Managing external identities to enable secure access for partners, customers, and other non-employees
How is authentication state handled in Microsoft Entra External ID?
Microsoft Entra External ID: What happens behind the authentication flow at the HTTP/session level?
Hello,
I’m a self-taught software developer and Python programmer with around four years of experience. Over the past few years, I’ve become particularly interested in identity and authentication, especially Microsoft B2C / CIAM and how authentication works at the HTTP and protocol levels.
While studying authentication flows, I’ve been trying to understand the relationship between the different states involved in a modern External ID authentication flow.
For example, from a high-level perspective, I’m looking at a flow similar to:
Authorization Request
↓
Session / State Establishment
↓
CSRF Protection
↓
Authentication
↓
OTP / MFA
↓
Token Issuance
↓
Authenticated Session
I have been implementing educational proof-of-concept projects in Python to better understand these concepts, including HTTP session management, CSRF state, token handling, OTP/MFA workflows, and API interactions.
My question is:
From the perspective of Microsoft Entra External ID, which parts of this conceptual flow should be considered client-side state, server-side state, or protocol-level state, and what is the recommended way for a developer to reason about these states when analyzing an authentication flow?
I’m particularly interested in understanding this correctly from an architectural perspective rather than simply reproducing a sequence of HTTP requests.
I’ve documented some of my educational work here:
GitHub: https://github.com/dev-nayef
I’d appreciate any clarification or recommended Microsoft documentation that could help me better understand the architecture behind these flows.
Thank you.