【问题标题】:Enable Azure AD SSO on Web Server which has no internet connection在没有 Internet 连接的 Web 服务器上启用 Azure AD SSO
【发布时间】:2020-09-21 03:18:14
【问题描述】:
【问题讨论】:
标签:
asp.net
azure-active-directory
single-sign-on
【解决方案1】:
据微软称,https://docs.microsoft.com/en-ca/office365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online
我相信第 56 类是用于身份和身份验证的,你是否需要它们,我不确定,但微软似乎是这样认为的?
56 允许
必需 是 *.msappproxy.net、*.msftidentity.com、*.msidentity.com、account.activedirectory.windowsazure.com、accounts.accesscontrol.windows.net、adminwebservice.microsoftonline.com、api.passwordreset.microsoftonline.com、 autologon.microsoftazuread-sso.com、becws.microsoftonline.com、clientconfig.microsoftonline-p.net、companymanager.microsoftonline.com、device.login.microsoftonline.com、graph.microsoft.com、graph.windows.net、登录。 microsoft.com、login.microsoftonline.com、login.microsoftonline-p.com、login.windows.net、logincert.microsoftonline.com、loginex.microsoftonline.com、login-us.microsoftonline.com、nexus.microsoftonline-p。 com、passwordreset.microsoftonline.com、provisioningapi.microsoftonline.com
20.190.128.0/18、40.126.0.0/18、2603:1006:2000::/48、2603:1007:200::/48、2603:1016:1400::/48、2603:1017::/48、 2603:1026:3000::/48, 2603:1027:1::/48, 2603:1036:3000::/48, 2603:1037:1::/48, 2603:1046:2000::/48, 2603:1047:1::/48, 2603:1056:2000::/48, 2603:1057:2::/48