Skip to content

External ID custom Email OTP extension fails account creation with generic account lookup error while using MSAL.js #8696

Description

@captain01010101

Core Library

MSAL.js (@azure/msal-browser)

Core Library Version

4.30.0

Wrapper Library

MSAL Angular (@azure/msal-angular)

Wrapper Library Version

4.1.1

Public or Confidential Client?

Public

Description

I’m seeing a failure in an MSAL.js sign-up/sign-in flow using Microsoft Entra External ID with a custom Email OTP provider.

When the custom Email OTP authentication extension is enabled, account creation fails with:

There was an issue looking up your account. Tap Next to try again.

This happens when starting the flow from my application using MSAL.js.

Documentation followed

https://learn.microsoft.com/en-us/entra/identity-platform/custom-extension-email-otp-get-started

Issue observed

The flow fails before the OTP email is successfully sent. The error shown to the user is generic and does not provide enough information to determine whether the failure is in MSAL.js, External ID, the custom authentication extension, or Azure Function authentication.

Additional details

The documentation says to use:

customauthenticationextension_extension (System key) URL

However, that system key does not appear to exist in the Function App UI. I only see the available Function App URLs. I tried all three URLs provided by the Function App, and the sign-up flow failed the same way each time.

There is also ambiguity around which app registration is expected in several places:

the frontend/client app registration
the Azure Functions authentication events API app registration
the app associated with the custom authentication extension

The documentation also says to protect the Azure Function by selecting an existing app registration “in this directory,” which appears to imply the Function App must be in the External ID tenant unless using the OpenID Connect path. This is not clearly stated.

Expected behavior

The MSAL.js sign-up/sign-in flow should proceed to OTP delivery using the configured custom Email OTP provider, or return a clear diagnostic error explaining what failed.

Actual behavior

Account creation fails with:

There was an issue looking up your account. Tap Next to try again.

Request

Can someone confirm whether this flow is currently supported and working with MSAL.js + Microsoft Entra External ID custom Email OTP provider, and clarify the correct Function URL / app registration configuration? Also MSAL should not be giving this error "There was an issue looking up your account." as I am trying to create a account not lookup a account.

Error Message

There was an issue looking up your account. Tap Next to try again.

