{"componentChunkName":"component---src-templates-tags-js","path":"/tags/mfa/","result":{"data":{"allMarkdownRemark":{"totalCount":1,"edges":[{"node":{"id":"bc886ff7-fff3-5ff2-a09a-faae6d5eea64","html":"<p>Flexibility is a key part of Azure Active Directory B2C. Use built-in policies to create a login experience in minutes. For more complex scenarios, use our identity experience framework to build custom policies.</p>\n<!--more-->\n<p>This article is one of the two part series I wrote on how to use Azure B2C as your identity manager.</p>\n<p>You can find <a href=\"/blog/2017/08/21/using-azure-b2c-identity-manager-part-2/\">part 2 here.</a></p>\n<p><a href=\"https://github.com/yashints/Angular4AzureB2C\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Full source code on Github.</a></p>\n<p>A while ago I was engaged in a front end project using Asp.Net Core and Angular 2. At some point we decided to integrate our application with Azure B2C as our identity management aka IDM.</p>\n<p>In a nutshell, Azure B2C allows us to let users sign in with their own email address as their username compared to Azure Active Directory (AD) in which you have to have an email with the domain associated with your tenant.</p>\n<p>It also supports social login and multi factor authentication (MFA), learn more about it with <a href=\"https://docs.microsoft.com/en-us/azure/multi-factor-authentication/multi-factor-authentication\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">this short video</a>.</p>\n<p>I am not going to go through all of its features, however you can find enough information <a href=\"https://azure.microsoft.com/en-au/services/active-directory-b2c/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">here</a>.</p>\n<p>In these blog series I will talk about how you can integrate your application into Azure B2C and use some of its features via <a href=\"https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-graph-api\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">GraphAPI</a>.</p>\n<h2 id=\"setup-your-b2c-tenant\" style=\"position:relative;\"><a href=\"#setup-your-b2c-tenant\" aria-label=\"setup your b2c tenant permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Setup your B2C tenant</h2>\n<p>First of all you need to setup a B2C tenant (or more if you have a multi tenant application). There are many good articles on how to set it up, but I used <a href=\"https://docs.microsoft.com/en-us/azure/active-directory-b2c/active-directory-b2c-get-started\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">this</a> from <a href=\"https://www.microsoft.com/en-au\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Microsoft</a> official documentation.</p>\n<h2 id=\"register-your-application\" style=\"position:relative;\"><a href=\"#register-your-application\" aria-label=\"register your application permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Register your application</h2>\n<p>You will need an application in order to talk to the login endpoint provided by Azure B2C. This is very important because this application contains the information about your application such as reply URL. Simply follow <a href=\"https://docs.microsoft.com/en-us/azure/active-directory-b2c/active-directory-b2c-app-registration#navigate-to-b2c-settings\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">this</a> link to set it up. Don’t forget to setup the <strong>scopes</strong> as you might spend hours trying to figure out why you are getting unauthorised error from Azure login endpoint.</p>\n<p>The below picture demonstrates the screen you will need to fill in.</p>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 576px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/b28abea37128d544a09907dc81561ab2/533c1/b2c-new-app-settings.