github / github/copilot-cli

Desktop app 1.1.17:  COPILOT_ENTRA_AUTH_AUD  (EMU audience) breaks MCP Entra sign-in with  ENTRA_CONFIG 2002 - CLI on the same machine works

Offen
#4,796 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

triage
Vorherrschende Sprache
Shell
Sterne
11.2k
Forks
1.9k
Ø Merge
14 Std. 16 Min.
Gemergte PRs (30 T.)
6

Beschreibung

Describe the bug

Environment

Item Detail
Failing GitHub Copilot desktop app 1.1.17, Windows
Bundled CLI runtime 1.0.83 (resources/copilot-sdk/cliVersion.d.ts)
Machine Windows 11, Entra-joined, GitHub EMU configured
Working @github/copilot CLI on the same machine, same variable set
Working Desktop app 1.1.17 on macOS, that build contains no OneAuth code path
Related #4660 (WAM landed in 1.0.81; fallback fix in 1.0.82, present in 1.0.83 and still failing)
The bug

Windows devices configured for GitHub Enterprise Managed Users carry a machine-scope variable:

COPILOT_ENTRA_AUTH_AUD = "some-value"
                     = "GitHub Enterprise Managed User (OIDC)"  (GitHub's tenant)

It exists for Copilot's own Entra to GitHub token exchange. Since the WAM/OneAuth MCP path landed (#4660), it also reaches MCP sign-in, pinning a cross-tenant audience while the authority is the customer's own tenant. OneAuth rejects the configuration before any network call:

Request session.mcp.oauth.login failed: Microsoft Entra sign-in for
https://<our-mcp-server>/mcp/ failed: ENTRA_CONFIG: the authenticator
rejected the configuration [code 2002, tag 7q6cl].
Set COPILOT_ENTRA_DISABLE_ONEAUTH=1 to sign in through the browser instead.
Three observations that isolate it to the OneAuth path
  1. Clearing the variable for a single process fixes it, with no client or server change:
Remove-Item Env:\COPILOT_ENTRA_AUTH_AUD
Start-Process "$env:LOCALAPPDATA\Programs\GitHub Copilot\github.exe"

Sign-in then succeeds immediately.

  1. The CLI works on the same machine with the machine-scope variable still set, consistent with the release note that machines without the broker library keep the browser flow.

  2. macOS 1.1.17 works. That build contains no OneAuth strings at all, so the variable is never consumed.

Steps to reproduce
  1. Windows machine with COPILOT_ENTRA_AUTH_AUD set machine-wide (any EMU-configured device).
  2. Add an Entra-protected MCP server whose API lives in a different tenant.
  3. Sign in from the MCP tab. Fails 100%.
  4. Same server, same machine, via the CLI. Succeeds.
Expected behavior

MCP token acquisition ignores COPILOT_ENTRA_AUTH_AUD, and an ENTRA_CONFIG rejection falls back to the browser flow rather than failing hard.

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Beginne damit, die gebündelte CLI-Laufzeit der Desktop-App in resources/copilot-sdk/cliVersion.d.ts mit dem funktionierenden @github/copilot-CLI-Verhalten unter Windows zu vergleichen. Reproduziere die MCP-Anmeldung mit gesetztem COPILOT_ENTRA_AUTH_AUD, dann ohne diese Variable und mit COPILOT_ENTRA_DISABLE_ONEAUTH=1. Erledigt ist dies, wenn die MCP-Anmeldung die Copilot-Zielgruppe ignoriert und nach einer ENTRA_CONFIG-Ablehnung auf den Browser zurückfällt.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
github
Bereich
authentication, cli, desktop-dev
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Aktiv
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
48/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.