Desktop app 1.1.17: COPILOT_ENTRA_AUTH_AUD (EMU audience) breaks MCP Entra sign-in with ENTRA_CONFIG 2002 - CLI on the same machine works
Nobody has claimed this yet.
- Dominant language
- Shell
- Stars
- 11.2k
- Forks
- 1.9k
- Avg merge
- 14h 16m
- Merged PRs (30d)
- 6
Description
Describe the bug
Environment
| Item | Detail |
|---|---|
| Failing | GitHub Copilot desktop app 1.1.17, Windows |
| Bundled CLI runtime | 1.0.83 (resources/copilot-sdk/cliVersion.d.ts) |
| Machine | Windows 11, Entra-joined, GitHub EMU configured |
| Working | @github/copilot CLI on the same machine, same variable set |
| Working | Desktop app 1.1.17 on macOS, that build contains no OneAuth code path |
| Related | #4660 (WAM landed in 1.0.81; fallback fix in 1.0.82, present in 1.0.83 and still failing) |
The bug
Windows devices configured for GitHub Enterprise Managed Users carry a machine-scope variable:
COPILOT_ENTRA_AUTH_AUD = "some-value"
= "GitHub Enterprise Managed User (OIDC)" (GitHub's tenant)
It exists for Copilot's own Entra to GitHub token exchange. Since the WAM/OneAuth MCP path landed (#4660), it also reaches MCP sign-in, pinning a cross-tenant audience while the authority is the customer's own tenant. OneAuth rejects the configuration before any network call:
Request session.mcp.oauth.login failed: Microsoft Entra sign-in for
https://<our-mcp-server>/mcp/ failed: ENTRA_CONFIG: the authenticator
rejected the configuration [code 2002, tag 7q6cl].
Set COPILOT_ENTRA_DISABLE_ONEAUTH=1 to sign in through the browser instead.
Three observations that isolate it to the OneAuth path
- Clearing the variable for a single process fixes it, with no client or server change:
Remove-Item Env:\COPILOT_ENTRA_AUTH_AUD
Start-Process "$env:LOCALAPPDATA\Programs\GitHub Copilot\github.exe"
Sign-in then succeeds immediately.
-
The CLI works on the same machine with the machine-scope variable still set, consistent with the release note that machines without the broker library keep the browser flow.
-
macOS 1.1.17 works. That build contains no OneAuth strings at all, so the variable is never consumed.
Steps to reproduce
- Windows machine with
COPILOT_ENTRA_AUTH_AUDset machine-wide (any EMU-configured device). - Add an Entra-protected MCP server whose API lives in a different tenant.
- Sign in from the MCP tab. Fails 100%.
- Same server, same machine, via the CLI. Succeeds.
Expected behavior
MCP token acquisition ignores COPILOT_ENTRA_AUTH_AUD, and an ENTRA_CONFIG rejection falls back to the browser flow rather than failing hard.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by comparing the desktop app's bundled CLI runtime in resources/copilot-sdk/cliVersion.d.ts with the working @github/copilot CLI behavior on Windows. Reproduce the MCP sign-in with COPILOT_ENTRA_AUTH_AUD set, then with it removed and with COPILOT_ENTRA_DISABLE_ONEAUTH=1. Done means MCP sign-in ignores the Copilot audience and falls back to the browser after an ENTRA_CONFIG rejection.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- authentication, cli, desktop-dev
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100