Desktop app 1.1.17: COPILOT_ENTRA_AUTH_AUD (EMU audience) breaks MCP Entra sign-in with ENTRA_CONFIG 2002 - CLI on the same machine works
Dieses Issue hat noch niemand übernommen.
- Vorherrschende Sprache
- Shell
- Sterne
- 11.2k
- Forks
- 1.9k
- Ø Merge
- 14 Std. 16 Min.
- Gemergte PRs (30 T.)
- 6
Beschreibung
Describe the bug
Environment
| Item | Detail |
|---|---|
| Failing | GitHub Copilot desktop app 1.1.17, Windows |
| Bundled CLI runtime | 1.0.83 (resources/copilot-sdk/cliVersion.d.ts) |
| Machine | Windows 11, Entra-joined, GitHub EMU configured |
| Working | @github/copilot CLI on the same machine, same variable set |
| Working | Desktop app 1.1.17 on macOS, that build contains no OneAuth code path |
| Related | #4660 (WAM landed in 1.0.81; fallback fix in 1.0.82, present in 1.0.83 and still failing) |
The bug
Windows devices configured for GitHub Enterprise Managed Users carry a machine-scope variable:
COPILOT_ENTRA_AUTH_AUD = "some-value"
= "GitHub Enterprise Managed User (OIDC)" (GitHub's tenant)
It exists for Copilot's own Entra to GitHub token exchange. Since the WAM/OneAuth MCP path landed (#4660), it also reaches MCP sign-in, pinning a cross-tenant audience while the authority is the customer's own tenant. OneAuth rejects the configuration before any network call:
Request session.mcp.oauth.login failed: Microsoft Entra sign-in for
https://<our-mcp-server>/mcp/ failed: ENTRA_CONFIG: the authenticator
rejected the configuration [code 2002, tag 7q6cl].
Set COPILOT_ENTRA_DISABLE_ONEAUTH=1 to sign in through the browser instead.
Three observations that isolate it to the OneAuth path
- Clearing the variable for a single process fixes it, with no client or server change:
Remove-Item Env:\COPILOT_ENTRA_AUTH_AUD
Start-Process "$env:LOCALAPPDATA\Programs\GitHub Copilot\github.exe"
Sign-in then succeeds immediately.
-
The CLI works on the same machine with the machine-scope variable still set, consistent with the release note that machines without the broker library keep the browser flow.
-
macOS 1.1.17 works. That build contains no OneAuth strings at all, so the variable is never consumed.
Steps to reproduce
- Windows machine with
COPILOT_ENTRA_AUTH_AUDset machine-wide (any EMU-configured device). - Add an Entra-protected MCP server whose API lives in a different tenant.
- Sign in from the MCP tab. Fails 100%.
- Same server, same machine, via the CLI. Succeeds.
Expected behavior
MCP token acquisition ignores COPILOT_ENTRA_AUTH_AUD, and an ENTRA_CONFIG rejection falls back to the browser flow rather than failing hard.
Beitragsleitfaden
Erste Schritte
- Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
- Forke das Repository und arbeite in einem Branch.
- Öffne einen Pull Request, der die Issue-Nummer nennt.
Rechercherichtung
Beginne damit, die gebündelte CLI-Laufzeit der Desktop-App in resources/copilot-sdk/cliVersion.d.ts mit dem funktionierenden @github/copilot-CLI-Verhalten unter Windows zu vergleichen. Reproduziere die MCP-Anmeldung mit gesetztem COPILOT_ENTRA_AUTH_AUD, dann ohne diese Variable und mit COPILOT_ENTRA_DISABLE_ONEAUTH=1. Erledigt ist dies, wenn die MCP-Anmeldung die Copilot-Zielgruppe ignoriert und nach einer ENTRA_CONFIG-Ablehnung auf den Browser zurückfällt.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- github
- Bereich
- authentication, cli, desktop-dev
- Issue-Typ
- Bug
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Aktiv
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 48/100