  2. 选择Enter data about the relying party manually,输入显示名称(比如Sitecore 9 CMS),点击下一步。
  3. 选择ADFS profile,点击下一步。
  4. 跳过加密证书(如果需要加密可以后续配置),点击下一步。
  5. 勾选Enable support for the SAML 2.0 WebSSO protocol,输入Sitecore Identity Server的回调URL(比如https://your-sitecore-identity-server.com/signin-saml2),点击下一步。
  6. 添加依赖方信任标识符(比如urn:sitecore:identityserver),点击下一步。
  7. 选择Permit all users to access this relying party,后续可以细化权限,点击下一步完成。
  8. 配置声明规则:右键刚创建的依赖方信任 → Edit Claim Issuance Policy,添加以下规则:
    • 规则1:传递用户名:选择Send LDAP Attributes as Claims,属性存储选Active Directory,LDAP属性选sAMAccountName,输出声明类型选Name ID(格式选Unspecified)。
    • 规则2:传递角色:选择Send Group Membership as Claims,输入AD组的DN(比如CN=Sitecore Authors,OU=Sitecore Groups,DC=yourdomain,DC=com),输出声明类型选http://schemas.microsoft.com/ws/2008/06/identity/claims/role。
    • 可以按需添加其他声明(比如邮箱、部门)。

第二步:Sitecore端配置联邦认证

这里分两种情况,取决于你的Sitecore 9版本:

情况A:Sitecore 9.1+(使用Sitecore Identity Server)
  1. 登录Sitecore Identity Server服务器,修改IdentityServer\Config\production\IdentityServerHost.xml:
    • 添加ADFS作为外部身份提供商,示例配置片段:
      <ExternalIdentityProviders>
        <ExternalIdentityProvider Name="ADFS" DisplayName="ADFS Login" Enabled="true" Type="Sitecore.Owin.Authentication.Configuration.DefaultExternalIdentityProvider, Sitecore.Owin.Authentication">
          <AuthenticationType>saml2</AuthenticationType>
          <Caption>ADFS Login</Caption>
          <Enabled>true</Enabled>
          <MetadataAddress>https://adfs.yourdomain.com/federationmetadata/2007-06/federationmetadata.xml</MetadataAddress>
          <EntityId>urn:sitecore:identityserver</EntityId>
          <CallbackPath>/signin-saml2</CallbackPath>
          <SignInScheme>idsrv.external</SignInScheme>
        </ExternalIdentityProvider>
      </ExternalIdentityProviders>
      
    • 保存后重启Sitecore Identity Server服务。
  2. 修改Sitecore CMS的App_Config\Include\Sitecore.Owin.Authentication.config(或自定义配置文件),添加声明映射:
    <authenticationProviders>
      <provider name="ADFS" type="Sitecore.Owin.Authentication.Configuration.DefaultAuthenticationProvider, Sitecore.Owin.Authentication">
        <transformations>
          <!-- 映射NameID到Sitecore用户名 -->
          <transformation name="Name Identifier to Claim" type="Sitecore.Owin.Authentication.Services.DefaultTransformation, Sitecore.Owin.Authentication">
            <sources>
              <claim name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier" />
            </sources>
            <targets>
              <claim name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name" />
            </targets>
            <keepSource>true</keepSource>
          </transformation>
          <!-- 映射ADFS角色到Sitecore角色 -->
          <transformation name="Role Transformation" type="Sitecore.Owin.Authentication.Services.DefaultTransformation, Sitecore.Owin.Authentication">
            <sources>
              <claim name="http://schemas.microsoft.com/ws/2008/06/identity/claims/role" />
            </sources>
            <targets>
              <claim name="http://schemas.microsoft.com/ws/2008/06/identity/claims/role" value="sitecore\{0}" />
            </targets>
            <keepSource>true</keepSource>
          </transformation>
        </transformations>
        <!-- 自动创建Sitecore用户 -->
        <userBuilder type="Sitecore.Owin.Authentication.Services.DefaultUserBuilder, Sitecore.Owin.Authentication">
          <options>
            <domain>sitecore</domain>
            <nameIdentifierClaimType>http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier</nameIdentifierClaimType>
          </options>
        </userBuilder>
      </provider>
    </authenticationProviders>
    
  3. 重启Sitecore CMS应用池,测试登录:访问Sitecore后台,点击ADFS Login,跳转到ADFS登录页面,输入域用户 credentials,验证是否成功登录,且角色是否正确同步。
情况B:Sitecore 9.0(使用传统Federated Authentication模块)
  1. 安装Sitecore Federated Authentication模块(如果未安装)。
  2. 配置App_Config\Include\Sitecore.FederatedAuthentication.config,添加ADFS认证方案,配置元数据地址、声明映射,步骤类似上面的Identity Server配置,但需要手动配置OWIN中间件的SAML2认证。
  3. 确保ADFS的回调URL指向Sitecore CMS的登录回调(比如https://your-sitecore-cms.com/sitecore/login)。

关键注意事项

  • 证书信任:把ADFS的签名证书导入到Sitecore服务器的受信任根证书颁发机构,避免证书验证失败。
  • 回调URL一致性:ADFS里配置的回调URL必须和Sitecore端的CallbackPath完全一致,包括HTTP/HTTPS、域名、路径。
  • 声明映射准确性:确保ADFS输出的声明类型和Sitecore端配置的映射类型一致,否则用户身份或角色无法正确同步。
  • 测试权限:登录后检查Sitecore用户的角色是否正确,比如AD组Sitecore Authors是否映射到Sitecore的sitecore\Sitecore Authors角色。

内容的提问来源于stack exchange,提问作者きむてそん

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:08:09