Microsoft Entra External ID custom OIDC federation redeems the same EU Login authorization code twice (AADSTS40016)

Andrea Zacconi 0 Punti di reputazione
2026-05-15T07:03:18.6766667+00:00

This issue is about Microsoft Entra External ID custom OIDC federation. I could not find a specific Microsoft Entra / External ID tag in the available list, so I selected the closest Azure category.

We configured a custom OpenID Connect federation between Microsoft Entra External ID and EU Login by following the official Microsoft documentation. However, the login flow is failing and our application receives the following error on the OIDC callback:

AADSTS40016: The Identity Provider returned an error.

With the latest example:

  • Trace ID: 3931bdc7-d029-48d4-b30c-1ca438b80000
  • Correlation ID: acac90ac-6b1b-40f4-888b-2627a303d362
  • Timestamp: 2026-05-15 06:49:58Z

Application log excerpt:

fail: Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler[12]

Message contains error: 'access_denied', error_description: 'AADSTS40016: The Identity Provider returned an error. Trace ID: 3931bdc7-d029-48d4-b30c-1ca438b80000 Correlation ID: acac90ac-6b1b-40f4-888b-2627a303d362 Timestamp: 2026-05-15 06:49:58Z', error_uri: 'https://lstestexternalentraid.ciamlogin.com/error?code=40016'.

We also contacted the external identity provider, EU Login. Their team told us that the same authorization code is being redeemed twice on their side. According to them, this is causing the failure because the authorization code is single-use.

From our application logs, during the failing attempt we do not receive an authorization code on /signin-oidc. We only receive the final error response from Entra External ID.

At this point, we need help understanding where the issue is: is Microsoft Entra External ID redeeming the same authorization code twice during the federation flow? Or is there something on the EU Login side that needs deeper investigation?

We would like Microsoft to investigate this from the Entra External ID side as well, because from the evidence we collected the problem seems to happen before the flow returns successfully to our application.

If needed, we can provide: sanitized application logs, sanitized EU Login feedback/log details, our custom OIDC provider configuration in Entra External ID

At the moment, the behavior suggests that the issue is happening in the federation layer between Microsoft Entra External ID and EU Login, not in our local application. We therefore ask Microsoft to investigate this flow in depth and confirm whether Entra is performing duplicate authorization code redemption or whether there is a known interoperability issue with this custom OIDC federation setup.

Configurazione app di Azure
Configurazione app di Azure

Un servizio di Azure che fornisce archiviazione universale ospitata per le configurazioni app di Azure.


1 risposta

Ordina per: Più utili
  1. VEMULA SRISAI 14,070 Punti di reputazione Personale Esterno Microsoft Moderatore
    2026-05-15T10:45:59.9833333+00:00

    Hello Andrea Zacconi,

    Thank you for the detailed information and logs.

    Based on your description, the issue is occurring within the federation flow between Microsoft Entra External ID and the EU Login IdP, and not in your application. The AADSTS40016 error indicates that Entra External ID received an error response from the external identity provider, which aligns with the feedback from EU Login stating that the authorization code is being rejected due to reuse (single-use violation).

    In a standard OIDC federation flow, Microsoft Entra External ID acts as an intermediary and is expected to redeem the authorization code once at the IdP token endpoint before issuing its own response back to the application. Since your application is not receiving an authorization code at /signin-oidc and only receives the final error, this confirms that the failure happens before the response is returned to your app, i.e., during the Entra ↔ EU Login exchange.

    At present, there is no known documented behavior where Entra External ID performs duplicate authorization code redemption in a valid flow. When an IdP reports duplicate redemption, it is typically associated with one of the following conditions at the federation boundary:

    • Retry or parallel token requests (for example, due to transient failures or timeouts)
    • Misconfiguration of redirect URI or token endpoint leading to repeated exchanges

    IdP-side validation or handling causing the same code to be treated as reused

    Recommended next steps

    To isolate the root cause, please validate the following:

    • From EU Login side:
      • Confirm if multiple token requests are received for the same authorization code
      • Check timestamps to determine if they are near-simultaneous (parallel) or retries
      From Entra configuration:
      • Ensure the redirect URI exactly matches the federation endpoints configured in both systems
        • Verify token endpoint and client authentication settings are aligned
    • From testing perspective:
    • Execute the flow using Entra “Run user flow” to confirm whether the issue reproduces without the application
      • If possible, capture a network trace (HAR/Fiddler) to validate if multiple backend calls are triggered.

    La risposta è stata utile?

    1 persona ha trovato utile questa risposta.

Risposta

Le risposte possono essere contrassegnate come "Accettata" dall'autore della domanda e "Consigliata" dai moderatori, in modo da consentire agli utenti di sapere che la risposta ha risolto il problema dell'autore.