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 112.59259259259258%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAXCAYAAAALHW+jAAAACXBIWXMAABnWAAAZ1gEY0crtAAACT0lEQVR42qWUy27aQBiF51nonk2KFJE+Syqk3LrOK7SvkqpSpOYF2kptpapZtOolEIiCbXzBHt9B4LHH9uk/hEZZRCSEX/o04IHj+c/MGdZqtbDTbqNNvGjv4PnWFhrPGmg01mN7exvNZhNsb38fewcHODg8wuHRK6jvuy9312af/tfpdMCE58K6+INQ11D4HmSSopYg6rWQQqIqK7DcGiG+vEByPUDc70HaNqoCkFm5BhXETKDIcrB0miKMfQQBR+B5cEgwThKoqut6LVQx60cf5yefoP++hEui3PfhE1VV4SnFBu++42z3LcZfexBVvvBhk2KTNEIQeQgDH5xzzOfzzQTd3iXOP3+DNxggSRNIKTcTzPIcspCoybOyLBfeqfE+1NwqFoJ/NRPdoQ5n7EA3TZi0y8ZoBF3XMaJRYRgGTMtEQrufpum9qLmiKMBm0wlS7iImQeQCdTZHvVxNveT/58d5+LOPbreHq6traEMDmqaD2w58spIXNfwl/AFcUSKjo8iSoYUxibjUmq1pcKm9iA54lEtEong03nSGnLpgZUlLuaVcjJVUubyDfJiC7KJsgUVxBJdW5HKK3XgM27GRk7nq+CiTpRJUPlK0VnEbvQltShhFiON4ETk/CCjL8Q30XM0XyxesQv1GvZhNJuniMkhIYD6bYdNiYRjAsiyYjgPDGSMIow2TkgmktMJBOMVHncOfiZur66mCd6+p6k78noLaGGZbHL+6JkFtG3x5sW7Q8tn7Lzh+fYrjN6c4OflAj0rMswxCiLXJ8xz/AHxqp4VTvEgMAAAAAElFTkSuQmCC'); background-size: cover; display: block;\"\n  ></span>\n  <img\n        class=\"gatsby-resp-image-image\"\n        alt=\"New B2C App\"\n        title=\"\"\n        src=\"/static/b28abea37128d544a09907dc81561ab2/533c1/b2c-new-app-settings.png\"\n        srcset=\"/static/b28abea37128d544a09907dc81561ab2/01bf6/b2c-new-app-settings.png 270w,\n/static/b28abea37128d544a09907dc81561ab2/07484/b2c-new-app-settings.png 540w,\n/static/b28abea37128d544a09907dc81561ab2/533c1/b2c-new-app-settings.png 576w\"\n        sizes=\"(max-width: 576px) 100vw, 576px\"\n        style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n        loading=\"lazy\"\n        decoding=\"async\"\n      />\n  </a>\n    </span></p>\n<p>The most important things you will need at the end of these steps are the <strong>application Id</strong> and <strong>secret key</strong> which you will generate on the keys menu. Also make sure the reply URL is pointing to where you handle the login callback (either on client or server side).</p>\n<h2 id=\"setup-mfa\" style=\"position:relative;\"><a href=\"#setup-mfa\" aria-label=\"setup mfa permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Setup MFA</h2>\n<p>The only thing that you cannot do through the new Azure portal is to create the MFA, which you can do via the <a href=\"https://manage.windowsazure.com/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">classic portal</a>. The instructions to setup the MFA can be found here.</p>\n<p>Unfortunately the soft tokens are not available with the default MFA settings (you will need a <a href=\"https://docs.microsoft.com/en-us/azure/multi-factor-authentication/multi-factor-authentication-get-started\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">MFA server</a>), but you can use SMS or email verification.</p>\n<h2 id=\"create-your-policies\" style=\"position:relative;\"><a href=\"#create-your-policies\" aria-label=\"create your policies permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Create your policies</h2>\n<p>The authentication flows are handled by <a href=\"https://docs.microsoft.com/en-us/azure/active-directory-b2c/active-directory-b2c-reference-policies\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">policies</a> on Azure B2C. There are some default policies you can setup and use or you can opt in to use custom policies which give you more options but are harder to manage.</p>\n<p>You can simply get started by using one of sign-in or sign-up policies. This <a href=\"https://docs.microsoft.com/en-us/azure/active-directory-b2c/active-directory-b2c-reference-policies\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">article</a> shows you how to set one up. Next you can setup a <a href=\"https://docs.microsoft.com/en-us/azure/active-directory-b2c/active-directory-b2c-reference-policies#create-a-password-reset-policy\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">password reset policy</a> if you want to allow users to reset their passwords.