Managing external identities to enable secure access for partners, customers, and other non-employees
Microsoft Entra External ID Facebook sign-in fails with AADSTS40015 during authorization code redemption
We are using Microsoft Entra External ID with a sign-up/sign-in user flow and the built-in Facebook external identity provider.
Google and Microsoft identity-provider sign-in work successfully with the same user flow. Facebook authentication, 2FA, and consent also complete successfully on Facebook. Facebook then redirects back to Microsoft Entra with an authorization code.
The failure occurs after that redirect, when Microsoft Entra appears to redeem the Facebook authorization code. The browser receives:
AADSTS40015: OAuth2IdPAuthCodeRedemptionUserError
We have verified the following:
- The Meta app is Live/published.
-
emailandpublic_profilehave been approved. - Client OAuth Login and Web OAuth Login are enabled.
- HTTPS and strict redirect URI matching are enabled.
- The Microsoft Entra External ID Facebook redirect URIs are configured in Meta.
- We re-entered the current Meta App Secret in the Entra Facebook identity-provider configuration and reproduced the failure with a completely new authentication attempt afterward.
- Google and Microsoft federation continue to work through the same External ID user flow.
- The failure happens before the Facebook customer is created in the External ID tenant, so our tenant sign-in logs do not expose the underlying Facebook token-redemption error.
A fresh failure after updating the Facebook App Secret occurred at:
2026-09-28 01:38:24 UTC
Error:
AADSTS40015 / OAuth2IdPAuthCodeRedemptionUserError
Trace ID:
c603c308-8bd3-4be6-a702-a834f29f0100
Correlation ID:
01a0e5a8-c564-7f72-bbd5-d8da1e8b9686
An earlier attempt produced the same error with a different trace/correlation ID.
We also observed that the Entra built-in Facebook integration appears to reference Facebook Graph API v19.0, while Facebook handles the request using a currently supported API version. We do not know whether this is related and are not assuming it is the cause.
Because the failure occurs during server-side authorization-code redemption, we cannot see the response Facebook returns to Microsoft Entra.
Could a Microsoft Entra External ID engineer confirm:
- What Facebook response causes
OAuth2IdPAuthCodeRedemptionUserErrorin this scenario? - Is there a known compatibility issue between the built-in Entra External ID Facebook identity provider and current Facebook Login/Graph API behavior?
- Is there any additional Facebook or Entra configuration required for the current built-in provider?
We can provide tenant ID, application ID, identity-provider ID, Meta App ID, additional correlation/trace IDs, and other diagnostic information privately if a Microsoft engineer needs them.We are using Microsoft Entra External ID with a sign-up/sign-in user flow and the built-in Facebook external identity provider.
Google and Microsoft identity-provider sign-in work successfully with the same user flow. Facebook authentication, 2FA, and consent also complete successfully on Facebook. Facebook then redirects back to Microsoft Entra with an authorization code.
The failure occurs after that redirect, when Microsoft Entra appears to redeem the Facebook authorization code. The browser receives:
AADSTS40015: OAuth2IdPAuthCodeRedemptionUserError
We have verified the following:
- The Meta app is Live/published.
-
emailandpublic_profilehave been approved. - Client OAuth Login and Web OAuth Login are enabled.
- HTTPS and strict redirect URI matching are enabled.
- The Microsoft Entra External ID Facebook redirect URIs are configured in Meta.
- We re-entered the current Meta App Secret in the Entra Facebook identity-provider configuration and reproduced the failure with a completely new authentication attempt afterward.
- Google and Microsoft federation continue to work through the same External ID user flow.
- The failure happens before the Facebook customer is created in the External ID tenant, so our tenant sign-in logs do not expose the underlying Facebook token-redemption error.
A fresh failure after updating the Facebook App Secret occurred at:
2026-09-28 01:38:24 UTC
Error:
AADSTS40015 / OAuth2IdPAuthCodeRedemptionUserError
Trace ID:
c603c308-8bd3-4be6-a702-a834f29f0100
Correlation ID:
01a0e5a8-c564-7f72-bbd5-d8da1e8b9686
An earlier attempt produced the same error with a different trace/correlation ID.
We also observed that the Entra built-in Facebook integration appears to reference Facebook Graph API v19.0, while Facebook handles the request using a currently supported API version. We do not know whether this is related and are not assuming it is the cause.
Because the failure occurs during server-side authorization-code redemption, we cannot see the response Facebook returns to Microsoft Entra.
Could a Microsoft Entra External ID engineer confirm:
- What Facebook response causes
OAuth2IdPAuthCodeRedemptionUserErrorin this scenario? - Is there a known compatibility issue between the built-in Entra External ID Facebook identity provider and current Facebook Login/Graph API behavior?
- Is there any additional Facebook or Entra configuration required for the current built-in provider?
We can provide tenant ID, application ID, identity-provider ID, Meta App ID, additional correlation/trace IDs, and other diagnostic information privately if a Microsoft engineer needs them.