My question is how to apply user authentication in web application using azure ad in case I don't have client secret. I just have client-id and tenant-id. I would appreciate your swift response.
My question is how to apply user authentication in web application using azure ad in case I don't have client secret. I just have client-id and tenant-id. I would appreciate your swift response.
AFAIK there is no need to use client secret in web application while we are authenticating with Azure AD.
While authenticating your App with Azure AD, your code snippet will be something like below:
{
"AzureAd": {
"Instance": "https://login.microsoftonline.com/",
"ClientId": "*******************************",
"TenantId": "*******************************",
"CallbackPath": "https://localhost/signin-oidc"
}
If you want to get access token via Postman without using client secret, you can make use of ROPC flow like below:
In Postman, Go to Authorization tab and select type as Oauth2.0
Go to Headers tab and include Content-Type key and give value as application/x-www-form-urlencoded
In Body tab, include parameters like client_id, grant_type, username, password and scope as below:
And you will get the access token like below: