Has anyone tried to use Azure B2C for their external users through their own homegrown portal? We are running into issues trying to use OIDC as the protocol to secure it and have SSO work properly.  OIDC's security model is to restrict 3rd party initiated logins so once we have users login to our portal, and pass the tokens from our portal to another app, we get an issuer mismatch error from our apps and can't create an SSO login experience for our users.

1.5k views1 Upvote2 Comments
Sort By:
Oldest
VP of Application Development in Finance (non-banking)3 months ago
This article uses a sample JavaScript single-page application (SPA) to illustrate how to add Azure Active Directory B2C (Azure AD B2C) authentication to your SPAs. https://learn.microsoft.com/en-us/azure/active-directory-b2c/configure-authentication-sample-spa-app

Also this may be helpful if they are using .NET https://learn.microsoft.com/en-us/entra/msal/dotnet/acquiring-tokens/desktop-mobile/social-identities 
1
lock icon

Please join or sign in to view more content.

By joining the Peer Community, you'll get:

  • Peer Discussions and Polls
  • One-Minute Insights
  • Connect with like-minded individuals
VP of Engineering in Insurance (except health)3 months ago
We do not use azure b2c in our company – we use aws and okta - but it sounds like there's a configured trust missing. Depending how your team set it up the trust is missing either between different auth servers or missing policies across apps within an auth server. Sorry I don't have a better answer but I hope this helps!
1

Content you might like

TCO19%

Pricing26%

Integrations21%

Alignment with Cloud Provider7%

Security10%

Alignment with Existing IT Skills4%

Product / Feature Set7%

Vendor Relationship / Reputation

Other (comment)

View Results
5.7k views3 Upvotes1 Comment
243 views2 Upvotes

Yes79%

No20%

1.2k views
Head of Enterprise Architecture MERCK Group in Healthcare and Biotecha year ago
Strategy & Architecture
Read More Comments
39k views5 Upvotes34 Comments