B2C wildcards in redirect uri?

JL 51 Reputation points
2021-10-09T07:13:48.237+00:00

Hi,

We are looking to migrate our platform to b2c.

Each of our customer are allocated their own subdomain,
eg, disney.finance.mycompany.com, atlassian.finance.mycompany.com

We have about 500 such subdomains/customers to date.

In our previous provider, we configure the app redirect to accept wildcard for our subdomain: *.finance.mycompany.com

How can we achieve the same thing with b2c?

I have tried to modify the manifest file for the application, but it doesn't work.

thanks

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. soumi-MSFT 11,831 Reputation points Microsoft Employee Moderator
    2021-10-09T15:49:15.697+00:00

    @JL , Wildcard redirect uris are something that are not supported by AAD or AAD B2C. One of the reasons behind this restriction is the security threat called Open Redirector. You can read more about this threat here:
    https://www.rfc-editor.org/rfc/rfc6819#section-4.1.5
    https://www.rfc-editor.org/rfc/rfc6819#section-4.2.4

    You can find the mitigation steps mentioned here: https://www.rfc-editor.org/rfc/rfc6819#section-5.2.3.5

    Also, you can check the following url to understand the various restrictions that are imposed on the redirect uris in AAD and AAD B2C: https://learn.microsoft.com/en-us/azure/active-directory/develop/reply-url#maximum-number-of-redirect-uris

    You can certainly add all the subdomains as a separate Redirect URI, but then that too has a limit of 256 redirect uris as listed here: https://learn.microsoft.com/en-us/azure/active-directory/develop/reply-url#maximum-number-of-redirect-uris


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.