Entra External ID custom OIDC federation fails with AADSTS50000 during account creation/token issuance

Josh Kempster 0 Reputation points
2026-09-13T12:59:31.32+00:00

We have isolated an Entra External ID custom OIDC federation failure.

A fresh External ID user flow and disposable test application reproduce the issue independently of our application code.

The source Microsoft Entra workforce user authenticates successfully and reaches the External ID “Add details” stage. After submission, External ID returns:

AADSTS50000 - There was an error issuing a token or an issue with our sign-in service.

No External ID user is created.

We have validated the OIDC issuer, client ID, redirect URIs, claims mapping, email claim, user-flow association and application association.

We also reproduced the problem with a pre-provisioned federated External ID user.

This appears to fail inside the External ID/CIAM account-creation or token-issuance stage. Please escalate this for backend investigation. I can provide the tenant IDs, correlation ID, timestamp and test-user details privately

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.