3,929 questions with Microsoft Security | Microsoft Entra | Microsoft Entra External ID tags

Sort by: Updated
1 answer

Microsoft Entra External ID – email claim not included in ID token from User Flow

I am using Microsoft Entra External ID (customer tenant) and I am unable to get the email claim in the ID token returned by a User Flow. Problem The ID token does not contain the email claim. This happens for both: Local accounts (Email with password) …

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-15T20:31:47.7566667+00:00
Alexandre Giuseppe 41 Reputation points
commented 2026-05-15T23:42:23.3866667+00:00
Sridevi Machavarapu 30,110 Reputation points Microsoft External Staff Moderator
1 answer

How to distinguish OTP requests types to send different email templates?

How to get these different "request types" in my OTP payload? "authenticationContext": { "requestType": "signUp" | "signIn" | "passwordReset" When I trigger the "reset password"…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-07T14:44:15.0933333+00:00
Jinki Lee 85 Reputation points
commented 2026-05-15T19:21:16.25+00:00
VEMULA SRISAI 13,025 Reputation points Microsoft External Staff Moderator
1 answer

Entra External ID - How to replace ciamlogin.com with custom domain while keeping Google and Facebook social login working

We are using Microsoft Entra External ID (CIAM) with Google and Facebook configured as social identity providers. Current behaviour: When users click "Sign in with Google", the Google sign-in page shows "Sign in to continue to…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-15T17:17:29.5366667+00:00
Ashok Kumar Busi 1 Reputation point
commented 2026-05-15T18:05:13.5766667+00:00
Sridevi Machavarapu 30,110 Reputation points Microsoft External Staff Moderator
0 answers

Lost Access to Entra External ID Tenant, how to recover?

Hello, Recently I have been unable to log into an Entra External ID tenant under my subscription in Azure. When prompted for MFA, it rejects the codes from my Microsoft Authenticator app. When trying the send notification to authenticator option, it does…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-02-12T20:24:46.93+00:00
Zach Cash 5 Reputation points
commented 2026-05-15T16:57:01.88+00:00
kagiyama yutaka 2,590 Reputation points
2 answers

Entra External ID Native Authentication - OTP not invalidated after resend on signup and SSPR flows

We are using Microsoft Entra External ID native authentication API for a customer-facing web application using the email with password authentication method. Issue: After calling /signup/v1.0/challenge again on the same continuation token to resend a new…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-15T09:12:55.9133333+00:00
Ashok Kumar Busi 1 Reputation point
edited an answer 2026-05-15T16:21:58.36+00:00
Rukmini 40,135 Reputation points Microsoft External Staff Moderator
1 answer

Locking / Unlocking Accounts after multiple failed attempts

I am using Native Authentication to Sign In to my application by calling these endpoints: https://<tenant>/oauth2/v2.0/initiate https://<tenant>/oauth2/v2.0/challenge https://<tenant>/oauth2/v2.0/token Is there a way to 'lock' the…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-12T15:45:55.9033333+00:00
Jinki Lee 85 Reputation points
commented 2026-05-15T14:27:32.4233333+00:00
VEMULA SRISAI 13,025 Reputation points Microsoft External Staff Moderator
1 answer

Tenant lockout / lost Global Administrator access.

Please route this case to the Microsoft Data Protection / Tenant Recovery team. I cannot sign in with my admin account to my Microsoft Entra External ID tenant. There is no other Global Administrator available. Can't open support ticket :-(

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-15T07:57:58.5+00:00
Simon Schmitt 0 Reputation points
commented 2026-05-15T13:34:25.3433333+00:00
Simon Schmitt 0 Reputation points
1 answer

Invitations are blocked for my tenant.

Forbidden({"error":{"code":"Forbidden","message":"Invitations are blocked for this directory due to suspicious activity. Please contact Microsoft support for help."}}) Can I get my tenant reviewed and the…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-15T04:27:34.42+00:00
Mark 0 Reputation points
commented 2026-05-15T04:59:22.61+00:00
Shubham Sharma 15,340 Reputation points Microsoft External Staff Moderator
1 answer

Entra External ID: OTP Verify button hangs indefinitely when invalid or empty code is submitted

On the OTP from Email verification page, clicking the "Verify" button with either an empty input or non-numeric characters causes the button to enter a permanent loading state with no error message shown and no way to recover without refreshing…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-04-08T11:49:43.93+00:00
Longlands, Dylan 5 Reputation points
commented 2026-05-14T22:16:20.5966667+00:00
RoryB 540 Reputation points
1 answer One of the answers was accepted by the question author.

