github / github/copilot-cli

Desktop app 1.1.17:  COPILOT_ENTRA_AUTH_AUD  (EMU audience) breaks MCP Entra sign-in with  ENTRA_CONFIG 2002 - CLI on the same machine works

Abierto
#4,796 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

triage
Lenguaje dominante
Shell
Estrellas
11.2k
Forks
1.9k
Merge medio
14 h 16 min
PR fusionados (30 d)
6

Descripción

Describe the bug

Environment

Item Detail
Failing GitHub Copilot desktop app 1.1.17, Windows
Bundled CLI runtime 1.0.83 (resources/copilot-sdk/cliVersion.d.ts)
Machine Windows 11, Entra-joined, GitHub EMU configured
Working @github/copilot CLI on the same machine, same variable set
Working Desktop app 1.1.17 on macOS, that build contains no OneAuth code path
Related #4660 (WAM landed in 1.0.81; fallback fix in 1.0.82, present in 1.0.83 and still failing)
The bug

Windows devices configured for GitHub Enterprise Managed Users carry a machine-scope variable:

COPILOT_ENTRA_AUTH_AUD = "some-value"
                     = "GitHub Enterprise Managed User (OIDC)"  (GitHub's tenant)

It exists for Copilot's own Entra to GitHub token exchange. Since the WAM/OneAuth MCP path landed (#4660), it also reaches MCP sign-in, pinning a cross-tenant audience while the authority is the customer's own tenant. OneAuth rejects the configuration before any network call:

Request session.mcp.oauth.login failed: Microsoft Entra sign-in for
https://<our-mcp-server>/mcp/ failed: ENTRA_CONFIG: the authenticator
rejected the configuration [code 2002, tag 7q6cl].
Set COPILOT_ENTRA_DISABLE_ONEAUTH=1 to sign in through the browser instead.
Three observations that isolate it to the OneAuth path
  1. Clearing the variable for a single process fixes it, with no client or server change:
Remove-Item Env:\COPILOT_ENTRA_AUTH_AUD
Start-Process "$env:LOCALAPPDATA\Programs\GitHub Copilot\github.exe"

Sign-in then succeeds immediately.

  1. The CLI works on the same machine with the machine-scope variable still set, consistent with the release note that machines without the broker library keep the browser flow.

  2. macOS 1.1.17 works. That build contains no OneAuth strings at all, so the variable is never consumed.

Steps to reproduce
  1. Windows machine with COPILOT_ENTRA_AUTH_AUD set machine-wide (any EMU-configured device).
  2. Add an Entra-protected MCP server whose API lives in a different tenant.
  3. Sign in from the MCP tab. Fails 100%.
  4. Same server, same machine, via the CLI. Succeeds.
Expected behavior

MCP token acquisition ignores COPILOT_ENTRA_AUTH_AUD, and an ENTRA_CONFIG rejection falls back to the browser flow rather than failing hard.

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Línea de trabajo

Empieza comparando el runtime de CLI incluido en la aplicación de escritorio en resources/copilot-sdk/cliVersion.d.ts con el comportamiento de CLI de @github/copilot que funciona en Windows. Reproduce el inicio de sesión de MCP con COPILOT_ENTRA_AUTH_AUD establecido, después elimínalo y hazlo con COPILOT_ENTRA_DISABLE_ONEAUTH=1. Se considera terminado cuando el inicio de sesión de MCP ignora la audiencia de Copilot y recurre al navegador después de un rechazo de ENTRA_CONFIG.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
github
Área
authentication, cli, desktop-dev
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Activo
Claridad
Bastante claro
Aptitud para principiantes
48/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.