快速入门:设置租户Quickstart: Set up a tenant

若要构建使用 Microsoft 标识平台进行标识和访问管理的应用,需要访问 Azure Active Directory (Azure AD) 租户。To build apps that use the Microsoft identity platform for identity and access management, you need access to an Azure Active Directory (Azure AD) tenant. 你可在 Azure AD 租户中注册和管理应用、配置这些应用对 Microsoft 365 和其他 Web API 中数据的访问权限,还可在这里启用条件访问等功能。It's in the Azure AD tenant that you register and manage your apps, configure their access to data in Microsoft 365 and other web APIs, and enable features like Conditional Access.

租户代表组织。A tenant represents an organization. 它是组织或应用开发人员在与 Microsoft 建立关系之初收到的 Azure AD 的专用实例。It's a dedicated instance of Azure AD that an organization or app developer receives at the beginning of a relationship with Microsoft. 例如,可通过注册 Azure、Microsoft Intune 或 Microsoft 365 来开启这种关系。That relationship could start with signing up for Azure, Microsoft Intune, or Microsoft 365, for example.

每个 Azure AD 租户都是独特的,独立于其他 Azure AD 租户。Each Azure AD tenant is distinct and separate from other Azure AD tenants. 它使用自己的工作和学校标识、使用者标识(如果是 Azure AD B2C 租户)和应用注册进行表示。It has its own representation of work and school identities, consumer identities (if it's an Azure AD B2C tenant), and app registrations. 仅可通过你的租户或所有租户中的帐户对你的租户中的应用注册进行身份验证。An app registration inside your tenant can allow authentications only from accounts within your tenant or all tenants.

先决条件Prerequisites

具有活动订阅的 Azure 帐户。An Azure account that has an active subscription. 创建帐户Create an account.

确定环境类型Determining the environment type

可创建两种类型的环境。You can create two types of environments. 环境仅取决于你的应用将进行身份验证的用户类型。The environment depends solely on the types of users your app will authenticate.

本快速入门介绍了你要构建的应用类型的两种适用方案:This quickstart addresses two scenarios for the type of app you want to build:

  • 工作和学校 (Azure AD) 帐户Work and school (Azure AD) accounts
  • 社交和本地 (Azure AD B2C) 帐户Social and local (Azure AD B2C) accounts

工作和学校帐户Work and school accounts

若要为工作和学校帐户生成环境,可使用现有 Azure AD 租户或新建一个租户。To build an environment for work and school accounts, you can use an existing Azure AD tenant or create a new one.

使用现有的 Azure AD 租户Use an existing Azure AD tenant

许多开发人员已通过绑定到 Azure AD 租户的服务或订阅(例如 Microsoft 365 或 Azure 订阅)获得了租户。Many developers already have tenants through services or subscriptions that are tied to Azure AD tenants, such as Microsoft 365 or Azure subscriptions.

若要检查租户:To check the tenant:

  1. 登录 Azure 门户Sign in to the Azure portal. 使用将用于管理应用程序的帐户。Use the account you'll use to manage your application.
  2. 查看右上角。Check the upper-right corner. 如果有租户,则会自动登录。If you have a tenant, you'll automatically be signed in. 你会在帐户名称下直接看到租户名称。You see the tenant name directly under your account name.
    • 将鼠标悬停在帐户名称上可查看你的姓名、电子邮件地址、目录或租户 ID (GUID) 和域。Hover over your account name to see your name, email address, directory or tenant ID (a GUID), and domain.
    • 如果帐户与多个租户相关联,则可以选择帐户名打开一个菜单,并在其中切换租户。If your account is associated with multiple tenants, you can select your account name to open a menu where you can switch between tenants. 每个租户都有自己的唯一租户 ID。Each tenant has its own tenant ID.

提示

如需查找租户 ID,可以:To find the tenant ID, you can:

  • 将鼠标悬停在帐户名称上来获取目录或租户 ID。Hover over your account name to get the directory or tenant ID.
  • 在 Azure 门户中,搜索“Azure Active Directory” > “属性” > “租户 ID”并将其选中 。Search and select Azure Active Directory > Properties > Tenant ID in the Azure portal.

如果没有与帐户关联的租户,那么你的帐户名称下会显示一个 GUID。If you don't have a tenant associated with your account, you'll see a GUID under your account name. 创建 Azure AD 租户之前,你将无法执行注册应用之类的操作。You won't be able to do actions like registering apps until you create an Azure AD tenant.

创建新的 Azure AD 租户Create a new Azure AD tenant

如果还没有 Azure AD 租户,或者想要新建一个来进行开发,请查看在 Azure AD 中创建新租户If you don't already have an Azure AD tenant or if you want to create a new one for development, see Create a new tenant in Azure AD. 或者,使用 Azure 门户中的目录创建体验Or use the directory creation experience in the Azure portal.

你要提供以下信息来创建新租户:You'll provide the following information to create your new tenant:

  • 组织名称Organization name
  • 初始域 - 此域是 *.partner.onmschina.cn 的一部分。Initial domain - This domain is part of *.partner.onmschina.cn. 稍后可对该域进行自定义。You can customize the domain later.
  • 国家或地区Country or region

备注

对租户进行命名时,请使用字母数字字符。When naming your tenant, use alphanumeric characters. 不允许使用特殊字符。Special characters aren't allowed. 名称不得超过 256 个字符。The name must not exceed 256 characters.

社交和本地帐户Social and local accounts

若要开始构建用于登录社交帐户和本地帐户的应用,需要创建一个 Azure AD B2C 租户。To begin building apps that sign in social and local accounts, create an Azure AD B2C tenant. 若要开始,请查看创建 Azure AD B2C 租户To begin, see Create an Azure AD B2C tenant.

后续步骤Next steps

注册应用以与 Microsoft 标识平台集成。Register an app to integrate with Microsoft identity platform.