Managing external identities to enable secure access for partners, customers, and other non-employees
Issue with Entra OIDC and authentication of desktop apps on Windows OS
We have a Microsoft Entra application that is set up with an external authentication method (EAM). The external authentication method performs an OIDC authentication to Shibboleth Identity Provider.
A policy is set up in Microsoft Entra and is applied to a specific group of users. All the resources are included in the target of this policy. Only one grant control is selected in this policy which is: "Require multifactor authentication".
When the end user logs in to Outlook web via Edge browser, the external authentication method is launched after the username/password authentication. The authentication is successful with no issue.
When the end user logs in to Outlook Desktop using a Mac OS machine, the external authentication method is launched in Safari browser after the username/password authentication. The authentication is successful with no issue.
When the end user logs in to Outlook desktop using a Windows machine, the external authentication method is launched after the username/password authentication via webview2. After the user authenticates to Shibboleth, webview2 presents a blank screen and the logs of Microsoft Entra show the following:
Date 20/10/2025, 16:06:53
Request ID c7971fc0-35db-4544-a0eb-ae0b98800100
Correlation ID 3848a36c-8b76-4e06-9d5c-adaa3b4a9939
Authentication requirement Multifactor authentication
Agent Type Not Agentic
Status Failure
Continuous access evaluation No
Sign-in error code 500741
Failure reason User will be redirected to the external provider to continue authentication.
Additional Details User needs to perform multi-factor authentication. There could be multiple things requiring multi-factor, e.g. Conditional Access policies, per-user enforcement, requested by client, among others.
It seems that webview2 used by Outlook Desktop is not able to handle the OIDC response of Shibboleth.
The use of Outlook desktop is one of the most common use cases in the Microsoft environment. Microsoft Entra External Authentication Method (EAM) should be working for Microsoft Desktop applications in a Windows machine.
Why does the Microsoft Entra External Authentication Method (EAM) not succeed in the case of Outlook Desktop on a Windows machine?
Is there any additional configuration that should be done in order to make it work?