A cloud-based identity and access management service for securing user authentication and resource access
OIDC discovery metadata inconsistent across regions — PKCE field missing on build 2.1.22024.3
Since Oct 3 2025, our applications using Microsoft Entra ID (Azure AD) OpenID Connect have seen intermittent authentication failures.
We discovered that different ESTS clusters behind https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration return different JSON metadata.
HeaderValuePKCE Fieldx-ms-ests-server: 2.1.22024.3 - FRC ProdSlicesFrance Central slicecode_challenge_methods_supported missingx-ms-ests-server: 2.1.22096.4 - WEULR1 ProdSlicesWest Europe slicecode_challenge_methods_supported: **["plain","S256"]**This causes clients (IdentityServer, MSAL, OIDC middleware) that rely on discovery to mis-detect PKCE support and fail SSO.
Captured Oct 5 2025 18:34 UTC / 18:09 UTC
Endpoint: https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration
Region codes: WEULR1 and FRC
See attached curl logs.
Impact: Multiple production tenants intermittently fail SSO depending on which ESTS region they hit.
// x-ms-ests-server: 2.1.22096.4 - WEULR1 ProdSlices
curl -v -H "Cache-Control: no-cache" https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration
* Host login.microsoftonline.com:443 was resolved.
* IPv6: (none)
* IPv4: 20.190.147.1, 20.190.177.21, 20.190.147.0, 20.190.177.85, 20.190.147.11, 20.190.147.2, 20.190.147.8, 20.190.177.22
* Trying 20.190.147.1:443...
* Connected to login.microsoftonline.com (20.190.147.1) port 443
* ALPN: curl offers h2,http/1.1
* (304) (OUT), TLS handshake, Client hello (1):
* CAfile: /etc/ssl/cert.pem
* CApath: none
* (304) (IN), TLS handshake, Server hello (2):
* (304) (OUT), TLS handshake, Client hello (1):
* (304) (IN), TLS handshake, Server hello (2):
* (304) (IN), TLS handshake, Unknown (8):
* (304) (IN), TLS handshake, Certificate (11):
* (304) (IN), TLS handshake, CERT verify (15):
* (304) (IN), TLS handshake, Finished (20):
* (304) (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / AEAD-AES256-GCM-SHA384 / [blank] / UNDEF
* ALPN: server accepted h2
* Server certificate:
* subject: C=US; ST=WA; L=Redmond; O=Microsoft Corporation; CN=stamp2.login.microsoftonline.com
* start date: Sep 23 13:06:29 2025 GMT
* expire date: Mar 22 13:06:29 2026 GMT
* subjectAltName: host "login.microsoftonline.com" matched cert's "login.microsoftonline.com"
* issuer: C=US; O=Microsoft Corporation; CN=Microsoft Azure RSA TLS Issuing CA 07
* SSL certificate verify ok.
* using HTTP/2
* [HTTP/2] [1] OPENED stream for https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration
* [HTTP/2] [1] [:method: GET]
* [HTTP/2] [1] [:scheme: https]
* [HTTP/2] [1] [:authority: login.microsoftonline.com]
* [HTTP/2] [1] [:path: /common/v2.0/.well-known/openid-configuration]
* [HTTP/2] [1] [user-agent: curl/8.7.1]
* [HTTP/2] [1] [accept: */*]
* [HTTP/2] [1] [cache-control: no-cache]
> GET /common/v2.0/.well-known/openid-configuration HTTP/2
> Host: login.microsoftonline.com
> User-Agent: curl/8.7.1
> Accept: */*
> Cache-Control: no-cache
>
* Request completely sent off
< HTTP/2 200
< cache-control: max-age=86400, private
< content-type: application/json; charset=utf-8
< strict-transport-security: max-age=31536000; includeSubDomains
< x-content-type-options: nosniff
< access-control-allow-origin: *
< access-control-allow-methods: GET, OPTIONS
< p3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
< x-ms-request-id: 6663007c-3052-4dd5-b31b-1cfbf3b13200
< x-ms-ests-server: 2.1.22096.4 - WEULR1 ProdSlices
< x-ms-srs: 1.P
< content-security-policy-report-only: object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-Trf0lzSk6CPwpq9aWLeDxg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All
< cross-origin-opener-policy-report-only: same-origin; report-to="coop-endpoint"
< reporting-endpoints: coop-endpoint="https://idux.azurewebsites.net/api/coopReport"
< x-xss-protection: 0
< set-cookie: fpc=AuxF2eFnKnxOvo7UdDDuoH8; expires=Tue, 04-Nov-2025 18:34:06 GMT; path=/; secure; HttpOnly; SameSite=None
< set-cookie: esctx=PAQABBwEAAABlMNzVhAPUTrARzfQjWPtKv2Imk50kXDvdiDJv8MUk1iYNx8hzUhrzQT1rvifqtcULfjOHy-G0ZywdQVzk-sxN2Bb2rOS6GHNX9qBpiYM3IunCNr9tM2gEqpgmiosrTcjexIfdvtY0KYcqwSRNrtwyc670BubSmZfFhSsjliN0kMcXXSH8Qex4R3N2m2jR-hcgAA; domain=.login.microsoftonline.com; path=/; secure; HttpOnly; SameSite=None
< set-cookie: x-ms-gateway-slice=estsfd; path=/; secure; samesite=none; httponly
< set-cookie: stsservicecookie=estsfd; path=/; secure; samesite=none; httponly
< date: Sun, 05 Oct 2025 18:34:06 GMT
< content-length: 1599
<
* Connection #0 to host login.microsoftonline.com left intact
{
"token_endpoint": "https://login.microsoftonline.com/common/oauth2/v2.0/token",
"token_endpoint_auth_methods_supported": [
"client_secret_post",
"private_key_jwt",
"client_secret_basic"
],
"jwks_uri": "https://login.microsoftonline.com/common/discovery/v2.0/keys",
"response_modes_supported": [
"query",
"fragment",
"form_post"
],
"subject_types_supported": [
"pairwise"
],
"id_token_signing_alg_values_supported": [
"RS256"
],
"code_challenge_methods_supported": [
"plain",
"S256"
],
"response_types_supported": [
"code",
"id_token",
"code id_token",
"id_token token"
],
"scopes_supported": [
"openid",
"profile",
"email",
"offline_access"
],
"issuer": "https://login.microsoftonline.com/{tenantid}/v2.0",
"request_uri_parameter_supported": false,
"userinfo_endpoint": "https://graph.microsoft.com/oidc/userinfo",
"authorization_endpoint": "https://login.microsoftonline.com/common/oauth2/v2.0/authorize",
"device_authorization_endpoint": "https://login.microsoftonline.com/common/oauth2/v2.0/devicecode",
"http_logout_supported": true,
"frontchannel_logout_supported": true,
"end_session_endpoint": "https://login.microsoftonline.com/common/oauth2/v2.0/logout",
"claims_supported": [
"sub",
"iss",
"cloud_instance_name",
"cloud_instance_host_name",
"cloud_graph_host_name",
"msgraph_host",
"aud",
"exp",
"iat",
"auth_time",
"acr",
"nonce",
"preferred_username",
"name",
"tid",
"ver",
"at_hash",
"c_hash",
"email"
],
"kerberos_endpoint": "https://login.microsoftonline.com/common/kerberos",
"tenant_region_scope": null,
"cloud_instance_name": "microsoftonline.com",
"cloud_graph_host_name": "graph.windows.net",
"msgraph_host": "graph.microsoft.com",
"rbac_url": "https://pas.windows.net"
}
x-ms-ests-server: 2.1.22024.3 - FRC ProdSlices
curl -v -H "Cache-Control: no-cache" https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration
* Host login.microsoftonline.com:443 was resolved.
* IPv6: (none)
* IPv4: 20.190.147.5, 20.190.147.8, 20.190.177.83, 20.190.177.82, 20.190.177.19, 20.190.177.84, 20.190.147.10, 20.190.147.3
* Trying 20.190.147.5:443...
* Connected to login.microsoftonline.com (20.190.147.5) port 443
* ALPN: curl offers h2,http/1.1
* (304) (OUT), TLS handshake, Client hello (1):
* CAfile: /etc/ssl/cert.pem
* CApath: none
* (304) (IN), TLS handshake, Server hello (2):
* (304) (OUT), TLS handshake, Client hello (1):
* (304) (IN), TLS handshake, Server hello (2):
* (304) (IN), TLS handshake, Unknown (8):
* (304) (IN), TLS handshake, Certificate (11):
* (304) (IN), TLS handshake, CERT verify (15):
* (304) (IN), TLS handshake, Finished (20):
* (304) (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / AEAD-AES256-GCM-SHA384 / [blank] / UNDEF
* ALPN: server accepted h2
* Server certificate:
* subject: C=US; ST=Washington; L=Redmond; O=Microsoft Corporation; CN=stamp2.login.microsoftonline.com
* start date: Sep 23 00:00:00 2025 GMT
* expire date: Mar 22 23:59:59 2026 GMT
* subjectAltName: host "login.microsoftonline.com" matched cert's "login.microsoftonline.com"
* issuer: C=US; O=DigiCert Inc; CN=DigiCert SHA2 Secure Server CA
* SSL certificate verify ok.