Global Admin cannot invite guest users – “Insufficient privileges”

I am a Global Administrator in our Microsoft Entra tenant. All guest invitations are failing with the message: “User invitation failed. Insufficient privileges to complete the operation.” This occurs for all users and all invite methods. This started…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-07T19:24:23+00:00
ImmersiveEventNewbie 25 Reputation points
commented 2026-05-14T19:39:45.9666667+00:00
ImmersiveEventNewbie 25 Reputation points
0 answers

Entra External ID forgot password page shows contradictory password complexity requirements

We are seeing contradictory password complexity guidance on the Microsoft-hosted Entra External ID forgot password / reset password page. On the same reset password screen, the static requirement text says: “Use at least 8 characters. The password is…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-14T16:44:08.0666667+00:00
DP 0 Reputation points
commented 2026-05-14T16:59:37.9866667+00:00
Sridevi Machavarapu 30,110 Reputation points Microsoft External Staff Moderator
2 answers

Invitations are blocked for this directory due to suspicious activity

We have encountered an issue where we are unable to invite any new B2B users to our Azure tenant. Seems to be a security mechanism that has kicked in automatically after we invited 8 external users in 20 minutes. Response from the API: Entra External ID:…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-08T06:54:13.85+00:00
JEEH 0 Reputation points
answered 2026-05-14T05:15:51.0366667+00:00
Shubham Sharma 15,340 Reputation points Microsoft External Staff Moderator
1 answer One of the answers was accepted by the question author.

Entra External ID - Native Authentication - Refresh Token - AADSTS9002326: Cross-origin token redemption is permitted only for the 'Single-Page Application' client-type

Got the following error when refreshing the access token in /oauth2/v2.0/token: { "error": "invalid_request", "error_description": "AADSTS9002326: Cross-origin token redemption is permitted only for the…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-11T13:59:05.34+00:00
HA 25 Reputation points
edited an answer 2026-05-13T16:46:29.7+00:00
Rukmini 40,135 Reputation points Microsoft External Staff Moderator
1 answer One of the answers was accepted by the question author.

Okta as OIDC based external identity provider in Microsoft Entra External ID: provider not appearing on login screen

Environment / context Microsoft Entra External ID (External ID) as the CIAM provider for our tenant Okta configured as an OpenID Connect (OIDC) external identity provider in the External ID tenant Created an External ID user flow and added Okta as a…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-03T09:59:03.9866667+00:00
Anuj Sharma 20 Reputation points
edited an answer 2026-05-13T09:12:47.82+00:00
Rukmini 40,135 Reputation points Microsoft External Staff Moderator
1 answer

Entra External ID (PKCE) – Forgot Password “Resend Code” Causes Infinite Loading

Hi, I’m working on a React-based application using Azure Entra External ID with the PKCE user flow for authentication. During the login process, I clicked on the “Forgot password” link and selected email verification. I received the verification code…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-02-13T06:33:55.2266667+00:00
Sachin More 5 Reputation points
commented 2026-05-13T05:54:37.4266667+00:00
Vihaan Yagnik 0 Reputation points
1 answer

Unable to access Azure AD B2C tenant after phone reset – MFA configured on old device

Hello Team, I am unable to access my Azure AD B2C tenant because Multi-Factor Authentication (MFA) is still linked to my old mobile device. Recently, I reset/replaced my phone, and the Microsoft Authenticator app configuration was lost. Now, whenever I…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-12T06:50:05.2533333+00:00
commented 2026-05-13T05:35:10.97+00:00
Shubham Sharma 15,340 Reputation points Microsoft External Staff Moderator
0 answers

Invitations are blocked for this directory due to suspicious activity

We have encountered an issue where we are unable to invite any new B2B users to our Azure tenant. Seems to be a security mechanism that has kicked in automatically due to increased activity. Response from the API: Entra External ID: Invitations are…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-03-11T10:47:59.5866667+00:00
Carl Schmidt 25 Reputation points
edited a comment 2026-05-13T03:54:05.1366667+00:00
VEMULA SRISAI 13,025 Reputation points Microsoft External Staff Moderator
0 answers

B2B guest accounts from specific domain blocked with error 530035 — "Invitations blocked due to suspicious activity"

Title: B2B guest accounts from specific domain blocked with error 530035 — "Invitations blocked due to suspicious activity" Description: Guest accounts from one external domain (transferonline.com) cannot sign in to our Azure Static Web Apps…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-03-30T19:23:18.2966667+00:00
Dylan Levsey 0 Reputation points
commented 2026-05-12T14:16:17.67+00:00
Turja Chowdhury 0 Reputation points
2 answers

Microsoft Entra External Microsoft SSO sign in page

Hello, We are using Microsoft Entra External as an identity provider. We use the Google and Apple identity providers in our user flow and these are working fine. However for the Microsoft sign in flow we have a couple of questions: Custom background …

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-08T13:06:22.6566667+00:00
Lisa 40 Reputation points
commented 2026-05-12T12:27:24.0833333+00:00
VEMULA SRISAI 13,025 Reputation points Microsoft External Staff Moderator
1 answer

B2C SAML Metadata Cache of PartnerEntity Duration

Hello, I have been unable to determine how long does B2C cache the SAML metadata for any external IDP defined by the 'PartnerEntity' property before fetching for changes. I am specifically looking for: How long is the SAML metadata cached for the…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-05-11T14:52:53.95+00:00
Eric Baines 0 Reputation points
answered 2026-05-11T15:13:17.15+00:00
Rukmini 40,135 Reputation points Microsoft External Staff Moderator