Microsoft Entra External ID Facebook sign-in fails with AADSTS40015 during authorization code redemption

OfferNab Engineering 0 Reputation points
2026-09-28T03:39:51.3566667+00:00

We are using Microsoft Entra External ID with a sign-up/sign-in user flow and the built-in Facebook external identity provider.

Google and Microsoft identity-provider sign-in work successfully with the same user flow. Facebook authentication, 2FA, and consent also complete successfully on Facebook. Facebook then redirects back to Microsoft Entra with an authorization code.

The failure occurs after that redirect, when Microsoft Entra appears to redeem the Facebook authorization code. The browser receives:

AADSTS40015: OAuth2IdPAuthCodeRedemptionUserError

We have verified the following:

  1. The Meta app is Live/published.
  2. email and public_profile have been approved.
  3. Client OAuth Login and Web OAuth Login are enabled.
  4. HTTPS and strict redirect URI matching are enabled.
  5. The Microsoft Entra External ID Facebook redirect URIs are configured in Meta.
  6. We re-entered the current Meta App Secret in the Entra Facebook identity-provider configuration and reproduced the failure with a completely new authentication attempt afterward.
  7. Google and Microsoft federation continue to work through the same External ID user flow.
  8. The failure happens before the Facebook customer is created in the External ID tenant, so our tenant sign-in logs do not expose the underlying Facebook token-redemption error.

A fresh failure after updating the Facebook App Secret occurred at:

2026-09-28 01:38:24 UTC

Error:

AADSTS40015 / OAuth2IdPAuthCodeRedemptionUserError

Trace ID:

c603c308-8bd3-4be6-a702-a834f29f0100

Correlation ID:

01a0e5a8-c564-7f72-bbd5-d8da1e8b9686

An earlier attempt produced the same error with a different trace/correlation ID.

We also observed that the Entra built-in Facebook integration appears to reference Facebook Graph API v19.0, while Facebook handles the request using a currently supported API version. We do not know whether this is related and are not assuming it is the cause.

Because the failure occurs during server-side authorization-code redemption, we cannot see the response Facebook returns to Microsoft Entra.

Could a Microsoft Entra External ID engineer confirm:

  1. What Facebook response causes OAuth2IdPAuthCodeRedemptionUserError in this scenario?
  2. Is there a known compatibility issue between the built-in Entra External ID Facebook identity provider and current Facebook Login/Graph API behavior?
  3. Is there any additional Facebook or Entra configuration required for the current built-in provider?

We can provide tenant ID, application ID, identity-provider ID, Meta App ID, additional correlation/trace IDs, and other diagnostic information privately if a Microsoft engineer needs them.We are using Microsoft Entra External ID with a sign-up/sign-in user flow and the built-in Facebook external identity provider.

Google and Microsoft identity-provider sign-in work successfully with the same user flow. Facebook authentication, 2FA, and consent also complete successfully on Facebook. Facebook then redirects back to Microsoft Entra with an authorization code.

The failure occurs after that redirect, when Microsoft Entra appears to redeem the Facebook authorization code. The browser receives:

AADSTS40015: OAuth2IdPAuthCodeRedemptionUserError

We have verified the following:

  1. The Meta app is Live/published.
  2. email and public_profile have been approved.
  3. Client OAuth Login and Web OAuth Login are enabled.
  4. HTTPS and strict redirect URI matching are enabled.
  5. The Microsoft Entra External ID Facebook redirect URIs are configured in Meta.
  6. We re-entered the current Meta App Secret in the Entra Facebook identity-provider configuration and reproduced the failure with a completely new authentication attempt afterward.
  7. Google and Microsoft federation continue to work through the same External ID user flow.
  8. The failure happens before the Facebook customer is created in the External ID tenant, so our tenant sign-in logs do not expose the underlying Facebook token-redemption error.

A fresh failure after updating the Facebook App Secret occurred at:

2026-09-28 01:38:24 UTC

Error:

AADSTS40015 / OAuth2IdPAuthCodeRedemptionUserError

Trace ID:

c603c308-8bd3-4be6-a702-a834f29f0100

Correlation ID:

01a0e5a8-c564-7f72-bbd5-d8da1e8b9686

An earlier attempt produced the same error with a different trace/correlation ID.

We also observed that the Entra built-in Facebook integration appears to reference Facebook Graph API v19.0, while Facebook handles the request using a currently supported API version. We do not know whether this is related and are not assuming it is the cause.

Because the failure occurs during server-side authorization-code redemption, we cannot see the response Facebook returns to Microsoft Entra.

Could a Microsoft Entra External ID engineer confirm:

  1. What Facebook response causes OAuth2IdPAuthCodeRedemptionUserError in this scenario?
  2. Is there a known compatibility issue between the built-in Entra External ID Facebook identity provider and current Facebook Login/Graph API behavior?
  3. Is there any additional Facebook or Entra configuration required for the current built-in provider?

We can provide tenant ID, application ID, identity-provider ID, Meta App ID, additional correlation/trace IDs, and other diagnostic information privately if a Microsoft engineer needs them.

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.