Core Library
MSAL.js (@azure/msal-browser)
Core Library Version
4.30.0
Wrapper Library
MSAL Angular (@azure/msal-angular)
Wrapper Library Version
4.1.1
Public or Confidential Client?
Public
Description
I’m seeing a failure in an MSAL.js sign-up/sign-in flow using Microsoft Entra External ID with a custom Email OTP provider.
When the custom Email OTP authentication extension is enabled, account creation fails with:
There was an issue looking up your account. Tap Next to try again.
This happens when starting the flow from my application using MSAL.js.
Documentation followed
https://learn.microsoft.com/en-us/entra/identity-platform/custom-extension-email-otp-get-started
Issue observed
The flow fails before the OTP email is successfully sent. The error shown to the user is generic and does not provide enough information to determine whether the failure is in MSAL.js, External ID, the custom authentication extension, or Azure Function authentication.
Additional details
The documentation says to use:
customauthenticationextension_extension (System key) URL
However, that system key does not appear to exist in the Function App UI. I only see the available Function App URLs. I tried all three URLs provided by the Function App, and the sign-up flow failed the same way each time.
There is also ambiguity around which app registration is expected in several places:
the frontend/client app registration
the Azure Functions authentication events API app registration
the app associated with the custom authentication extension
The documentation also says to protect the Azure Function by selecting an existing app registration “in this directory,” which appears to imply the Function App must be in the External ID tenant unless using the OpenID Connect path. This is not clearly stated.
Expected behavior
The MSAL.js sign-up/sign-in flow should proceed to OTP delivery using the configured custom Email OTP provider, or return a clear diagnostic error explaining what failed.
Actual behavior
Account creation fails with:
There was an issue looking up your account. Tap Next to try again.
Request
Can someone confirm whether this flow is currently supported and working with MSAL.js + Microsoft Entra External ID custom Email OTP provider, and clarify the correct Function URL / app registration configuration? Also MSAL should not be giving this error "There was an issue looking up your account." as I am trying to create a account not lookup a account.
Error Message
There was an issue looking up your account. Tap Next to try again.
MSAL Logs
Nothing shows up in the console even when setting the LogLevel as per the documentation. However, under network table I am receiving a http 200 on https://example.ciamlogin.com/common/GetCredentialType?mkt=en-US
{
"Username": "user@example.com",
"Display": "user@example.com",
"IfExistsResult": 1,
"IsUnmanaged": false,
"ThrottleStatus": 1,
"Credentials": {
"PrefCredential": 1,
"HasPassword": true,
"RemoteNgcParams": null,
"FidoParams": null,
"QrCodePinParams": null,
"SasParams": null,
"CertAuthParams": null,
"GoogleParams": null,
"FacebookParams": null,
"OtcNotAutoSent": false
},
"DfpProperties": {},
"EstsProperties": {
"DomainType": 1
},
"FlowToken": "BgABIQEAAAAdDD7nC9b5Q7JPd_okEQRFRXZvU3RzQXJ0aWZhY3RzAQAAAAAAQ1gCwx_cJS5xNSncOjoZTKa-dFVMRghhg366tvKyMqHzgmHXppiBNhivP82yABp_jqk_vmfDTQZAO-yT6JugS-H6QiXTy_1fentjJ9ymxYLfNEKIASrHXhBFF06NfXIOspDtnKde79rtOz6FUT0krx5T036j4YWra3M28IhlomIvg9G9Bsz_xD3xI1o7JJNcUqdH0mKz62IReyCg7j9BvPy4CdIeTN9xk78wrIwINBUMJ9QA9rAKxDhRSg4USfPbyllqcyNWTdSGCOMy325QrR42x77k5x5C6aGyv7SiHYdGI814gIIWfu6KvP6V5Tepq-x3vhywgXZVg10TMQ2EyJ12poAGc4ZP3nwh-4qazKYDR2LvOh9RGLMTIOLRld75FuHrBTARmZBsyDud_nwMxC-G920A27SV3Fc-MCj7KadZ_b6QB2YeSznBJPeh2OrMzEO0RefmLyH2Q1SXDWcC0xcHZK8JRk0Ho0ZOOJqr-CBBCnwvtHT6sIYTwrCT-E-7N1B8jHI3r9fMbMOjjE8RlQAc6gru1RIULdtEkt4XsBBYd_oRhJV6klkCtM6V6A0d6_BYd5W_iJ8pw-8UPPe-HXzQ2LiInZe_u9byGrlql8PCsOy1r47VHKhfEQ-3U5iSd2_DUyzj1_kxccUDBB-nJtRYivnXc8EG68jj6_niNLjluPKP56nJQutNtBi0I88k1lX-q1GbfNf0QMT3zKCrk3_3liiZqB0HWNsHRl3GxgRRXaBaL3Y8UfB_Ehr03TtJi3hq3UJlEUoZ6PV5QqMXx99rA1TU8PiXN7gCU0EJOJYDqRW3k-p6jRCWyz7ndDXH-_JeE4Ar17JdDhtPxcK0_njE66ORLGWVj-T1Zd5GmKPrz-sXXq9y-_YRqJFmBNz01wb7ZO4tHXa1bK2223hu-zUl9BwpuUOXAxWjOj7UsnZTegdSjfflvoPbktEYGllkIpxz8IkqrVVgXzScFvUFAWiLBxm2qDK2T_RZ5_DjKPc6f50KC1cGpuDIloxwqxAPczop766GvqqJ7H3rKTyDFBK6-ik5M0eLAY5wcVgZiPJsq4DFko0EkebdhZ4Di9PWP0jkL885MOsRtgWXeO48N4EhHuMa7yMp2YFraEW7BZZToHZ_muWfnZv9U3YItWhiV9h26kAZKJQOWSxVCmX1nRQTH3GaXTn2Y6US_kNwWWV4UPl00QyzA1MsJ_kc40j8s1EvB4kT6NUAR3XnYc-vcstA5I3d-uRLdvgqaB46QZXKuvJwY5AlfG44mwu4xAhItqDn1JEcS7f_W9MBPVJ-Vw9PhCQFlQE-UWn0clvIhGyEe_rzrufoPS8MjEuuybfOvjMSPpIHmll-WFfOHn9GqCAA",
