An API that connects multiple Microsoft services, enabling data access and automation across platforms
The error indicates that the payload no longer matches the expected schema for onPasswordSubmitCustomExtension. The Microsoft Graph resource now uses endpointConfiguration instead of the older targetUrl + authenticationConfiguration shape shown in the developer guide sample.
To resolve the "The 'endpointConfiguration' field is invalid in request" error, the request body must be updated to the current schema and the endpoint configuration must be valid. From the available documentation, the key checks are:
- Ensure the endpoint configuration uses the correct property name and structure expected by the API version in use (beta). The error is specifically about
endpointConfiguration, so Graph is validating that block. - Ensure the HTTPS endpoint is valid and allowed:
- It must be a customer-managed HTTPS endpoint (for example, an Azure Function) and must not point to Microsoft Graph, Microsoft Entra endpoints, or the legacy IdP’s interactive sign-in URL.
- It must be the function endpoint that implements the password validation logic.
- The URL must start with
httpsand be in proper URL format.
- Ensure the resource/service principal configuration is valid:
- The
resourceId(or equivalent in the newendpointConfigurationblock) must correspond to a real service principal in the tenant. - The identifier URI must follow the documented format:
"api://{fully qualified domain name}/{appid}". - The service principal must be enabled.
- The Microsoft Graph service principal must exist and be enabled in the tenant.
- The
- Ensure the custom extension app has the correct app role permission:
- The service principal must have admin consent for the
Microsoft Graph CustomAuthenticationExtensions.Receive.Payloadapp role so it can receive custom authentication extension HTTP requests.
- The service principal must have admin consent for the
If the endpointConfiguration block is mis‑shaped (for example, still using targetUrl and authenticationConfiguration instead of the new structure), Graph will reject it with the error seen. Aligning the request body with the current onPasswordSubmitCustomExtension schema and verifying the above conditions will allow the extension to be created successfully.
After updating the payload, if creation still fails, use Microsoft Entra sign‑in logs to get the detailed error code for the custom authentication extension call and cross‑check against the error codes reference (for example, CustomExtensionIncorrectTargetUrlFormat, CustomExtensionIncorrectResourceIdFormat, CustomExtensionPermissionNotGrantedToServicePrincipal, etc.) to pinpoint configuration issues.
References: