Microsoft Entra External ID
Authentication

Add OIDC for customer sign-in

In brief

Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

What Entra admins need to know

Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Known limitations

Issuer URI updates

Conditional Access policies that require MFA registration don't function as expected whenWhen you update the Issuer URI for an External ID tenant is federated with an externalexisting OIDC identity provider (IdP). This can result, the updated configuration might not automatically take effect in one ofuser flows. As a result, the following behaviors:IdP sign-in option might not appear on the sign-in page.

    To apply the change:

    1. Users are unable to register an MFA method and can't complete sign-in, often encountering an error.Disable the IdP in the user flow.
    2. Users aren't redirected toSave the MFA registration (sign-up)user flow.
    3. Re-enable the IdP.
    4. Save the user flow during sign-in as expected.again.

Related content

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…