Azure AD Claims mapping requires custom signing key

Viewed 5502

We're using application client credentials to authenticate via Azure AD.

When we do this the Identity.Name is null. This is because there is no name claim mapped into the JWT.

We discovered you can map custom claims, like so: Claims mapping in Azure Active Directory.

When you apply the policy to the application, the next time you authenticate you receive an error:

"AADSTS50146: This application is required to be configured with an application-specific signing key."

Cool, there is a way out of this though: New-AzureADApplicationKeyCredential. It indicates you can create a Symmetric signing key in your application and voila -- we now have a JWT with the custom claim.

The problem, not resolved: it generates a jwt with a HS256 header, not the required RS256 algorithm.

When I try to authorize the jwt against the application. It fails, unauthorized.

Now I am stuck, I can map a custom claim, but with no way to authorize the jwt :(

I there a way to resolve this issue?

3 Answers

It's good to remember to set acceptMappedClaims to true in the application registration manifest in Azure.

Our application was using:

UseWindowsAzureActiveDirectoryBearerAuthentication(
                new WindowsAzureActiveDirectoryBearerAuthenticationOptions

Changing the application to:

UseJwtBearerAuthentication(
            new Microsoft.Owin.Security.Jwt.JwtBearerAuthenticationOptions

Allows us to authorize the JWT token. considering the claims mapping feature is in preview; I'll take this as an answer for now. Assuming when the feature is released we can add Asymmetric application signing keys.

For now I am happy to just map the appid claim (and does not require a custom claim mapping) to the name claim, like so :

JwtSecurityTokenHandler.InboundClaimTypeMap.Add("appid", System.Security.Claims.ClaimTypes.Name);

According to this article the error message can also be because the policy is invalid. In my case, I was able to get the error to stop by using the Set-AzureADPolicy PowerShell command to change the policy and the error went away. I believe I had some invalid claim IDs.

Related