"IsSignupDisallowed": false,
"IsReactUxSupported": true,
"apiCanary": "PAQABDgEAAAAdDD7nC9b5Q7JPd_okEQRFRXZvU3RzQXJ0aWZhY3RzCAAAAAAACvuQTEQdov2n8XKCu17JOxKAseedk-414nYq2WEsgDnSgwplg-SHrulRjkFFohxP4mTtni9z489d3YFL3C7rDH_DwEydfnSpGBqLyMNVsGprPI3vabbGX6o4AcpIBnSMgpBCV4_SnNzFMfQqNT6WMUj-fDhcq6u9XPIdpXtTPC2RCAzxtwQfPYVYUKMC6MC2RXvRoreeFrGSXh4ZnVFHUyAA"
}
Network Trace (Preferrably Fiddler)
MSAL Configuration
return new PublicClientApplication({
auth: {
clientId: environment.msalConfig.auth.clientId,
redirectUri: '/',
postLogoutRedirectUri: '/',
authority: environment.b2cPolicies.authorities.signIn.authority,
knownAuthorities: [environment.b2cPolicies.authorityDomain]
},
cache: {
cacheLocation: 'sessionStorage'
},
Relevant Code Snippets
No custom code used to reproduce
Reproduction Steps
Following this documentation: https://learn.microsoft.com/en-us/entra/identity-platform/custom-extension-email-otp-get-started?utm_source=chatgpt.com
Expected Behavior
It should send a OTP email
Identity Provider
Entra ID (formerly Azure AD) / MSA
Browsers Affected (Select all that apply)
Chrome
Regression
No response
Core Library
MSAL.js (@azure/msal-browser)
Core Library Version
4.30.0
Wrapper Library
MSAL Angular (@azure/msal-angular)
Wrapper Library Version
4.1.1
Public or Confidential Client?
Public
Description
I’m seeing a failure in an MSAL.js sign-up/sign-in flow using Microsoft Entra External ID with a custom Email OTP provider.
When the custom Email OTP authentication extension is enabled, account creation fails with:
There was an issue looking up your account. Tap Next to try again.
This happens when starting the flow from my application using MSAL.js.
Documentation followed
https://learn.microsoft.com/en-us/entra/identity-platform/custom-extension-email-otp-get-started
Issue observed
The flow fails before the OTP email is successfully sent. The error shown to the user is generic and does not provide enough information to determine whether the failure is in MSAL.js, External ID, the custom authentication extension, or Azure Function authentication.
Additional details
The documentation says to use:
customauthenticationextension_extension (System key) URL
However, that system key does not appear to exist in the Function App UI. I only see the available Function App URLs. I tried all three URLs provided by the Function App, and the sign-up flow failed the same way each time.
There is also ambiguity around which app registration is expected in several places:
the frontend/client app registration
the Azure Functions authentication events API app registration
the app associated with the custom authentication extension
The documentation also says to protect the Azure Function by selecting an existing app registration “in this directory,” which appears to imply the Function App must be in the External ID tenant unless using the OpenID Connect path. This is not clearly stated.
Expected behavior
The MSAL.js sign-up/sign-in flow should proceed to OTP delivery using the configured custom Email OTP provider, or return a clear diagnostic error explaining what failed.
Actual behavior
Account creation fails with:
There was an issue looking up your account. Tap Next to try again.
Request
Can someone confirm whether this flow is currently supported and working with MSAL.js + Microsoft Entra External ID custom Email OTP provider, and clarify the correct Function URL / app registration configuration? Also MSAL should not be giving this error "There was an issue looking up your account." as I am trying to create a account not lookup a account.
Error Message
There was an issue looking up your account. Tap Next to try again.
