Entra External ID: Sign in with Apple doesn't pre-fill first/last name. Apple sends user.name but Entra holds null at OnAttributeCollectionStart

LGem 0 Reputation points
2026-09-25T00:44:27.7333333+00:00

Summary

In an external tenant with the built-in Apple identity provider, a brand-new Apple sign-up shows the hosted attribute collection page with First name, Last name and Display name blank. The same user flow with Google pre-fills them, and email pre-fills for Apple. The Apple GA announcement says "Entra will automatically prefill user information from Apple, such as name, last name, and email address."

I can show that Apple does send the name to Entra, but Entra doesn't hold it by the time the attribute collection page is built.

Setup

  • External tenant (Entra External ID for customers), built-in Apple provider (External Identities → All identity providers → Apple: Services ID, Team ID, Key ID, .p8 key).
  • Self-service sign-up flow with Email + password, Google and Apple. The attribute collection page collects givenName, surname and displayName (all required and editable, no default values) plus one custom boolean.
  • No custom authentication extensions on the attribute collection events (except for the temporary probe below).
  • Client: MSAL.js loginPopup with domain_hint=apple.

Repro

  1. Use an Apple ID that has never authorized this Services ID (first authorization).
  2. Start sign-in with domain_hint=apple and complete Apple's consent screen, sharing name and email.
  3. The attribute collection page appears.

Expected: names pre-filled from Apple Actual: email pre-filled, names blank.

What I checked

  1. Scopes requested. Entra's authorize redirect to Apple uses scope=openid email name and response_mode=form_post.
  2. Apple sends the name. A browser capture of Apple's form_post to https://<tenant>.ciamlogin.com/<tenant-id>/federation/oauth2 (first authorization) contains a user field: user={"name":{"firstName":"<first>","lastName":"<last>"},"email":"<email>"} (Apple's ID token itself has no name claims.)
  3. Entra doesn't hold it. I temporarily attached an OnAttributeCollectionStart custom authentication extension to the flow that only logs the request body and returns continueWithDefaultBehavior. For a fresh Apple sign-up (first authorization), userSignUpInfo was:
       "attributes": {
         "displayName": { "value": null, "attributeType": "builtIn" },
         "givenName":   { "value": null, "attributeType": "builtIn" },
         "surname":     { "value": null, "attributeType": "builtIn" },
         "extension_<id>_termsOfUse": { "value": null, "attributeType": "directorySchemaExtension" }
       },
       "identities": [ { "signInType": "federated", "issuer": "https://appleid.apple.com<tenant-id>", "issuerAssignedId": "<apple sub>" } ]
    
    So the user form field appears to be dropped, while ID-token claims (email) are used.
  4. No mapping to configure. The built-in Apple provider (appleManagedIdentityProvider in Graph) exposes only serviceId, developerId, keyId and certificateData. There is no claims-mapping setting, and OIDC claims mapping covers ID-token claims only.

Questions

  1. Is the built-in Apple provider supposed to map user.name.firstName / lastName to givenName / surname (and displayName)? If yes, is this a known issue?
  2. If it isn't supported, can the announcement and docs be corrected, and is there a supported way to get names pre-filled?
  3. Since Apple only sends the name on first authorization, is there any supported way to read it, for example in an OnAttributeCollectionStart or OnAttributeCollectionSubmit extension?
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.