Desktop app 1.1.17: COPILOT_ENTRA_AUTH_AUD (EMU audience) breaks MCP Entra sign-in with ENTRA_CONFIG 2002 - CLI on the same machine works
Personne n'a encore pris cette issue.
- Langage dominant
- Shell
- Étoiles
- 11.2k
- Forks
- 1.9k
- Merge moyen
- 14 h 16 min
- PR mergées (30 j)
- 6
Description
Describe the bug
Environment
| Item | Detail |
|---|---|
| Failing | GitHub Copilot desktop app 1.1.17, Windows |
| Bundled CLI runtime | 1.0.83 (resources/copilot-sdk/cliVersion.d.ts) |
| Machine | Windows 11, Entra-joined, GitHub EMU configured |
| Working | @github/copilot CLI on the same machine, same variable set |
| Working | Desktop app 1.1.17 on macOS, that build contains no OneAuth code path |
| Related | #4660 (WAM landed in 1.0.81; fallback fix in 1.0.82, present in 1.0.83 and still failing) |
The bug
Windows devices configured for GitHub Enterprise Managed Users carry a machine-scope variable:
COPILOT_ENTRA_AUTH_AUD = "some-value"
= "GitHub Enterprise Managed User (OIDC)" (GitHub's tenant)
It exists for Copilot's own Entra to GitHub token exchange. Since the WAM/OneAuth MCP path landed (#4660), it also reaches MCP sign-in, pinning a cross-tenant audience while the authority is the customer's own tenant. OneAuth rejects the configuration before any network call:
Request session.mcp.oauth.login failed: Microsoft Entra sign-in for
https://<our-mcp-server>/mcp/ failed: ENTRA_CONFIG: the authenticator
rejected the configuration [code 2002, tag 7q6cl].
Set COPILOT_ENTRA_DISABLE_ONEAUTH=1 to sign in through the browser instead.
Three observations that isolate it to the OneAuth path
- Clearing the variable for a single process fixes it, with no client or server change:
Remove-Item Env:\COPILOT_ENTRA_AUTH_AUD
Start-Process "$env:LOCALAPPDATA\Programs\GitHub Copilot\github.exe"
Sign-in then succeeds immediately.
-
The CLI works on the same machine with the machine-scope variable still set, consistent with the release note that machines without the broker library keep the browser flow.
-
macOS 1.1.17 works. That build contains no OneAuth strings at all, so the variable is never consumed.
Steps to reproduce
- Windows machine with
COPILOT_ENTRA_AUTH_AUDset machine-wide (any EMU-configured device). - Add an Entra-protected MCP server whose API lives in a different tenant.
- Sign in from the MCP tab. Fails 100%.
- Same server, same machine, via the CLI. Succeeds.
Expected behavior
MCP token acquisition ignores COPILOT_ENTRA_AUTH_AUD, and an ENTRA_CONFIG rejection falls back to the browser flow rather than failing hard.
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Piste de recherche
Commencez par comparer le runtime CLI fourni avec l’application de bureau dans resources/copilot-sdk/cliVersion.d.ts avec le comportement fonctionnel de la CLI @github/copilot sous Windows. Reproduisez la connexion MCP avec COPILOT_ENTRA_AUTH_AUD défini, puis sans cette variable et avec COPILOT_ENTRA_DISABLE_ONEAUTH=1. C’est terminé lorsque la connexion MCP ignore l’audience Copilot et revient au navigateur après un rejet ENTRA_CONFIG.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- github
- Domaine
- authentication, cli, desktop-dev
- Type d'issue
- Bug
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Activité
- Active
- Clarté
- Plutôt claire
- Accessibilité débutants
- 48/100