A cloud-based identity and access management service for securing user authentication and resource access
Static Web Apps built-in auth: sign-in loop in Edge only, Entra sign-in logs show Success every time
We have an Azure Static Web App (Free→Standard tier, using the built-in/generic Azure AD identity provider, no custom provider configured) where users on Microsoft Edge get stuck in a repeating sign-in loop: Microsoft's sign-in page loads, shows "Trying to sign you in…", goes blank, and redirects back to Microsoft sign-in again — repeating indefinitely. The exact same account on the exact same machine signs in instantly and correctly on Google Chrome.
What we've already ruled out (exhaustively tested, same affected accounts/machines):
- Full cookie and site-data clear for both
login.microsoftonline.comand our domain - Full browser cache clear and PC restart
- No browser extensions installed (checked including hidden/dev-mode-only ones)
- Edge Tracking Prevention disabled for the site
- "Block third-party cookies" already disabled
- Device's Entra work-account registration disconnected and reconnected (
dsregcmd /statusconfirmed clean re-registration) - No duplicate device objects in Entra ID
-
edge://policyshows no relevant enterprise policy (one unrelated policy only) - Conditional Access: only one policy exists tenant-wide, Report-only, unscoped, MFA-only — not enforcing anything
- Intune device compliance: device shows "Not applicable" (no compliance policy assigned) but no CA policy requires compliance, so this is unrelated
- A completely fresh Edge profile (not just InPrivate) reproduces the same loop
- Site permissions (Pop-ups/redirects, JavaScript, etc.) checked across every domain in the chain — all default or explicitly allowed
- Disabling MSAL's native broker option in our own app's client code — no change (though this occurs before our app code even loads, as the loop happens entirely within the SWA broker's own flow)
Incognito/InPrivate mode works correctly — same account, same machine. So does a completely unrelated browser (Chrome) in a normal, non-private window.
Given authentication succeeds every time per Entra's own logs, and the failure is isolated to Edge specifically within the Static Web Apps built-in broker's own post-auth flow, has anyone seen this specific combination before, or know what else differs between Edge and other Chromium browsers at this exact step?