External ID (CIAM): local email+password sign-ins for some users no longer validated in our tenant; admin password resets ineffective

Darrell Draney 0 Reputation points
2026-07-24T18:35:30.7333333+00:00

Since mid-July 2026, a growing subset of customers in our Entra External ID tenant, specifically local email+password accounts whose email domain is verified in another Entra tenant, can no longer sign in. Failed attempts produce no sign-in log entries in our tenant, and the error page renders the home tenant's company branding instead of ours. One affected user's password was admin-reset three times in one afternoon (audit-confirmed) and still could not sign in, with zero sign-in log entries that day. A control account on the same email domain that exists only in our tenant logs failures normally; the affected account, which also exists in its home tenant, logs nothing, so the behavior is per-user. Our tenant has no federation configured (built-in Email+password/OTP only) and no configuration changes in the audit log. We also hold cross-tenant sign-in log evidence I can share privately. Has a home-realm-discovery or sign-in rollout changed how External ID local accounts on foreign-verified domains are validated (~July 15-21)? We need this tenant exempted/rolled back. I have tenant IDs, object IDs, correlation IDs, and timestamps ready for a private channel if needed.

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
0 comments No comments

2 answers

Sort by: Most helpful
  1. pogula kavitha 0 Reputation points
    2026-07-31T03:23:08.1933333+00:00

    Yes,Iwnt to use quiziz

    Was this answer helpful?

    0 comments No comments

  2. Jerald Felix 18,200 Reputation points Volunteer Moderator
    2026-07-31T02:00:10.1+00:00

    Hello Darrell Draney ,

    Greetings! Thanks for raising this question in Q&A forum.

    Based on the symptoms you described, the most likely cause is a change in Home Realm Discovery (HRD) or sign-in routing behavior for email domains that are verified in another Microsoft Entra tenant. The key indicator is that affected users are being directed to the home tenant branding and no sign-in logs are generated in your External ID tenant, which suggests the authentication request may not be reaching your tenant at all.

    1. Verify whether the affected accounts are local identities in your External ID tenant and whether the same email address also exists as a member or guest account in another Entra tenant.
    2. Compare the affected users with the working control account and confirm whether the only difference is the existence of a corresponding account in another tenant using the same verified domain.
    3. Collect the correlation IDs, timestamps, tenant IDs, and screenshots showing the unexpected home-tenant branding during sign-in.
    4. Open a Microsoft support request and provide the collected evidence, including the cross-tenant sign-in logs you mentioned. Because authentication requests are not appearing in your tenant logs, backend investigation is required to determine whether a recent HRD or authentication routing change is affecting External ID local accounts.
    5. Request the support engineer to validate whether there are any known service changes or regressions introduced around July 15-21, 2026, impacting External ID local email/password accounts whose domains are verified in another tenant.

    At this stage, the next action belongs to Microsoft Support/Product Engineering. Forum-level troubleshooting is limited because the authentication flow appears to be diverted before your tenant receives the sign-in request. The engineering team will need to review backend authentication and routing logs using the correlation IDs you already have available.

    If this answer helps you kindly accept the answer which will help others who have similar questions

    Best Regards,

    Jerald Felix.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.