MSAL Logs

Nothing shows up in the console even when setting the LogLevel as per the documentation. However, under network table I am receiving a http 200 on https://example.ciamlogin.com/common/GetCredentialType?mkt=en-US
{
"Username": "user@example.com",
"Display": "user@example.com",
"IfExistsResult": 1,
"IsUnmanaged": false,
"ThrottleStatus": 1,
"Credentials": {
"PrefCredential": 1,
"HasPassword": true,
"RemoteNgcParams": null,
"FidoParams": null,
"QrCodePinParams": null,
"SasParams": null,
"CertAuthParams": null,
"GoogleParams": null,
"FacebookParams": null,
"OtcNotAutoSent": false
},
"DfpProperties": {},
"EstsProperties": {
"DomainType": 1
},
"FlowToken": "BgABIQEAAAAdDD7nC9b5Q7JPd_okEQRFRXZvU3RzQXJ0aWZhY3RzAQAAAAAAQ1gCwx_cJS5xNSncOjoZTKa-dFVMRghhg366tvKyMqHzgmHXppiBNhivP82yABp_jqk_vmfDTQZAO-yT6JugS-H6QiXTy_1fentjJ9ymxYLfNEKIASrHXhBFF06NfXIOspDtnKde79rtOz6FUT0krx5T036j4YWra3M28IhlomIvg9G9Bsz_xD3xI1o7JJNcUqdH0mKz62IReyCg7j9BvPy4CdIeTN9xk78wrIwINBUMJ9QA9rAKxDhRSg4USfPbyllqcyNWTdSGCOMy325QrR42x77k5x5C6aGyv7SiHYdGI814gIIWfu6KvP6V5Tepq-x3vhywgXZVg10TMQ2EyJ12poAGc4ZP3nwh-4qazKYDR2LvOh9RGLMTIOLRld75FuHrBTARmZBsyDud_nwMxC-G920A27SV3Fc-MCj7KadZ_b6QB2YeSznBJPeh2OrMzEO0RefmLyH2Q1SXDWcC0xcHZK8JRk0Ho0ZOOJqr-CBBCnwvtHT6sIYTwrCT-E-7N1B8jHI3r9fMbMOjjE8RlQAc6gru1RIULdtEkt4XsBBYd_oRhJV6klkCtM6V6A0d6_BYd5W_iJ8pw-8UPPe-HXzQ2LiInZe_u9byGrlql8PCsOy1r47VHKhfEQ-3U5iSd2_DUyzj1_kxccUDBB-nJtRYivnXc8EG68jj6_niNLjluPKP56nJQutNtBi0I88k1lX-q1GbfNf0QMT3zKCrk3_3liiZqB0HWNsHRl3GxgRRXaBaL3Y8UfB_Ehr03TtJi3hq3UJlEUoZ6PV5QqMXx99rA1TU8PiXN7gCU0EJOJYDqRW3k-p6jRCWyz7ndDXH-_JeE4Ar17JdDhtPxcK0_njE66ORLGWVj-T1Zd5GmKPrz-sXXq9y-_YRqJFmBNz01wb7ZO4tHXa1bK2223hu-zUl9BwpuUOXAxWjOj7UsnZTegdSjfflvoPbktEYGllkIpxz8IkqrVVgXzScFvUFAWiLBxm2qDK2T_RZ5_DjKPc6f50KC1cGpuDIloxwqxAPczop766GvqqJ7H3rKTyDFBK6-ik5M0eLAY5wcVgZiPJsq4DFko0EkebdhZ4Di9PWP0jkL885MOsRtgWXeO48N4EhHuMa7yMp2YFraEW7BZZToHZ_muWfnZv9U3YItWhiV9h26kAZKJQOWSxVCmX1nRQTH3GaXTn2Y6US_kNwWWV4UPl00QyzA1MsJ_kc40j8s1EvB4kT6NUAR3XnYc-vcstA5I3d-uRLdvgqaB46QZXKuvJwY5AlfG44mwu4xAhItqDn1JEcS7f_W9MBPVJ-Vw9PhCQFlQE-UWn0clvIhGyEe_rzrufoPS8MjEuuybfOvjMSPpIHmll-WFfOHn9GqCAA",
"IsSignupDisallowed": false,
"IsReactUxSupported": true,
"apiCanary": "PAQABDgEAAAAdDD7nC9b5Q7JPd_okEQRFRXZvU3RzQXJ0aWZhY3RzCAAAAAAACvuQTEQdov2n8XKCu17JOxKAseedk-414nYq2WEsgDnSgwplg-SHrulRjkFFohxP4mTtni9z489d3YFL3C7rDH_DwEydfnSpGBqLyMNVsGprPI3vabbGX6o4AcpIBnSMgpBCV4_SnNzFMfQqNT6WMUj-fDhcq6u9XPIdpXtTPC2RCAzxtwQfPYVYUKMC6MC2RXvRoreeFrGSXh4ZnVFHUyAA"
}

Network Trace (Preferrably Fiddler)

  • Sent
  • Pending

MSAL Configuration

return new PublicClientApplication({
    auth: {
      clientId: environment.msalConfig.auth.clientId,
      redirectUri: '/',
      postLogoutRedirectUri: '/',
      authority: environment.b2cPolicies.authorities.signIn.authority,
      knownAuthorities: [environment.b2cPolicies.authorityDomain]
    },
    cache: {
      cacheLocation: 'sessionStorage'
    },

Relevant Code Snippets

No custom code used to reproduce

Reproduction Steps

Following this documentation: https://learn.microsoft.com/en-us/entra/identity-platform/custom-extension-email-otp-get-started?utm_source=chatgpt.com

Expected Behavior

It should send a OTP email

Identity Provider

Entra ID (formerly Azure AD) / MSA

Browsers Affected (Select all that apply)

Chrome

Regression

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Needs: Attention 👋Awaiting response from the MSAL.js teambug-unconfirmedA reported bug that needs to be investigated and confirmedmsal-angularRelated to @azure/msal-angular packagemsal-browserRelated to msal-browser packagepublic-clientIssues regarding PublicClientApplicationsquestionCustomer is asking for a clarification, use case or information.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions