Azure-docs: Registering the IdentityExperienceFramework and ProxyIdentityExperienceFramework apps through the App registrations (Preview) causes the example custom flows to work only for sign up, but not authentication

Created on 29 Apr 2020  Â·  10Comments  Â·  Source: MicrosoftDocs/azure-docs

The problem itself is that after registration, the redirect is done properly and the user is redirected with a token. When an attempt is made to sign in with the same user, though, a message 'Invalid username or password' is displayed and the user does not get authenticated. I am certain this was with the correct credentials, as using a wrong email or a wrong password was returning different error messages each.

Using the supposedly deprecated 'App registrations (Legacy)' method works, though.


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

B2subsvc Pri1 active-directorsvc awaiting-product-team-response cxp product-question triaged

Most helpful comment

@Negwood @MSRobert @vivaladan @AmitavaHazra Please see above.

All 10 comments

I am also facing same issue (sign up is done, but not able to sign in) but it was working properly few hours back.

@Negwood Thanks for your feedback! We will investigate and update as appropriate.

I've reported this issue to the product team to ask if there is an outage. @negwood, was it also working for you before like it was for Amita? Amita, at what time did it stop working? Do you have any error logs you can share?

We have reached out to the product team to see if there was a recent outage. Typically this issue happens when the permissions on the ProxyIdentityExperienceFramework aren't set properly. I'd say doublecheck that ProxyIdentityExperienceFramework has Admin consent for Azure Active Directory Graph: User.Read and IdentityExperienceFramework: User_Impersonation. In the meantime if I hear back from the PG I will post the status here.

@MarileeTurscak-MSFT I cannot tell if it had been working before, as this was the first time I have tried working with custom policies.

Thanks for the tips and the attention!

@MarileeTurscak-MSFT @SaurabhSharma-MSFT I've also encountered this issue. Cannot login with existing local accounts and while I can create new accounts through the custom policy, I can't login with them either. It works after deleting the applications and creating them with the legacy steps.

I have the same issue with a new setup. I have even started from scratch with the policy starter pack without any customizations.

@Negwood set allowpublicclient to true in the manifest for proxy app.

A hotfix has been issued for this problem, should be resolved by Monday.

The UI element for the following step in the instructions was made unavailable:
3. Under Advanced settings, enable Treat application as a public client (select Yes).

As a temporary work around:

  1. Go to the 'Manifest blade' in the App Registration for ProxyIdentityExperienceFramework
  2. Set the allowPublicClient value to "true"

@Negwood @MSRobert @vivaladan @AmitavaHazra Please see above.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

Ponant picture Ponant  Â·  3Comments

DeepPuddles picture DeepPuddles  Â·  3Comments

AronT-TLV picture AronT-TLV  Â·  3Comments

jharbieh picture jharbieh  Â·  3Comments

mrdfuse picture mrdfuse  Â·  3Comments