在Entra External ID租户创建自定义身份验证扩展失败求助
门户点击式创建失败
使用Global Administrator角色账号在Entra External ID租户中创建Custom Authentication Extension,按官方文档操作后创建失败,网络面板捕获到未知验证错误:
{ "error": { "code": "AADB2C90063", "message": "There is a problem with the service.", "innerError": { "correlationId": "e55a7013-2a27-48e2-b500-7e2bae5eea58", "date": "2025-05-15T15:32:51", "request-id": "dbfc4085-b81e-435f-9a09-d11f0546f500", "client-request-id": "dbfc4085-b81e-435f-9a09-d11f0546f500" } } }
操作流程:进入企业应用 → 选择自定义身份验证扩展 → 点击创建自定义扩展 → 完成所有步骤后点击创建。应用已成功注册,但扩展创建失败。尝试Azure Entra External ID面板和Microsoft Entra管理中心,结果一致。
门户失败后的审计日志
调用Graph API https://graph.microsoft.com/v1.0/auditLogs/directoryAudits 获取租户访问令牌后,得到以下审计日志:
{ "id": "B2C_e55a7013-2a27-48e2-b500-7e2bae5eea58_{tenantId}_133917967711438880", "category": "PolicyManagement", "correlationId": "e55a7013-2a27-48e2-b500-7e2bae5eea58", "result": "failure", "resultReason": "NA", "activityDisplayName": "Validate customExtension authenticationConfiguration", "activityDateTime": "2025-05-15T15:32:51.143888Z", "loggedByService": "B2C", "operationType": "Read", "initiatedBy": { "app": null, "user": { "id": "{userId}", "displayName": "{userEmail}", "userPrincipalName": "{userEmail}", "ipAddress": "20.20.34.96", "userType": null, "homeTenantId": null, "homeTenantName": null } }, "targetResources": [ { "id": null, "displayName": "{tenantName}", "type": "Other", "userPrincipalName": null, "groupType": null, "modifiedProperties": [] } ], "additionalDetails": [ { "key": "targetTenant", "value": "{tenantId}" }, { "key": "targetEntityType", "value": "Policy" }, { "key": "actorIdentityType", "value": "UPN" }, { "key": "RequestId", "value": "e55a7013-2a27-48e2-b500-7e2bae5eea58" } ] }
Graph API方式创建失败
由于审计日志未提供有效信息,尝试通过Graph API分步创建:
- 注册应用:
POST https://graph.microsoft.com/v1.0/applications - 创建服务主体:
POST https://graph.microsoft.com/v1.0/servicePrincipals - 更新应用详情:
PUT https://graph.microsoft.com/v1.0/applications/{applicationObjectId}
注:官方文档中此步骤应为POST(创建而非更新),且包含错误的应用权限。
更新应用详情的请求体:
{ "identifierUris": [ "api://{Function_Url_Hostname}/{applicationAppId}" ], "api": { "requestedAccessTokenVersion": 2, "acceptMappedClaims": null, "knownClientApplications": [], "oauth2PermissionScopes": [], "preAuthorizedApplications": [] }, "requiredResourceAccess": [ { "resourceAppId": "00000003-0000-0000-c000-000000000000", "resourceAccess": [ // Unknown permission // { // "id": "00aa00aa-bb11-cc22-dd33-44ee44ee44ee", // "type": "Role" // }, // CustomAuthenticationExtension.ReadWrite.All { "id": "c2667967-7050-4e7e-b059-4cbbb3811d03", "type": "Role" } ] } ] }
下一步执行注册自定义身份验证扩展请求:POST https://graph.microsoft.com/beta/identity/customAuthenticationExtensions,请求失败,错误信息如下:
{ "error": { "code": "AADB2C", "message": "The application does not have any of the required delegated permissions (CustomAuthenticationExtension.ReadWrite.All) to access the resource. ", "innerError": { "correlationId": "54d42225-15a2-4ef6-8fab-0335e8e17504", "date": "2025-05-19T08:27:51", "request-id": "5235b509-61cf-46e2-b1e2-fbbe2fe426fc", "client-request-id": "5235b509-61cf-46e2-b1e2-fbbe2fe426fc" } } }
注:尝试非beta版本Graph API https://graph.microsoft.com/v1.0/identity/customAuthenticationExtensions,同样失败。
Graph API请求失败后的审计日志
{ "id": "B2C_54d42225-15a2-4ef6-8fab-0335e8e17504_{tenantId}_133921168709963190", "category": "Authorization", "correlationId": "54d42225-15a2-4ef6-8fab-0335e8e17504", "result": "failure", "resultReason": "Access denied. Client app does not have required app permissions.", "activityDisplayName": "Create customAuthenticationExtension", "activityDateTime": "2025-05-19T08:27:50.996319Z", "loggedByService": "B2C", "operationType": "Create", "initiatedBy": { "app": null, "user": { "id": "{userId}", "displayName": "{userEmail}", "userPrincipalName": "{userEmail}", "ipAddress": "20.20.34.160", "userType": null, "homeTenantId": null, "homeTenantName": null } }, "targetResources": [ { "id": null, "displayName": "00000000-0000-0000-0000-000000000000", "type": "Other", "userPrincipalName": null, "groupType": null, "modifiedProperties": [] } ], "additionalDetails": [ { "key": "targetTenant", "value": "00000000-0000-0000-0000-000000000000" }, { "key": "targetEntityType", "value": "Policy" }, { "key": "actorIdentityType", "value": "UPN" }, { "key": "RequiredPermissions", "value": "Delegated_CustomAuthenticationExtensionReadWrite, Application_CustomAuthenticationExtensionReadWrite" }, { "key": "RequestId", "value": "54d42225-15a2-4ef6-8fab-0335e8e17504" } ] }
已配置权限说明
已为应用授予CustomAuthenticationExtension.ReadWrite.All的应用权限和委派权限,截图如下:
已尝试所有文档记载的方法,是否存在非文档化的解决方式?
内容的提问来源于stack exchange,提问作者Ion Ciobanu