</p>\n<p>After you setup the policies you can check the metadata endpoint by hitting metadata URL (replace the tenant and policy with yours):</p>\n<div class=\"custom-block info\"><div class=\"custom-block-body\"> <a href=\"https://login.microsoftonline.com/your-tenant-domain-qualifier/v2.0/.well-known/openid-configuration?p=your-policy-name\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">https://login.microsoftonline.com/your-tenant-domain-qualifier/v2.0/.well-known/openid-configuration?p=your-policy-name</a></div></div>\n<p>You can find the same link at the bottom of the policy details page where you can test the policy alone.</p>\n<h2 id=\"configurations-and-customisations\" style=\"position:relative;\"><a href=\"#configurations-and-customisations\" aria-label=\"configurations and customisations permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Configurations and customisations</h2>\n<p>There are some default settings for token, session and single sign-on configuration, which you can use. However, if you have some requirement which force you to customise these settings, <a href=\"https://docs.microsoft.com/en-us/azure/active-directory-b2c/active-directory-b2c-token-session-sso\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">this link</a> contains the required information.</p>\n<h2 id=\"authorisation-flow\" style=\"position:relative;\"><a href=\"#authorisation-flow\" aria-label=\"authorisation flow permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Authorisation flow</h2>\n<p>So far we saw how to setup the B2C to get it to a point where you can use it in your application. At this point you will need to follow three simple steps to successfully authenticate someone.</p>\n<ol>\n<li>Get an authorization code</li>\n<li>Get a token</li>\n<li>Use the token</li>\n</ol>\n<p>You can also refresh the token if you want, and before you think of these terms I have to say yes these are all part of OAuth 2.0 authorisation code flow.</p>\n<p>In the next blog post I will show you some code and samples which will help you integrate your application and also use some of the features that are available only via GraphAPI.</p>","timeToRead":3,"frontmatter":{"title":"Using Azure B2C as your identity manager (Part 1)","unformattedDate":"2017-08-16T00:00:00.000Z","date":"Aug 16, 2017","path":"using-azure-b2c-identity-manager-part-1/","author":"Yaser Adel Mehraban","tags":["angular 2","aspnetcore","authentication","azure","b2c","idm","mfa"],"thumbnail":{"childImageSharp":{"gatsbyImageData":{"layout":"constrained","placeholder":{"fallback":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAADiUlEQVR42pWUWW8bVRiGfdG/wmV/Q4QggELktI63ZLylUMSmXoFUEKiVegM/AC4AUVRVYin1Fq/jhnRJVCoRILE9jsf2LE6cJt5qvNuZmZdvEkdKaF2aI41GmnP0zHPe7zvHYBgzJpaXz+jv+VDmZUc4W3KEN2vMYsZ4OIczhtOMI5g9kHrDnZA6TlYAE8vDc0fetwfSVn3uymjNKWAbk+6E2LZH8nBHRPVCVFJtYV5zs9JwPsCZXsj0pJnYmYvkcPleUeGrmxDqHK6ubKm2EK+5EvK+ZWQ6Mc70uJmLFdsLrIgZX1L15rpYl5xYE4yIi20Yb6c0F22fiUtD2zjT42YuMnPFCqAiKJYgh+/+LKPcXEOl+Tt+TFZhCWZgX8yoTCSnMaz0tOl/M1ugAhBMtYeyuHZfxFcPZZSafdS6Q3z9sIgvViQCZnWodvBjVjxmOoIeVXOOCmD0pRUzWeiwG39s4/14DnytTdAe3o3l8D19+5Kg+pqp2ynVvMhrDt3Ue2hqsPnWX/Ho1Yzm8fFdWY0IA/ywXsW3j4r4aKmAcz4OwpMedtsDzPgzuJTI4xuau/53BRFxgE/vbWnmEE+m0tAaTJ8zuFmxQEWAJyoo2WoOqeIcdhuruLa6R3mlYSWTAgEfE9Aa3ISJcr18d4fW/IUN+TyE2gbeihVVe0SHinWDixVEerAQFQnIIylbsNN4gA/ulCgnDpZABvkR0EJAG31zR4vYbqwR0EjttI63dWCYgHGpYWCC3Gu05a6deu6T+0U1VOhhp6XiN7mOWYKZ/IeGuyPDaS8HH19BuaMhIvTx+YNtzbyY1ZysqNj9KfNBjtT5056E3NOhb3rTyjtUiEpngCW5gVd/SSJXb+Fxq4vJW0l4+Sqag318SPm+fksvCsESsmL1p5gTbTPn25iiPLsXaPuWAKcuRHnskVWk8IS23EepNcSv2Roa/X28R4WZ8aU1dyx/YGbzpW3P7EXd1MXKPU+8gPN+TrlIpnsdBcXaTxArN/FPX8ElMiOY6ojl1fm4pB6ZTVxZfvZp0U2dcaHrpKY1+Xn1UamEJe4s4qmXkCxvUY45zRGlJ37cDM8/z9T5004ynaX+up6sKLVWDPVWCD9nqups8GRmT5mNg1p96SkmJnYt4Tw+WymrV1erqiVE51c3C/6P2fNMGTI1h3Mw0fl1nMZs7HUW5ieZULY8H842bS9wsf4L4xQxdlKVJ9kAAAAASUVORK5CYII="},"backgroundColor":"transparent","images":{"fallback":{"src":"/static/a48f145fa949a39d816306c94c6831f8/be182/b2c.png","srcSet":"/static/a48f145fa949a39d816306c94c6831f8/be182/b2c.png 150w","sizes":"(min-width: 150px) 150px, 100vw"},"sources":[{"srcSet":"/static/a48f145fa949a39d816306c94c6831f8/5d458/b2c.webp 150w","type":"image/webp","sizes":"(min-width: 150px) 150px, 100vw"}]},"width":150,"height":150}}}}}}]}},"pageContext":{"tag":"mfa"}},"staticQueryHashes":[],"slicesMap":{}}