Managing external identities to enable secure access for partners, customers, and other non-employees
In the built-in SignInSignUp user flows of Microsoft Entra External ID, there are some limitations regarding customization for handling unknown email addresses and password reset behavior:
- Customization for Unknown Users: The built-in user flows do not allow for extensive customization based on whether an email address is registered or not. Specifically, you cannot show different UI behavior for existing versus non-existing users directly within these flows. This means you cannot control the appearance of the password page based on email existence.
- Anti-User Enumeration Protection: Microsoft Entra does intentionally prevent revealing whether an account exists to mitigate user enumeration attacks. This means that if a user enters an unregistered email, the system will not provide specific feedback indicating that the account does not exist.
- Advanced Control with Custom Policies: If you require advanced control, such as domain-based routing and preconditions, you would need to use Azure AD B2C with custom policies. The built-in user flows are limited in this regard and do not support such detailed customization.
- Password Reset Behavior: For password reset scenarios, if a user clicks “Forgot password,” the system will send a reset link or OTP only if the account exists. However, the flow does not provide feedback about the existence of the account prior to this point.
In summary, while you can enable self-service password reset and MFA, the built-in user flows do not support the level of customization you are looking for regarding user experience for unknown email addresses. For more tailored experiences, consider using Azure AD B2C with custom policies.
References: