Dual authentication with ASP.NET Core MVC

Viewed 141

I have an ASP.NET Core MVC web application and I want to allow my users to authenticate using identity server 4 and Azure Active Directory. All my internal users (company users) need to use Azure AD and all external users should use identity server to signing.

I have setup authentication in startup class as follows:

 services.AddAuthentication(options =>
            {
                options.DefaultScheme = OpenIdConnectDefaults.AuthenticationScheme;
            })
             .AddOpenIdConnect("oidc",  options =>
             {
                 options.Authority = Configuration["Identity:WebApiUrl"];
    
                 options.ClientId = "xxxxxxx";
                 options.ClientSecret = "xxxxxxxxx";
                 options.ResponseType = "id_token";
    
                 options.Scope.Add("openid");
                 options.Scope.Add("profile");
    
                 options.GetClaimsFromUserInfoEndpoint = true;
                 options.ClaimActions.MapUniqueJsonKey("email", "email");
    
                 options.SaveTokens = true;
             })
             .AddMicrosoftIdentityWebApp(Configuration.GetSection("AzureAd"));

This will only allow internal users to signin using azure AD and external users gets following error.

Exception: Correlation failed.
Unknown location

Exception: An error was encountered while handling the remote login.

Microsoft.AspNetCore.Authentication.RemoteAuthenticationHandler.HandleRequestAsync()

How can I solve this issue and allow both external and internal users to login ?

Thank you.

0 Answers
Related