Federated Google Login - Microsoft Entra External ID

Wistedt, Carl 60 Reputation points
2025-06-01T19:21:34.5266667+00:00

Hi,

I have setup an "Entra External Id" and federated login to google. I works all fine from my SPA application. But after like a day or so when i open my app again and i think the tokens needs to refresh it goes:

My App -> Ciam Login -> Google

But it gets stuck showing "parameter not allowed for this message type: username"
I can just hit F5 and then it works. But i would like to know why this hapens and if this is something i need to fix on my end or if there are some config i forgot in Azure or maybe a bugg in Azure Entra Extenal Id.

Screenshot_20250528-080819_Chrome-EDIT

Microsoft Security | Microsoft Entra | Microsoft Entra External ID

Answer accepted by question author
Antonio Gazzeri 85 Reputation points
2025-06-23T14:42:18.6133333+00:00

Hello,

Just in case it helps others, I implemented the workaround advised above by Rukmini in my .Net Core 9 c# Razor Pages web app by adding an options.Events.OnRedirectToIdentityProvider handler to AddMicrosoftIdentityWebApp, and it works. However, of course the user experience is degraded as there is no silent login even when the token would still be valid. Any updates on getting a proper fix for this?

builder.Services.AddAuthentication(OpenIdConnectDefaults.AuthenticationScheme)
    .AddMicrosoftIdentityWebApp(options =>
    {
        builder.Configuration.Bind("AzureAd", options);
        options.SaveTokens = true;
        options.Events.OnRedirectToIdentityProvider = (context =>
        {
            context.ProtocolMessage.Prompt = "select_account";
            return Task.CompletedTask;
        });
    });

Was this answer helpful?

2 people found this answer helpful.

3 additional answers

Sort by: Oldest
  1. Paweł Tamkowicz 0 Reputation points
    2025-09-03T10:05:01.32+00:00

    I have the same error. It breaks user experience and I'm thinking about to replace AD with Cognito. During internal tests, Cognito doesn't have this issue and user can easily refresh token. I hope someone from MS will see it because we need the solution asap

    Was this answer helpful?


  2. Sebastian Moebius 0 Reputation points
    2026-02-16T00:49:52.8266667+00:00

    I have the same issue and it is very annoying since google is such a common IdP.

    I am using react-oidc-context and the issue with the "username" error persists even if I set
    prompt: "select_account"

    I cannot find any settings other than client id and client secret in my IdP Federation settings in Entra ID

    Was this answer helpful?


  3. Raffael Prem 0 Reputation points
    2026-02-24T07:27:02.57+00:00

    I have the same error, and it a large issue, breaking UX for our Google users. This is a much needed fix.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.