Guest accounts from workforce tenant can no longer auth (login loop) with an SSO in a Microsoft External ID (CIAM)

Preben Lundborg Hansen 10 Reputation points
2025-10-25T12:21:52.8+00:00

Short system overview:

We have 3 app regs in a CIAM Tenant (Microsoft External ID).

We create member users that could login and still can login using the 3 apps.

Selected employees from the workforce tenant Microsoft Entra ID are created/invited as guest object users in CIAM Microsoft External ID.

For over a month guest users were able to login without any problems, but by the 23th of October guest login is no longer possible. The login proces stops when the user has entered the UPN and should get on option to enter a password. A user with a valid token is still getting access, but new logins are stalled.

This unexpected behavior has hit 3 instances of External ID (dev, test, prod) at the same time. They all have guest object form the same workforce tenant.

Looking at the "debug dev tools" -> network section in a browser gives no errors, but keeps returning to this url when pressing enter:

User's image

I have had no succes in locating the root course of this problem.

There are no traces of error around login in the workforce External ID or the CIAM External ID.

I expect Microsoft has changed something in the login process but what and how can we get around this modification

Any Ideas ?

Microsoft Security | Microsoft Entra | Microsoft Entra External ID

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.