* using HTTP/2
* [HTTP/2] [1] OPENED stream for https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration
* [HTTP/2] [1] [:method: GET]
* [HTTP/2] [1] [:scheme: https]
* [HTTP/2] [1] [:authority: login.microsoftonline.com]
* [HTTP/2] [1] [:path: /common/v2.0/.well-known/openid-configuration]
* [HTTP/2] [1] [user-agent: curl/8.7.1]
* [HTTP/2] [1] [accept: */*]
* [HTTP/2] [1] [cache-control: no-cache]
> GET /common/v2.0/.well-known/openid-configuration HTTP/2
> Host: login.microsoftonline.com
> User-Agent: curl/8.7.1
> Accept: */*
> Cache-Control: no-cache
>
* Request completely sent off
< HTTP/2 200
< cache-control: max-age=86400, private
< content-type: application/json; charset=utf-8
< strict-transport-security: max-age=31536000; includeSubDomains
< x-content-type-options: nosniff
< access-control-allow-origin: *
< access-control-allow-methods: GET, OPTIONS
< p3p: CP="DSP CUR OTPi IND OTRi ONL FIN"
< x-ms-request-id: 123749ef-6f5c-48a9-98b0-56252c907500
< x-ms-ests-server: 2.1.22024.3 - FRC ProdSlices
< x-ms-srs: 1.P
< content-security-policy-report-only: object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-J1ikez6qo5cmil9pyNWKlg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All
< cross-origin-opener-policy-report-only: same-origin; report-to="coop-endpoint"
< reporting-endpoints: coop-endpoint="https://idux.azurewebsites.net/api/coopReport"
< x-xss-protection: 0
< set-cookie: fpc=Akh3kjkWE95Hrgfs_bGAvNI; expires=Tue, 04-Nov-2025 18:09:09 GMT; path=/; secure; HttpOnly; SameSite=None
< set-cookie: esctx=PAQABBwEAAABlMNzVhAPUTrARzfQjWPtKCjs8HgTHj-Iok0KnPVpJBV79bV_g8_JINpA8K2vVgyivdWIfW01K6s5DGpIpaD6XwXMgorgcJSDTTqYr56G5Kh9zKDRZpObk1TDWj7KvT4gJfSGx_IsCD3NyZ3qceFYLvZujaHOzrFdJ4Gw3yYV6DECDMhMWJfiKxKsK3t8uj1wgAA; domain=.login.microsoftonline.com; path=/; secure; HttpOnly; SameSite=None
< set-cookie: x-ms-gateway-slice=estsfd; path=/; secure; samesite=none; httponly
< set-cookie: stsservicecookie=estsfd; path=/; secure; samesite=none; httponly
< date: Sun, 05 Oct 2025 18:09:09 GMT
< content-length: 1547
<
* Connection #0 to host login.microsoftonline.com left intact
{
"token_endpoint": "https://login.microsoftonline.com/common/oauth2/v2.0/token",
"token_endpoint_auth_methods_supported": [
"client_secret_post",
"private_key_jwt",
"client_secret_basic"
],
"jwks_uri": "https://login.microsoftonline.com/common/discovery/v2.0/keys",
"response_modes_supported": [
"query",
"fragment",
"form_post"
],
"subject_types_supported": [
"pairwise"
],
"id_token_signing_alg_values_supported": [
"RS256"
],
"response_types_supported": [
"code",
"id_token",
"code id_token",
"id_token token"
],
"scopes_supported": [
"openid",
"profile",
"email",
"offline_access"
],
"issuer": "https://login.microsoftonline.com/{tenantid}/v2.0",
"request_uri_parameter_supported": false,
"userinfo_endpoint": "https://graph.microsoft.com/oidc/userinfo",
"authorization_endpoint": "https://login.microsoftonline.com/common/oauth2/v2.0/authorize",
"device_authorization_endpoint": "https://login.microsoftonline.com/common/oauth2/v2.0/devicecode",
"http_logout_supported": true,
"frontchannel_logout_supported": true,
"end_session_endpoint": "https://login.microsoftonline.com/common/oauth2/v2.0/logout",
"claims_supported": [
"sub",
"iss",
"cloud_instance_name",
"cloud_instance_host_name",
"cloud_graph_host_name",
"msgraph_host",
"aud",
"exp",
"iat",
"auth_time",
"acr",
"nonce",
"preferred_username",
"name",
"tid",
"ver",
"at_hash",
"c_hash",
"email"
],
"kerberos_endpoint": "https://login.microsoftonline.com/common/kerberos",
"tenant_region_scope": null,
"cloud_instance_name": "microsoftonline.com",
"cloud_graph_host_name": "graph.windows.net",
"msgraph_host": "graph.microsoft.com",
"rbac_url": "https://pas.windows.net"
}
Request:
Confirm whether build 2.1.22024.x of the ESTS service omitted the code_challenge_methods_supported field from the OpenID Connect discovery document at https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration.
Confirm whether build 2.1.22096.x (or newer) re-introduces this field, and clarify if the rollout has reached the Europe / Northern Europe clusters (e.g. WEULR1, NEULR1, FRC).
Expected behavior:
The OpenID Connect discovery document should consistently include the field "code_challenge_methods_supported": ["S256", "plain"] as part of the metadata defined in RFC 8414 §2.1.
The metadata should be **identical across all ESTS regional slices** behind `login.microsoftonline.com`, ensuring clients receive the same discovery configuration regardless of the responding server.
The endpoint should return a valid JSON document with `Content-Type: application/json; charset=utf-8` and not vary between builds or regions.
Provide confirmation that the current configuration (with inconsistent PKCE metadata) is **not intentional**, and whether tenant-specific discovery endpoints are recommended as a stable workaround.Impact: Multiple production tenants intermittently fail SSO depending on which ESTS region they hit.