Managing external identities to enable secure access for partners, customers, and other non-employees
Entra External ID: Sign in with Apple doesn't pre-fill first/last name. Apple sends user.name but Entra holds null at OnAttributeCollectionStart
Summary
In an external tenant with the built-in Apple identity provider, a brand-new Apple sign-up shows the hosted attribute collection page with First name, Last name and Display name blank. The same user flow with Google pre-fills them, and email pre-fills for Apple. The Apple GA announcement says "Entra will automatically prefill user information from Apple, such as name, last name, and email address."
I can show that Apple does send the name to Entra, but Entra doesn't hold it by the time the attribute collection page is built.
Setup
- External tenant (Entra External ID for customers), built-in Apple provider (External Identities → All identity providers → Apple: Services ID, Team ID, Key ID, .p8 key).
- Self-service sign-up flow with Email + password, Google and Apple. The attribute collection page collects
givenName,surnameanddisplayName(all required and editable, no default values) plus one custom boolean. - No custom authentication extensions on the attribute collection events (except for the temporary probe below).
- Client: MSAL.js
loginPopupwithdomain_hint=apple.
Repro
- Use an Apple ID that has never authorized this Services ID (first authorization).
- Start sign-in with
domain_hint=appleand complete Apple's consent screen, sharing name and email. - The attribute collection page appears.
Expected: names pre-filled from Apple Actual: email pre-filled, names blank.
What I checked
- Scopes requested. Entra's authorize redirect to Apple uses
scope=openid email nameandresponse_mode=form_post. - Apple sends the name. A browser capture of Apple's form_post to
https://<tenant>.ciamlogin.com/<tenant-id>/federation/oauth2(first authorization) contains auserfield:user={"name":{"firstName":"<first>","lastName":"<last>"},"email":"<email>"}(Apple's ID token itself has no name claims.) - Entra doesn't hold it. I temporarily attached an
OnAttributeCollectionStartcustom authentication extension to the flow that only logs the request body and returnscontinueWithDefaultBehavior. For a fresh Apple sign-up (first authorization),userSignUpInfowas:
So the"attributes": { "displayName": { "value": null, "attributeType": "builtIn" }, "givenName": { "value": null, "attributeType": "builtIn" }, "surname": { "value": null, "attributeType": "builtIn" }, "extension_<id>_termsOfUse": { "value": null, "attributeType": "directorySchemaExtension" } }, "identities": [ { "signInType": "federated", "issuer": "https://appleid.apple.com<tenant-id>", "issuerAssignedId": "<apple sub>" } ]userform field appears to be dropped, while ID-token claims (email) are used. - No mapping to configure. The built-in Apple provider (
appleManagedIdentityProviderin Graph) exposes onlyserviceId,developerId,keyIdandcertificateData. There is no claims-mapping setting, and OIDC claims mapping covers ID-token claims only.
Questions
- Is the built-in Apple provider supposed to map
user.name.firstName/lastNametogivenName/surname(anddisplayName)? If yes, is this a known issue? - If it isn't supported, can the announcement and docs be corrected, and is there a supported way to get names pre-filled?
- Since Apple only sends the name on first authorization, is there any supported way to read it, for example in an
OnAttributeCollectionStartorOnAttributeCollectionSubmitextension?