how to use azure ad without client secret just with client id and tenant id?

Viewed 522

My question is how to apply user authentication in web application using azure ad in case I don't have client secret. I just have client-id and tenant-id. I would appreciate your swift response.

1 Answers

AFAIK there is no need to use client secret in web application while we are authenticating with Azure AD.

While authenticating your App with Azure AD, your code snippet will be something like below:

{  
"AzureAd": {  
"Instance": "https://login.microsoftonline.com/",  
"ClientId": "*******************************",  
"TenantId": "*******************************",  
"CallbackPath": "https://localhost/signin-oidc"
}

If you want to get access token via Postman without using client secret, you can make use of ROPC flow like below:

  • In Postman, Go to Authorization tab and select type as Oauth2.0

  • Go to Headers tab and include Content-Type key and give value as application/x-www-form-urlencoded

  • In Body tab, include parameters like client_id, grant_type, username, password and scope as below:

enter image description here

And you will get the access token like below:

enter image description here

Related