github / github/copilot-cli

Desktop app 1.1.17:  COPILOT_ENTRA_AUTH_AUD  (EMU audience) breaks MCP Entra sign-in with  ENTRA_CONFIG 2002 - CLI on the same machine works

オープン
#4,796 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

triage
主要言語
Shell
スター
11.2k
フォーク
1.9k
平均マージ
14時間 16分
マージ済み PR(30日)
6

説明

Describe the bug

Environment

Item Detail
Failing GitHub Copilot desktop app 1.1.17, Windows
Bundled CLI runtime 1.0.83 (resources/copilot-sdk/cliVersion.d.ts)
Machine Windows 11, Entra-joined, GitHub EMU configured
Working @github/copilot CLI on the same machine, same variable set
Working Desktop app 1.1.17 on macOS, that build contains no OneAuth code path
Related #4660 (WAM landed in 1.0.81; fallback fix in 1.0.82, present in 1.0.83 and still failing)
The bug

Windows devices configured for GitHub Enterprise Managed Users carry a machine-scope variable:

COPILOT_ENTRA_AUTH_AUD = "some-value"
                     = "GitHub Enterprise Managed User (OIDC)"  (GitHub's tenant)

It exists for Copilot's own Entra to GitHub token exchange. Since the WAM/OneAuth MCP path landed (#4660), it also reaches MCP sign-in, pinning a cross-tenant audience while the authority is the customer's own tenant. OneAuth rejects the configuration before any network call:

Request session.mcp.oauth.login failed: Microsoft Entra sign-in for
https://<our-mcp-server>/mcp/ failed: ENTRA_CONFIG: the authenticator
rejected the configuration [code 2002, tag 7q6cl].
Set COPILOT_ENTRA_DISABLE_ONEAUTH=1 to sign in through the browser instead.
Three observations that isolate it to the OneAuth path
  1. Clearing the variable for a single process fixes it, with no client or server change:
Remove-Item Env:\COPILOT_ENTRA_AUTH_AUD
Start-Process "$env:LOCALAPPDATA\Programs\GitHub Copilot\github.exe"

Sign-in then succeeds immediately.

  1. The CLI works on the same machine with the machine-scope variable still set, consistent with the release note that machines without the broker library keep the browser flow.

  2. macOS 1.1.17 works. That build contains no OneAuth strings at all, so the variable is never consumed.

Steps to reproduce
  1. Windows machine with COPILOT_ENTRA_AUTH_AUD set machine-wide (any EMU-configured device).
  2. Add an Entra-protected MCP server whose API lives in a different tenant.
  3. Sign in from the MCP tab. Fails 100%.
  4. Same server, same machine, via the CLI. Succeeds.
Expected behavior

MCP token acquisition ignores COPILOT_ENTRA_AUTH_AUD, and an ENTRA_CONFIG rejection falls back to the browser flow rather than failing hard.

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

調査の方向性

まず、resources/copilot-sdk/cliVersion.d.ts にあるデスクトップアプリのバンドル済み CLI ランタイムを、Windows で動作する @github/copilot CLI の挙動と比較します。COPILOT_ENTRA_AUTH_AUD を設定した状態で MCP サインインを再現し、次にそれを削除した状態、さらに COPILOT_ENTRA_DISABLE_ONEAUTH=1 を設定した状態で再現します。MCP サインインが Copilot の audience を無視し、ENTRA_CONFIG による拒否の後にブラウザーへフォールバックすれば完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
github
領域
authentication, cli, desktop-dev
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
活発
明瞭さ
おおむね明確
初心者へのやさしさ
48/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。