MSAL Logs
Nothing shows up in the console even when setting the LogLevel as per the documentation. However, under network table I am receiving a http 200 on https://example.ciamlogin.com/common/GetCredentialType?mkt=en-US
{
"Username": "user@example.com",
"Display": "user@example.com",
"IfExistsResult": 1,
"IsUnmanaged": false,
"ThrottleStatus": 1,
"Credentials": {
"PrefCredential": 1,
"HasPassword": true,
"RemoteNgcParams": null,
"FidoParams": null,
"QrCodePinParams": null,
"SasParams": null,
"CertAuthParams": null,
"GoogleParams": null,
"FacebookParams": null,
"OtcNotAutoSent": false
},
"DfpProperties": {},
"EstsProperties": {
"DomainType": 1
},
"FlowToken": "BgABIQEAAAAdDD7nC9b5Q7JPd_okEQRFRXZvU3RzQXJ0aWZhY3RzAQAAAAAAQ1gCwx_cJS5xNSncOjoZTKa-dFVMRghhg366tvKyMqHzgmHXppiBNhivP82yABp_jqk_vmfDTQZAO-yT6JugS-H6QiXTy_1fentjJ9ymxYLfNEKIASrHXhBFF06NfXIOspDtnKde79rtOz6FUT0krx5T036j4YWra3M28IhlomIvg9G9Bsz_xD3xI1o7JJNcUqdH0mKz62IReyCg7j9BvPy4CdIeTN9xk78wrIwINBUMJ9QA9rAKxDhRSg4USfPbyllqcyNWTdSGCOMy325QrR42x77k5x5C6aGyv7SiHYdGI814gIIWfu6KvP6V5Tepq-x3vhywgXZVg10TMQ2EyJ12poAGc4ZP3nwh-4qazKYDR2LvOh9RGLMTIOLRld75FuHrBTARmZBsyDud_nwMxC-G920A27SV3Fc-MCj7KadZ_b6QB2YeSznBJPeh2OrMzEO0RefmLyH2Q1SXDWcC0xcHZK8JRk0Ho0ZOOJqr-CBBCnwvtHT6sIYTwrCT-E-7N1B8jHI3r9fMbMOjjE8RlQAc6gru1RIULdtEkt4XsBBYd_oRhJV6klkCtM6V6A0d6_BYd5W_iJ8pw-8UPPe-HXzQ2LiInZe_u9byGrlql8PCsOy1r47VHKhfEQ-3U5iSd2_DUyzj1_kxccUDBB-nJtRYivnXc8EG68jj6_niNLjluPKP56nJQutNtBi0I88k1lX-q1GbfNf0QMT3zKCrk3_3liiZqB0HWNsHRl3GxgRRXaBaL3Y8UfB_Ehr03TtJi3hq3UJlEUoZ6PV5QqMXx99rA1TU8PiXN7gCU0EJOJYDqRW3k-p6jRCWyz7ndDXH-_JeE4Ar17JdDhtPxcK0_njE66ORLGWVj-T1Zd5GmKPrz-sXXq9y-_YRqJFmBNz01wb7ZO4tHXa1bK2223hu-zUl9BwpuUOXAxWjOj7UsnZTegdSjfflvoPbktEYGllkIpxz8IkqrVVgXzScFvUFAWiLBxm2qDK2T_RZ5_DjKPc6f50KC1cGpuDIloxwqxAPczop766GvqqJ7H3rKTyDFBK6-ik5M0eLAY5wcVgZiPJsq4DFko0EkebdhZ4Di9PWP0jkL885MOsRtgWXeO48N4EhHuMa7yMp2YFraEW7BZZToHZ_muWfnZv9U3YItWhiV9h26kAZKJQOWSxVCmX1nRQTH3GaXTn2Y6US_kNwWWV4UPl00QyzA1MsJ_kc40j8s1EvB4kT6NUAR3XnYc-vcstA5I3d-uRLdvgqaB46QZXKuvJwY5AlfG44mwu4xAhItqDn1JEcS7f_W9MBPVJ-Vw9PhCQFlQE-UWn0clvIhGyEe_rzrufoPS8MjEuuybfOvjMSPpIHmll-WFfOHn9GqCAA",
"IsSignupDisallowed": false,
"IsReactUxSupported": true,
"apiCanary": "PAQABDgEAAAAdDD7nC9b5Q7JPd_okEQRFRXZvU3RzQXJ0aWZhY3RzCAAAAAAACvuQTEQdov2n8XKCu17JOxKAseedk-414nYq2WEsgDnSgwplg-SHrulRjkFFohxP4mTtni9z489d3YFL3C7rDH_DwEydfnSpGBqLyMNVsGprPI3vabbGX6o4AcpIBnSMgpBCV4_SnNzFMfQqNT6WMUj-fDhcq6u9XPIdpXtTPC2RCAzxtwQfPYVYUKMC6MC2RXvRoreeFrGSXh4ZnVFHUyAA"
}
Network Trace (Preferrably Fiddler)
MSAL Configuration
Relevant Code Snippets
Reproduction Steps
Following this documentation: https://learn.microsoft.com/en-us/entra/identity-platform/custom-extension-email-otp-get-started?utm_source=chatgpt.com
Expected Behavior
It should send a OTP email
Identity Provider
Entra ID (formerly Azure AD) / MSA
Browsers Affected (Select all that apply)
Chrome
Regression
No response