How to handle unknown email addresses and password reset behavior in Microsoft Entra External ID SignInSignUp flow?

BHANU PRATAP SINGH 10 Reputation points
2026-02-18T18:21:46.86+00:00

I am working with a Microsoft Entra External ID (Customer) tenant using the built-in SignInSignUp user flow, and I would like clarification on supported behavior for unknown users and password reset scenarios.


Scenario

We have:

  • Local accounts (email + password) enabled

Google/Yahoo federated identity providers configured

Conditional Access policy enforcing MFA

Self-Service Password Reset (SSPR) enabled


Expected User Experience

We would like the flow to behave as follows:

User enters email address.

Based on domain:

Federated domains (Google/Yahoo) → redirect to respective IdP

  Local domain → show password textbox
  
  If the email is **not registered in the tenant**:
  
     Show password screen
     
        Provide “Forgot password” link
        
        If password is correct:
        
           Trigger MFA (if required)
           
           If user clicks “Forgot password”:
           
              Verify email
              
                 If account exists → send reset link / OTP
                 
                    Complete password reset
                    
                       Enforce MFA during sign-in
                       

Questions

In built-in SignInSignUp flows, is it possible to customize behavior when a user enters an email address that is not registered?

Is there a supported way to:

Show different UI behavior for existing vs non-existing users?

  Control how the password page appears based on email existence?
  
  Does Entra intentionally prevent revealing whether an account exists (anti-user enumeration protection)?
  
  If advanced control is required (such as domain-based routing + preconditions), is Azure AD B2C with custom policies the only supported approach?
  

Environment Details

Tenant Type: Microsoft Entra External ID (Customer)

Using built-in user flows (not custom policies)

MFA enabled via Conditional Access

SSPR enabled


We are trying to design a secure and user-friendly onboarding experience while staying within supported Entra External ID capabilities.

Any clarification on supported vs unsupported customization options would be greatly appreciated.

Microsoft Security | Microsoft Entra | Microsoft Entra External ID

1 answer

Sort by: Most helpful
  1. AI answer

    2026-02-18T18:22:00.0633333+00:00

    In the built-in SignInSignUp user flows of Microsoft Entra External ID, there are some limitations regarding customization for handling unknown email addresses and password reset behavior:

    1. Customization for Unknown Users: The built-in user flows do not allow for extensive customization based on whether an email address is registered or not. Specifically, you cannot show different UI behavior for existing versus non-existing users directly within these flows. This means you cannot control the appearance of the password page based on email existence.
    2. Anti-User Enumeration Protection: Microsoft Entra does intentionally prevent revealing whether an account exists to mitigate user enumeration attacks. This means that if a user enters an unregistered email, the system will not provide specific feedback indicating that the account does not exist.
    3. Advanced Control with Custom Policies: If you require advanced control, such as domain-based routing and preconditions, you would need to use Azure AD B2C with custom policies. The built-in user flows are limited in this regard and do not support such detailed customization.
    4. Password Reset Behavior: For password reset scenarios, if a user clicks “Forgot password,” the system will send a reset link or OTP only if the account exists. However, the flow does not provide feedback about the existence of the account prior to this point.

    In summary, while you can enable self-service password reset and MFA, the built-in user flows do not support the level of customization you are looking for regarding user experience for unknown email addresses. For more tailored experiences, consider using Azure AD B2C with custom policies.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.