You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Amplify集成Azure AD:无法配置urn格式应用ID URI的求助

Amplify集成Entra ID时的SAML标识符冲突问题

我在将应用与Active Directory集成时,先在amplify/auth/resource.ts中添加了以下SAML配置:

externalProviders: {
    saml: {
        name: 'MyApp',
        metadata: {
            metadataContent: 'https://login.microsoftonline.com/<Tenant ID>/federationmetadata/2007-06/federationmetadata.xml',
            metadataType: 'URL'
        },
    },
}

接下来我在Azure门户创建应用注册,原本需要修改清单中的identifierUris为以下格式,让Cognito能找到该应用:

"identifierUris": ["urn:amazon:cognito:sp:<region>_<UserPoolID>"]

但现在Entra ID已经不允许这种操作了,报错如下:

根据组织的默认租户策略,所有新添加的URI必须包含租户验证域名、租户ID或应用ID。

现在标识符URI(应用ID URI)只能设置成这种格式:

api://<Application ID>

当我在代码中调用登录方法:

await signInWithRedirect({ provider: { custom: "MyApp" } });

此时收到如下错误:

抱歉,我们无法完成登录。
AADSTS700016: 目录中未找到标识符为'urn:amazon:cognito:sp:region_UserPoolID'的应用

问题在于我找不到修改Amplify中SAML应用标识符的方式——比如想在配置里加一个appIdentifier字段指定自定义的标识符:

externalProviders: {
    saml: {
        name: 'MyApp', 
        appIdentifier: 'api://<Application ID>'
    }
}

看起来urn:amazon:cognito:sp:[region]_[UserPoolID]这个标识符是硬编码死的,目前没找到变通方法。有没有人已经解决这个问题了?

内容的提问来源于stack exchange,提问作者Duzmac

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 04:44:51