Issue with Sub‑Step 3 in JIT Migration Developer Guide – Custom Authentication Extension Creation Error

Mendoza, Arvin Ramil 0 Reputation points
2026-03-10T14:33:20.58+00:00

Hello Microsoft team,

We are following the Developer Guide for the B2C to Entra External ID Migration Tool, specifically Sub‑Step 3: Create the Custom Authentication Extension.

When applying the extension using the provided PowerShell sample, we consistently encounter the following error:

Invoke-RestMethod:

{

"error": {

"code": "AADB2C",

"message": "The 'endpointConfiguration' field is invalid in request. Please check the request body and parameters.",

"innerError": {

  "correlationId": "de5a914b-73df-4df5-8857-668804e21ded",

  "date": "2026-03-10T12:03:17",

  "request-id": "0679a257-39b0-44c9-9444-ef3232874cc5",

  "client-request-id": "0679a257-39b0-44c9-9444-ef3232874cc5"

}

}

}

Repro Steps :

Custom Authentication Extension

$extensionBody = @{

"@odata.type" = "#microsoft.graph.onPasswordSubmitCustomExtension"

displayName = "JIT Password Migration Extension - Local Testing"

description = "Validates passwords against B2C and migrates users on first successful login"

targetUrl = "$ngrokUrl/api/JitAuthentication"

authenticationConfiguration = @{

    "@odata.type" = "#microsoft.graph.azureAdTokenAuthentication"

    resourceId = "api://$customExtensionAppClientId"

}

} | ConvertTo-Json -Depth 10

Call Graph to Apply extension

$response = Invoke-RestMethod -Method Post `

-Uri "https://graph.microsoft.com/beta/identity/customAuthenticationExtensions" `

-Headers @{

    Authorization = "Bearer $accessToken"

    "Content-Type" = "application/json"

} `

-Body $extensionBody

Observed Behavior: The request fails with the error above, indicating endpointConfiguration is invalid. However, the Developer Guide sample uses targetUrl and authenticationConfiguration, which appear inconsistent with the Graph documentation for .

We already completed the custom delagated role as well

Microsoft Security | Microsoft Graph
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-03-10T14:33:34.19+00:00

    The error indicates that the payload no longer matches the expected schema for onPasswordSubmitCustomExtension. The Microsoft Graph resource now uses endpointConfiguration instead of the older targetUrl + authenticationConfiguration shape shown in the developer guide sample.

    To resolve the "The 'endpointConfiguration' field is invalid in request" error, the request body must be updated to the current schema and the endpoint configuration must be valid. From the available documentation, the key checks are:

    1. Ensure the endpoint configuration uses the correct property name and structure expected by the API version in use (beta). The error is specifically about endpointConfiguration, so Graph is validating that block.
    2. Ensure the HTTPS endpoint is valid and allowed:
      • It must be a customer-managed HTTPS endpoint (for example, an Azure Function) and must not point to Microsoft Graph, Microsoft Entra endpoints, or the legacy IdP’s interactive sign-in URL.
      • It must be the function endpoint that implements the password validation logic.
      • The URL must start with https and be in proper URL format.
    3. Ensure the resource/service principal configuration is valid:
      • The resourceId (or equivalent in the new endpointConfiguration block) must correspond to a real service principal in the tenant.
      • The identifier URI must follow the documented format: "api://{fully qualified domain name}/{appid}".
      • The service principal must be enabled.
      • The Microsoft Graph service principal must exist and be enabled in the tenant.
    4. Ensure the custom extension app has the correct app role permission:
      • The service principal must have admin consent for the Microsoft Graph CustomAuthenticationExtensions.Receive.Payload app role so it can receive custom authentication extension HTTP requests.

    If the endpointConfiguration block is mis‑shaped (for example, still using targetUrl and authenticationConfiguration instead of the new structure), Graph will reject it with the error seen. Aligning the request body with the current onPasswordSubmitCustomExtension schema and verifying the above conditions will allow the extension to be created successfully.

    After updating the payload, if creation still fails, use Microsoft Entra sign‑in logs to get the detailed error code for the custom authentication extension call and cross‑check against the error codes reference (for example, CustomExtensionIncorrectTargetUrlFormat, CustomExtensionIncorrectResourceIdFormat, CustomExtensionPermissionNotGrantedToServicePrincipal, etc.) to pinpoint configuration issues.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.