As mentioned here, you can use Azure AD Apps for the Client Credential Flow for Service Accounts. It is not optimal but it works.
- Define an Azure AD App for the Web API
- Define an Azure AD App per Service Account
- Configure the Web API to accept tokens from your B2C Tenant and Azure AD
- Request an access token against the Service Account AD App for the Web API
Note: be sure to create the Azure AD Apps under your B2C Tenant.
Code Snippet to get an Access Token from C#
using (var httpClient = new HttpClient())
httpClient.BaseAddress = new Uri("");
var content = new FormUrlEncodedContent(new[]
new KeyValuePair<string, string>("grant_type", "client_credentials")
, new KeyValuePair<string, string>("client_id", "[service account app id e.g. 10d635e5-7615-472f-8200-a81d5c87c0ca")
, new KeyValuePair<string, string>("client_secret", "[client secret defined in the service account e.g. 5L2ZJOBK8GI1wRSgGFooHcBkAOUOj65lQd9DgJxQOrw=]")
, new KeyValuePair<string, string>("scope", "[App ID URI of the web api azure ad app]/.default e.g.")
var requestResult = await httpClient.PostAsync("/[your b2c tenant]", content);
var contentResult = await requestResult.Content.ReadAsStringAsync();
var json = JObject.Parse(contentResult);
var accessToken = (string)json["access_token"];
You will probably want to define some custom claim(s) to secure the Web API. See 'Application Permissions' here.
Modify the application manifest on the Web API Azure AD App
"appRoles": [{
"allowedMemberTypes": [
"displayName": "Some display nane",
"id": "[create a new guid]",
"isEnabled": true,
"description": "Allow the application to _____ as itself.",
"value": "the-blah-role"
Grant the Service Account Azure AD App permission to the custom application permission(s) defined
The permissions granted to the service account will come back in the roles
"roles": [
Please upvote the user voice feedback item to make this easier 😀