Entra External ID sign-up redirect url with custom domain redirecting back to ciamlogin.com domain

Paul Karl Gaynor 40 Reputation points
2026-06-08T02:24:09.4266667+00:00

Hi,

I have created a working custom login domain using Entra External Id + frontdoor and everything is working great except for when a user signs up with a new email address. They are correctly redirected back to the custom domain site to the .auth/login/aad/callback url but the user is then redirected again to the <application>.ciamlogin.com endpoint for account selection.

What I cannot figure out is how to configure the aad/callback url to go to the custom domain instead of the ciamlogin.com domain in that step.

I am sure I am missing something but haven't had much luck finding any info on this.

Thanks for looking!

Microsoft Security | Microsoft Entra | Microsoft Entra External ID

Answer accepted by question author
Shubham Sharma 17,930 Reputation points Microsoft External Staff Moderator
2026-06-08T05:34:20.0166667+00:00

Hey Paul, it sounds like you’ve got your custom login domain working until the post-signup account selection step, where it falls back to <app>. That happens because by default the “issuer” for the account selection flow is still the default identity host. To force it to use your custom domain end-to-end, you need to override the issuer URL in your identity provider configuration (and in your app’s MSAL/OpenID Connect settings) so it points at your custom host instead of the default host.

Here’s what to do:

  1. In the Azure portal, go to your App Service (or wherever you configured External ID).
  2. Under Authentication → Identity Providers, edit your Microsoft identity provider.
  3. In Advanced settings, locate the Issuer URL (it’ll default to https://<your-tenant>.ciamlogin.com/{tenantID}) and change it to your custom domain, e.g.: https://login.contoso.com/{tenantID}
  4. Save and let it propagate (takes a couple minutes).

Next, in your application code/config:

• Update your authority to point at the custom domain, for example:

authority: https://login.contoso.com/{tenantID}/v2.0

• In your MSAL (or OpenID Connect) config, include your custom domain in knownAuthorities so MSAL won’t redirect to the default host:


  msalConfig = {

    auth: {

      clientId: "<your-client-id>",

      authority: "https://login.contoso.com/{tenantID}/v2.0",

      knownAuthorities: ["login.contoso.com"],

      redirectUri: "https://login.contoso.com/{tenantID}/authresp"

    }

  }

By overriding the issuer URL and application authority to use your custom hostname, all steps — including the account selection page after the /auth/login/aad/callback response — will stay on your branded domain.

References:

• Custom URL domains in external tenants – Blocking the default domain: https://learn.microsoft.com/entra/external-id/customers/concept-custom-url-domain#blocking-the-default-domain

• Enable custom URL domains for apps in external tenants: https://learn.microsoft.com/entra/external-id/customers/how-to-custom-url-domain#configure-your-applications

If the answer is helpful, kindly upvote it. If you have extra questions about this answer, please click "Comment".

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.