Sign-in with "Accounts in this organizational directory only - single tenant" not work with MSAL Android library

Viewed 252

We are having a serious problem when trying to log in via Azure AD Single-tenant. We've read many forums and many other issues and no solution or answer seems to explain how to correctly configure a native android application, using msal library, to work as it should. The error says that we are using an incompatible endpoint, but there is no way to force an endpoint in the current configuration of the msal.config file. We are currently with our hands tied.

We did all the setup correctly. We chose "Accounts in this organizational directory only - single tenant" in Supported Account Types. We configure the return URLs using package name + sha when adding the Android platform. We configured msal_config.json as shown:

{
  "client_id": "my-client-id",
  "redirect_uri": "msauth://my-package-name/sha",
  "broker_redirect_uri_registered": true,
  "authorities": [
    {
      "type": "AAD",
      "audience": {
        "type": "AzureADMyOrg",
        "tenant_id": "my-tenant-id"
      },
      "default": true 
    }
  ]
}

We configure the intent-filter in android manifest as shown:

<activity
      android:name="com.microsoft.identity.client.BrowserTabActivity">
      <intent-filter>
        <action android:name="android.intent.action.VIEW" />
        <category android:name="android.intent.category.DEFAULT" />
        <category android:name="android.intent.category.BROWSABLE" />
        <data
          android:scheme="msauth"
          android:host="my-package-name"
          android:path="/sha" />
      </intent-filter>
    </activity>

It was expected that the token would be returned and the login process would complete.

The login process runs well halfway through. The app correctly opens the Microsoft login screen, you can fill in the user's email and password, but when you go to login, this error appears in the android LOG:

Application 'my-tenant-id-here'(PORTAL_APPGAMIFICATION) is not configured as a multi-tenant application. Usage of the /common endpoint is not supported for such applications created after '10/15/2018'. Use a tenant-specific endpoint or configure the application to be multi-tenant.

We don't want multi-tenant. We don't want any logins that aren't from within our organization's directory. It makes no sense to reconfigure Azure AD to "multi-tenant", the library should work fine with the single-tenant option.

0 Answers
Related