Managing external identities to enable secure access for partners, customers, and other non-employees
This is an old post, but just for the record if someone faces the same issue. I was able to make the domain_hint work using the domain of the issuer URI registered for the externasl OIDC provider in Entra.
Similat to the instructions documented here: https://learn.microsoft.com/en-us/entra/external-id/customers/concept-authentication-methods-customers#issuer-acceleration
- Custom OIDC:
domain_hint=<issuer URI>. For a custom OIDC identity provider, use the domain part of the Issuer URI in thedomain_hintsyntax such as"www.linkedin.com"for LinkedIn.