Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

ISSUE

"AADSTS5007413: Authentication with external provider cannot be completed due to invalid provider discovery response".

Image RemovedImage Added

CAUSE

From Februrary 2026 Microsoft made a change so that they would strictly only accept the Discovery URL and the JWKS URI in the following format:

...

You should see the values have automatically been updated.  If not, click on the Load Default button at the top

Image Modified

Copy the new Discovery URL

On Azure, navigate to your EAM Policy and Click on Configure

Paste in the new Discovery URL as per the example below.

Image Added


Save the change.

You may have to wait up to 20 minutes for Microsoft to refresh this configuration.  Once done, please test again