Issue with Entra OIDC and authentication of desktop apps on Windows OS

Giles Caunter 0 Reputation points
2025-10-21T12:09:15.11+00:00

We have a Microsoft Entra application that is set up with an external authentication method (EAM). The external authentication method performs an OIDC authentication to Shibboleth Identity Provider.

A policy is set up in Microsoft Entra and is applied to a specific group of users. All the resources are included in the target of this policy. Only one grant control is selected in this policy which is: "Require multifactor authentication".

 

When the end user logs in to Outlook web via Edge browser, the external authentication method is launched after the username/password authentication. The authentication is successful with no issue.

 

When the end user logs in to Outlook Desktop using a Mac OS machine, the external authentication method is launched in Safari browser after the username/password authentication. The authentication is successful with no issue.

 

When the end user logs in to Outlook desktop using a Windows machine, the external authentication method is launched after the username/password authentication via webview2. After the user authenticates to Shibboleth, webview2 presents a blank screen and the logs of Microsoft Entra show the following:

 

Date 20/10/2025, 16:06:53

Request ID c7971fc0-35db-4544-a0eb-ae0b98800100

Correlation ID 3848a36c-8b76-4e06-9d5c-adaa3b4a9939

Authentication requirement Multifactor authentication

Agent Type Not Agentic

Status Failure

Continuous access evaluation No

Sign-in error code 500741

Failure reason User will be redirected to the external provider to continue authentication.

Additional Details User needs to perform multi-factor authentication. There could be multiple things requiring multi-factor, e.g. Conditional Access policies, per-user enforcement, requested by client, among others.

 

It seems that webview2 used by Outlook Desktop is not able to handle the OIDC response of Shibboleth.

 

The use of Outlook desktop is one of the most common use cases in the Microsoft environment. Microsoft Entra External Authentication Method (EAM) should be working for Microsoft Desktop applications in a Windows machine.

 

Why does the Microsoft Entra External Authentication Method (EAM) not succeed in the case of Outlook Desktop on a Windows machine?

Is there any additional configuration that should be done in order to make it work?

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.