Azure Entra External ID + OIDC Federation - Local and Federated Identities Issue

Saravana Kumar Palanisamy 20 Reputation points
2025-12-11T08:23:01.0133333+00:00

I’m integrating Entra External ID (CIAM) with an external OIDC identity provider (Azure AD B2C). I’m creating users in the EEID tenant using Microsoft Graph, and giving them both local and federated identities with Password profile

Here’s the identity fetched after creating:



     

     "identities": [
        {
            "signInType": "federated",
            "issuer": "https://demodigitalb2c.b2clogin.com/*******-7659-4181-8671-7e4c934bfdcf/v2.0/</*******--a3ec-4fa7-a471-d4eb8006dedb>",
            "issuerAssignedId": "8180e51e-aa7b-403d-9bbc-a27b8f728562"
        },
        {
            "signInType": "emailAddress",
            "issuer": "demodigitalciamuat.onmicrosoft.com",
            "issuerAssignedId": "******@email.ghostinspector.com"
        },
        {
            "signInType": "userPrincipalName",
            "issuer": "demodigitalciamuat.onmicrosoft.com",
            "issuerAssignedId": "******@demodigitalciamuat.onmicrosoft.com"
        }
    ],



The Issues faced are

  1. When I go to the login page and enter the email address, I get: “There was an issue looking up your account. Tap Next to try again.”

User's image

  1. If I click the Federated login button, it redirects to the external IdP and logs in successfully.
  2. But after logging out and trying again, the login page shows: AADSTS50000: There was an error issuing a token or an issue with our sign-in service.

User's image

Can you please help on this.

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
0 comments No comments
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.