You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Entra External ID租户创建自定义身份验证扩展失败求助

Entra External ID租户创建自定义身份验证扩展失败问题排查

门户点击式创建失败

使用Global Administrator角色账号在Entra External ID租户中创建Custom Authentication Extension,按官方文档操作后创建失败,网络面板捕获到未知验证错误:

{
    "error": {
        "code": "AADB2C90063",
        "message": "There is a problem with the service.",
        "innerError": {
            "correlationId": "e55a7013-2a27-48e2-b500-7e2bae5eea58",
            "date": "2025-05-15T15:32:51",
            "request-id": "dbfc4085-b81e-435f-9a09-d11f0546f500",
            "client-request-id": "dbfc4085-b81e-435f-9a09-d11f0546f500"
        }
    }
}

操作流程:进入企业应用 → 选择自定义身份验证扩展 → 点击创建自定义扩展 → 完成所有步骤后点击创建。应用已成功注册,但扩展创建失败。尝试Azure Entra External ID面板和Microsoft Entra管理中心,结果一致。

门户失败后的审计日志

调用Graph API https://graph.microsoft.com/v1.0/auditLogs/directoryAudits 获取租户访问令牌后,得到以下审计日志:

{
    "id": "B2C_e55a7013-2a27-48e2-b500-7e2bae5eea58_{tenantId}_133917967711438880",
    "category": "PolicyManagement",
    "correlationId": "e55a7013-2a27-48e2-b500-7e2bae5eea58",
    "result": "failure",
    "resultReason": "NA",
    "activityDisplayName": "Validate customExtension authenticationConfiguration",
    "activityDateTime": "2025-05-15T15:32:51.143888Z",
    "loggedByService": "B2C",
    "operationType": "Read",
    "initiatedBy": {
        "app": null,
        "user": {
            "id": "{userId}",
            "displayName": "{userEmail}",
            "userPrincipalName": "{userEmail}",
            "ipAddress": "20.20.34.96",
            "userType": null,
            "homeTenantId": null,
            "homeTenantName": null
        }
    },
    "targetResources": [
        {
            "id": null,
            "displayName": "{tenantName}",
            "type": "Other",
            "userPrincipalName": null,
            "groupType": null,
            "modifiedProperties": []
        }
    ],
    "additionalDetails": [
        {
            "key": "targetTenant",
            "value": "{tenantId}"
        },
        {
            "key": "targetEntityType",
            "value": "Policy"
        },
        {
            "key": "actorIdentityType",
            "value": "UPN"
        },
        {
            "key": "RequestId",
            "value": "e55a7013-2a27-48e2-b500-7e2bae5eea58"
        }
    ]
}

Graph API方式创建失败

由于审计日志未提供有效信息,尝试通过Graph API分步创建:

  • 注册应用:POST https://graph.microsoft.com/v1.0/applications
  • 创建服务主体:POST https://graph.microsoft.com/v1.0/servicePrincipals
  • 更新应用详情:PUT https://graph.microsoft.com/v1.0/applications/{applicationObjectId}

注:官方文档中此步骤应为POST(创建而非更新),且包含错误的应用权限。

更新应用详情的请求体:

{
    "identifierUris": [
        "api://{Function_Url_Hostname}/{applicationAppId}"
    ],
    "api": {
        "requestedAccessTokenVersion": 2,
        "acceptMappedClaims": null,
        "knownClientApplications": [],
        "oauth2PermissionScopes": [],
        "preAuthorizedApplications": []
    },
    "requiredResourceAccess": [
        {
            "resourceAppId": "00000003-0000-0000-c000-000000000000",
            "resourceAccess": [
                // Unknown permission
                // { 
                //     "id": "00aa00aa-bb11-cc22-dd33-44ee44ee44ee",
                //     "type": "Role"
                // },
                // CustomAuthenticationExtension.ReadWrite.All
                {
                    "id": "c2667967-7050-4e7e-b059-4cbbb3811d03",
                    "type": "Role"
                }
            ]
        }
    ]
}

下一步执行注册自定义身份验证扩展请求:POST https://graph.microsoft.com/beta/identity/customAuthenticationExtensions,请求失败,错误信息如下:

{
    "error": {
        "code": "AADB2C",
        "message": "The application does not have any of the required delegated permissions (CustomAuthenticationExtension.ReadWrite.All) to access the resource. ",
        "innerError": {
            "correlationId": "54d42225-15a2-4ef6-8fab-0335e8e17504",
            "date": "2025-05-19T08:27:51",
            "request-id": "5235b509-61cf-46e2-b1e2-fbbe2fe426fc",
            "client-request-id": "5235b509-61cf-46e2-b1e2-fbbe2fe426fc"
        }
    }
}

注:尝试非beta版本Graph API https://graph.microsoft.com/v1.0/identity/customAuthenticationExtensions,同样失败。

Graph API请求失败后的审计日志

{
    "id": "B2C_54d42225-15a2-4ef6-8fab-0335e8e17504_{tenantId}_133921168709963190",
    "category": "Authorization",
    "correlationId": "54d42225-15a2-4ef6-8fab-0335e8e17504",
    "result": "failure",
    "resultReason": "Access denied. Client app does not have required app permissions.",
    "activityDisplayName": "Create customAuthenticationExtension",
    "activityDateTime": "2025-05-19T08:27:50.996319Z",
    "loggedByService": "B2C",
    "operationType": "Create",
    "initiatedBy": {
        "app": null,
        "user": {
            "id": "{userId}",
            "displayName": "{userEmail}",
            "userPrincipalName": "{userEmail}",
            "ipAddress": "20.20.34.160",
            "userType": null,
            "homeTenantId": null,
            "homeTenantName": null
        }
    },
    "targetResources": [
        {
            "id": null,
            "displayName": "00000000-0000-0000-0000-000000000000",
            "type": "Other",
            "userPrincipalName": null,
            "groupType": null,
            "modifiedProperties": []
        }
    ],
    "additionalDetails": [
        {
            "key": "targetTenant",
            "value": "00000000-0000-0000-0000-000000000000"
        },
        {
            "key": "targetEntityType",
            "value": "Policy"
        },
        {
            "key": "actorIdentityType",
            "value": "UPN"
        },
        {
            "key": "RequiredPermissions",
            "value": "Delegated_CustomAuthenticationExtensionReadWrite, Application_CustomAuthenticationExtensionReadWrite"
        },
        {
            "key": "RequestId",
            "value": "54d42225-15a2-4ef6-8fab-0335e8e17504"
        }
    ]
}

已配置权限说明

已为应用授予CustomAuthenticationExtension.ReadWrite.All的应用权限和委派权限,截图如下:
权限授予截图

已尝试所有文档记载的方法,是否存在非文档化的解决方式?

内容的提问来源于stack exchange,提问作者Ion Ciobanu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 02:44:51