Managing external identities to enable secure access for partners, customers, and other non-employees
Hey Paul, it sounds like you’ve got your custom login domain working until the post-signup account selection step, where it falls back to <app>. That happens because by default the “issuer” for the account selection flow is still the default identity host. To force it to use your custom domain end-to-end, you need to override the issuer URL in your identity provider configuration (and in your app’s MSAL/OpenID Connect settings) so it points at your custom host instead of the default host.
Here’s what to do:
- In the Azure portal, go to your App Service (or wherever you configured External ID).
- Under Authentication → Identity Providers, edit your Microsoft identity provider.
- In Advanced settings, locate the Issuer URL (it’ll default to
https://<your-tenant>.ciamlogin.com/{tenantID}) and change it to your custom domain, e.g.:https://login.contoso.com/{tenantID} - Save and let it propagate (takes a couple minutes).
Next, in your application code/config:
• Update your authority to point at the custom domain, for example:
authority: https://login.contoso.com/{tenantID}/v2.0
• In your MSAL (or OpenID Connect) config, include your custom domain in knownAuthorities so MSAL won’t redirect to the default host:
msalConfig = {
auth: {
clientId: "<your-client-id>",
authority: "https://login.contoso.com/{tenantID}/v2.0",
knownAuthorities: ["login.contoso.com"],
redirectUri: "https://login.contoso.com/{tenantID}/authresp"
}
}
By overriding the issuer URL and application authority to use your custom hostname, all steps — including the account selection page after the /auth/login/aad/callback response — will stay on your branded domain.
References:
• Custom URL domains in external tenants – Blocking the default domain: https://learn.microsoft.com/entra/external-id/customers/concept-custom-url-domain#blocking-the-default-domain
• Enable custom URL domains for apps in external tenants: https://learn.microsoft.com/entra/external-id/customers/how-to-custom-url-domain#configure-your-applications
If the answer is helpful, kindly upvote it. If you have extra questions about this answer, please click "Comment".