Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To add Azure AD sign-in or token validation to ASP.NET Core, first match your app to the right identity scenario, then configure a Microsoft Entra app registration and use Microsoft.Identity.Web. A browser-based web app that signs users in and a Web API that accepts bearer tokens need different setup; an app that calls another API also needs token acquisition and a suitable token cache.

Azure Active Directory is now called Microsoft Entra ID, but “Azure AD” remains common in older configuration names and searches. Microsoft’s ASP.NET Core authentication guidance separates web-app sign-in, protected APIs, and downstream API access. Use the matching pattern rather than combining snippets from different scenarios.

Choose the ASP.NET Core identity scenario

Before adding packages or copying code, identify what the app does and who will use it. Microsoft.Identity.Web provides the integration library family for Microsoft identity platform authentication and authorization, including Entra ID.

Application need Typical authentication pattern What to configure
Web app signs users in Interactive OpenID Connect sign-in, with an app session Microsoft.Identity.Web web-app setup and an Entra app registration
Web app signs users in and calls a protected API Interactive sign-in plus downstream token acquisition Web-app setup, API permissions, and a token cache
Web API accepts access tokens JWT bearer-token validation Microsoft.Identity.Web API setup, exposed permissions, and authorization rules
API calls another protected API API authentication plus downstream token acquisition Permissions and a token-acquisition design appropriate to the caller context

Choose the audience as well: an organization’s workforce tenant and an external/customer tenant have different registration and sign-in considerations. Microsoft’s preparation tutorial covers workforce and external tenant contexts; its scenario index links the distinct ASP.NET Core patterns.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prepare the tenant and app registration

Entra ID is the identity provider; an app registration tells it which application is requesting sign-in or tokens and which platform behavior and permissions apply. Collect the registration details before wiring up the app: authority instance, tenant ID, client ID, and the relevant platform and callback settings. Microsoft.Identity.Web’s configuration overview shows settings-file configuration using an AzureAd section with Instance, TenantId, and ClientId. The section name is a configuration convention, not evidence that the current product name is still Azure AD.

Follow the prerequisite for the specific Microsoft tutorial you use rather than assuming a single universal minimum. The web-app preparation tutorial lists the .NET 8.0 SDK as its minimum prerequisite, while the web-app sign-in quickstart lists the .NET 9 SDK. The API quickstart also lists .NET 9; Microsoft’s API security tutorial specifies .NET 8.0 SDK or later.

Configure a web app that signs users in

For an interactive web app, use the web-app pattern in Microsoft’s sign-in quickstart. It supports either creating a project with authentication configured or adding Microsoft.Identity.Web to an existing app. The existing-app path uses Microsoft.Identity.Web; Microsoft.Identity.Web.UI is optional when you need the library’s UI components. Register authentication with AddMicrosoftIdentityWebApp and the application configuration.

A minimal registration shape, following that pattern, is:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
builder.Services.AddAuthentication(OpenIdConnectDefaults.AuthenticationScheme)
    .AddMicrosoftIdentityWebApp(builder.Configuration.GetSection("AzureAd"));

Ensure the registration values and platform callback settings match the app’s deployment and the redirect URI registered with Entra ID. A mismatch commonly prevents the sign-in response from returning to the application as intended.

If this web app only signs users in, downstream token acquisition is not required. Add it when the app must call a protected API on a user’s behalf; use the quickstart’s corresponding token-acquisition configuration rather than adding unrelated API snippets.

Configure a protected Web API

A Web API validates bearer access tokens; it does not use the same interactive sign-in setup as a server-rendered web app. Microsoft’s API quickstart uses AddMicrosoftIdentityWebApi for JWT bearer authentication, then authentication and authorization middleware and [Authorize] to protect endpoints.

builder.Services
    .AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
    .AddMicrosoftIdentityWebApi(builder.Configuration.GetSection("AzureAd"));

app.UseAuthentication();
app.UseAuthorization();

Apply [Authorize] to controllers or actions that require a valid authenticated caller. Token validation alone does not define which callers may perform which operations: align the API’s configured audience, the permissions it exposes, and the permissions granted to each calling client. Add authorization policies or permission checks that reflect what each endpoint is allowed to do. Microsoft’s API security tutorial walks through building and securing an ASP.NET Core API.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the API permission model

The permission model depends on whether a user is present in the call. Microsoft’s API tutorial describes delegated permissions as scopes and application permissions as app roles.

Permission type Use when What the API/client configuration represents
Delegated permission A signed-in user’s context is part of the request Scopes: permissions the client requests for a user-context call
Application permission A client calls without a signed-in user App roles: permissions assigned to an application identity for app-only access

Expose and grant the permissions the scenario requires, then enforce them in the API. A token being valid for the API is not by itself proof that its caller has the authorization needed for a particular operation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Add downstream API calls and choose a token cache

When a web app calls another protected API, it needs to acquire a token for that downstream resource in the correct user context. Configure the downstream API and permissions using the relevant web-app quickstart guidance; do not treat ordinary sign-in as if it automatically grants access to another API.

The quickstart uses an in-memory token cache for demonstration and recommends a distributed cache in production. The distinction matters in deployments that restart or run multiple app instances: an in-memory cache belongs to an individual process and does not provide shared cache durability across instances. Select and configure a distributed cache that fits the deployment rather than promoting the sample cache unchanged.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep Entra ID separate from ASP.NET Core Identity

Microsoft Entra ID is an external identity provider that authenticates users or applications for your app. ASP.NET Core Identity is a separate framework for application-owned local accounts and related login UI. Microsoft explicitly states that the Microsoft identity platform is not related to ASP.NET Core Identity in its ASP.NET Core Identity overview.

Use the Entra integration when users authenticate through a configured tenant. Use ASP.NET Core Identity when your application needs to manage its own local account system. They address different account and authentication models; adding one does not automatically configure the other.

Customize only what the scenario needs

Microsoft.Identity.Web supplies defaults and extension points for options, events, claims, UI, and token acquisition. Start with the documented scenario and customize only where the application needs different behavior. Microsoft’s customization guidance, last updated April 29, 2026, describes those extension points; avoid replacing library behavior without understanding the security consequences.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.