Azure Function V2 JWT - AD Authentication

Viewed 1966

I am trying to authenticate the Azure Functions v2. I am getting below error Microsoft.AspNetCore.Authentication.Core: No authentication handler is registered for the scheme 'WebJobsAuthLevel'. The registered schemes are: Bearer. Did you forget to call AddAuthentication().Add[SomeAuthHandler]("WebJobsAuthLevel",...)?.

below is the code I am using in Startup.cs

    public class Startup : IWebJobsStartup
    {
        public void Configure(IWebJobsBuilder builder)
        {
            builder.Services.AddAuthentication()
                    .AddJwtBearer(JwtBearerDefaults.AuthenticationScheme,o =>
                    {
                        o.Audience = "https://*******************.azurewebsites.net/";
                        o.Authority = "http://localhost:****";
                        o.RequireHttpsMetadata = false;
                        o.TokenValidationParameters = new Microsoft.IdentityModel.Tokens.TokenValidationParameters
                        {
                            RequireSignedTokens = true,
                            ValidAudience = "https://***************.azurewebsites.net/",
                            ValidateAudience = true,
                            ValidIssuer = "https://sts.windows.net/***************-5********2**/",
                            ValidateIssuer = true,
                            ValidateIssuerSigningKey = true,
                            ValidateLifetime = true
                        };
                    });
        }

    }

changed the code but still getting same given error. Which one I am missing?

1 Answers

Consider using the Azure App Service Authentication/Authorization feature (also known unofficially as EasyAuth). If you follow the express flow in the Azure Portal, it will create an AAD V1 application registration for your function application, and automatically configure your app to allow authentication using AAD. If you then set Action to take when request is not authenticated to Login with Azure Active Directory, only authenticated requests will be authorized to make any request to your application.

EasyAuth has built in support for accepting Bearer tokens for your AAD app registration, as well as some other OAuth2/OIDC flows for AAD and our other supported identity providers (Facebook, Google, Twitter). Through this feature, you shouldn't need to add any code on your end, it will all be handled by the Azure platform.

Related