Managing external identities to enable secure access for partners, customers, and other non-employees
3,929 questions with Microsoft Security | Microsoft Entra | Microsoft Entra External ID tags
Microsoft Entra External ID – email claim not included in ID token from User Flow
I am using Microsoft Entra External ID (customer tenant) and I am unable to get the email claim in the ID token returned by a User Flow. Problem The ID token does not contain the email claim. This happens for both: Local accounts (Email with password) …
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
How to distinguish OTP requests types to send different email templates?
How to get these different "request types" in my OTP payload? "authenticationContext": { "requestType": "signUp" | "signIn" | "passwordReset" When I trigger the "reset password"…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Entra External ID - How to replace ciamlogin.com with custom domain while keeping Google and Facebook social login working
We are using Microsoft Entra External ID (CIAM) with Google and Facebook configured as social identity providers. Current behaviour: When users click "Sign in with Google", the Google sign-in page shows "Sign in to continue to…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Lost Access to Entra External ID Tenant, how to recover?
Hello, Recently I have been unable to log into an Entra External ID tenant under my subscription in Azure. When prompted for MFA, it rejects the codes from my Microsoft Authenticator app. When trying the send notification to authenticator option, it does…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Entra External ID Native Authentication - OTP not invalidated after resend on signup and SSPR flows
We are using Microsoft Entra External ID native authentication API for a customer-facing web application using the email with password authentication method. Issue: After calling /signup/v1.0/challenge again on the same continuation token to resend a new…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Locking / Unlocking Accounts after multiple failed attempts
I am using Native Authentication to Sign In to my application by calling these endpoints: https://<tenant>/oauth2/v2.0/initiate https://<tenant>/oauth2/v2.0/challenge https://<tenant>/oauth2/v2.0/token Is there a way to 'lock' the…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Tenant lockout / lost Global Administrator access.
Please route this case to the Microsoft Data Protection / Tenant Recovery team. I cannot sign in with my admin account to my Microsoft Entra External ID tenant. There is no other Global Administrator available. Can't open support ticket :-(
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Invitations are blocked for my tenant.
Forbidden({"error":{"code":"Forbidden","message":"Invitations are blocked for this directory due to suspicious activity. Please contact Microsoft support for help."}}) Can I get my tenant reviewed and the…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Entra External ID: OTP Verify button hangs indefinitely when invalid or empty code is submitted
On the OTP from Email verification page, clicking the "Verify" button with either an empty input or non-numeric characters causes the button to enter a permanent loading state with no error message shown and no way to recover without refreshing…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Global Admin cannot invite guest users – “Insufficient privileges”
I am a Global Administrator in our Microsoft Entra tenant. All guest invitations are failing with the message: “User invitation failed. Insufficient privileges to complete the operation.” This occurs for all users and all invite methods. This started…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Entra External ID forgot password page shows contradictory password complexity requirements
We are seeing contradictory password complexity guidance on the Microsoft-hosted Entra External ID forgot password / reset password page. On the same reset password screen, the static requirement text says: “Use at least 8 characters. The password is…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Invitations are blocked for this directory due to suspicious activity
We have encountered an issue where we are unable to invite any new B2B users to our Azure tenant. Seems to be a security mechanism that has kicked in automatically after we invited 8 external users in 20 minutes. Response from the API: Entra External ID:…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Entra External ID - Native Authentication - Refresh Token - AADSTS9002326: Cross-origin token redemption is permitted only for the 'Single-Page Application' client-type
Got the following error when refreshing the access token in /oauth2/v2.0/token: { "error": "invalid_request", "error_description": "AADSTS9002326: Cross-origin token redemption is permitted only for the…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Okta as OIDC based external identity provider in Microsoft Entra External ID: provider not appearing on login screen
Environment / context Microsoft Entra External ID (External ID) as the CIAM provider for our tenant Okta configured as an OpenID Connect (OIDC) external identity provider in the External ID tenant Created an External ID user flow and added Okta as a…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Entra External ID (PKCE) – Forgot Password “Resend Code” Causes Infinite Loading
Hi, I’m working on a React-based application using Azure Entra External ID with the PKCE user flow for authentication. During the login process, I clicked on the “Forgot password” link and selected email verification. I received the verification code…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Unable to access Azure AD B2C tenant after phone reset – MFA configured on old device
Hello Team, I am unable to access my Azure AD B2C tenant because Multi-Factor Authentication (MFA) is still linked to my old mobile device. Recently, I reset/replaced my phone, and the Microsoft Authenticator app configuration was lost. Now, whenever I…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Invitations are blocked for this directory due to suspicious activity
We have encountered an issue where we are unable to invite any new B2B users to our Azure tenant. Seems to be a security mechanism that has kicked in automatically due to increased activity. Response from the API: Entra External ID: Invitations are…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
B2B guest accounts from specific domain blocked with error 530035 — "Invitations blocked due to suspicious activity"
Title: B2B guest accounts from specific domain blocked with error 530035 — "Invitations blocked due to suspicious activity" Description: Guest accounts from one external domain (transferonline.com) cannot sign in to our Azure Static Web Apps…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
Microsoft Entra External Microsoft SSO sign in page
Hello, We are using Microsoft Entra External as an identity provider. We use the Google and Apple identity providers in our user flow and these are working fine. However for the Microsoft sign in flow we have a couple of questions: Custom background …
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees
B2C SAML Metadata Cache of PartnerEntity Duration
Hello, I have been unable to determine how long does B2C cache the SAML metadata for any external IDP defined by the 'PartnerEntity' property before fetching for changes. I am specifically looking for: How long is the SAML metadata cached for the…
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Managing external identities to enable secure access for partners, customers, and other non-employees