Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Why does “signInAudience”: “AzureADMultipleOrgs” cause 'The URI scheme is invalid or unsupported'

I am getting an error when trying to switch the Supported account types to: Accounts in any organizational directory (Any Azure AD directory - Multitenant)

I am using as IdentifierUris the amazon cognito urn:amazon:cognito:sp:XXXXXXXXXXX

enter image description here

like image 431
Said Rahmani Avatar asked Sep 20 '25 18:09

Said Rahmani


1 Answers

For a single tenant application, it is sufficient for the App ID URI to be unique within that tenant.

For a multi-tenant application, it must be globally unique so Azure AD can find the application across all tenants. Global uniqueness is enforced by requiring the App ID URI to have a host name that matches a verified domain of the Azure AD tenant.

If the name of your tenant was contoso.onmicrosoft.com then a valid App ID URI would be https://contoso.onmicrosoft.com/myapp. If your tenant had a verified domain of contoso.com, then a valid App ID URI would also be https://contoso.com/myapp. If the App ID URI doesn’t follow this pattern, setting an application as multi-tenant fails.

like image 74
Tony Ju Avatar answered Sep 22 '25 07:09

Tony Ju