How is authentication state handled in Microsoft Entra External ID?

Nayef Ashour 0 Reputation points
2026-10-05T10:00:51.9833333+00:00

Microsoft Entra External ID: What happens behind the authentication flow at the HTTP/session level?

Hello,

I’m a self-taught software developer and Python programmer with around four years of experience. Over the past few years, I’ve become particularly interested in identity and authentication, especially Microsoft B2C / CIAM and how authentication works at the HTTP and protocol levels.

While studying authentication flows, I’ve been trying to understand the relationship between the different states involved in a modern External ID authentication flow.

For example, from a high-level perspective, I’m looking at a flow similar to:

Authorization Request
        ↓
Session / State Establishment
        ↓
CSRF Protection
        ↓
Authentication
        ↓
OTP / MFA
        ↓
Token Issuance
        ↓
Authenticated Session

I have been implementing educational proof-of-concept projects in Python to better understand these concepts, including HTTP session management, CSRF state, token handling, OTP/MFA workflows, and API interactions.

My question is:

From the perspective of Microsoft Entra External ID, which parts of this conceptual flow should be considered client-side state, server-side state, or protocol-level state, and what is the recommended way for a developer to reason about these states when analyzing an authentication flow?

I’m particularly interested in understanding this correctly from an architectural perspective rather than simply reproducing a sequence of HTTP requests.

I’ve documented some of my educational work here:

GitHub: https://github.com/dev-nayef

I’d appreciate any clarification or recommended Microsoft documentation that could help me better understand the architecture behind these flows.

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.