Repository navigation
Az login on Web Account Manager (WAM) does nto work for professional accounts #34121
Description
Activity
- addedbugThis issue requires a change to an existing behavior in the product in order to be resolved.This issue requires a change to an existing behavior in the product in order to be resolved.
on Sep 23, 2026 azure-client-tools-bot-prd commented
on Sep 23, 2026 More actions2.88.0 is not the latest Azure CLI(2.90.0).
If you haven't already attempted to do so, please upgrade to the latest Azure CLI version by following https://learn.microsoft.com/en-us/cli/azure/update-azure-cli.
- addedcustomer-reportedIssues that are reported by GitHub users external to the Azure organization.Issues that are reported by GitHub users external to the Azure organization.Auto-AssignAuto assign by botAuto assign by botAccountaz login/accountaz login/accountAzure CLI TeamThe command of the issue is owned by Azure CLI teamThe command of the issue is owned by Azure CLI teamquestionThe issue doesn't require a change to the product in order to be resolved. Most issues start as thatThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
on Sep 23, 2026 Thank you for opening this issue, we will look into it.
2.88.0 is not the latest Azure CLI(2.90.0).
If you haven't already attempted to do so, please upgrade to the latest Azure CLI version by following https://learn.microsoft.com/en-us/cli/azure/update-azure-cli.
This might be an issue if the user does not have permissions to manage their apps upgrades.
- removedquestionThe issue doesn't require a change to the product in order to be resolved. Most issues start as thatThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
on Sep 23, 2026 Just upgraded to 2.90.0 cli the bug remains.
Version
PS C:\Users\Pedro Lopes\source\repos\gs1pt-mono-associated-area> az --version azure-cli 2.90.0 core 2.90.0 telemetry 1.1.0 Extensions: automation 1.0.0b2 azure-devops 1.0.6 ml 2.42.0 Dependencies: msal 1.36.0 azure-mgmt-resource 24.0.0 Python location 'C:\Program Files\Microsoft SDKs\Azure\CLI2\python.exe' Config directory 'C:\Users\Pedro Lopes\.azure' Extensions directory 'C:\Users\Pedro Lopes\.azure\cliextensions' Python (Windows) 3.14.6 (tags/v3.14.6:c63aec6, Jun 10 2026, 10:26:10) [MSC v.1944 64 bit (AMD64)] Legal docs and information: aka.ms/AzureCliLegal Your CLI is up-to-date.Trace
PS C:\Users\Pedro Lopes\source\repos\gs1pt-mono-associated-area> az login --debug cli.knack.cli: Command arguments: ['login', '--debug'] cli.knack.cli: __init__ debug log: Enable color in terminal. Enable VT mode. cli.knack.cli: Event: Cli.PreExecute [] cli.knack.cli: Event: CommandParser.OnGlobalArgumentsCreate [<function CLILogging.on_global_arguments at 0x0000018DC7DB9B10>, <function OutputProducer.on_global_arguments at 0x0000018DC82C4A90>, <function CLIQuery.on_global_arguments at 0x0000018DC82F3110>] cli.knack.cli: Event: CommandInvoker.OnPreCommandTableCreate [] cli.azure.cli.core: Using packaged command index for profile 'latest'. cli.azure.cli.core: Found installed extension 'automation' (azext_automation). cli.azure.cli.core: Blending packaged core index with local extension index. cli.azure.cli.core: Modules found from index for 'login': ['azure.cli.command_modules.profile'] cli.azure.cli.core: Loading command modules... cli.azure.cli.core: Name Load Time Groups Commands cli.azure.cli.core: profile 0.003 2 8 cli.azure.cli.core: Loaded command modules: cli.azure.cli.core: Total (1) 0.004 2 8 cli.azure.cli.core: These extensions are not installed and will be skipped: ['azext_ai_examples', 'azext_next'] cli.azure.cli.core: Loading extensions: cli.azure.cli.core: Name Load Time Groups Commands Directory cli.azure.cli.core: Total (0) 0.000 0 0 cli.azure.cli.core: Loaded 2 groups, 8 commands. cli.azure.cli.core: Found a match in the command table. cli.azure.cli.core: Raw command : login cli.azure.cli.core: Command table: login cli.knack.cli: Event: CommandInvoker.OnPreCommandTableTruncate [<function AzCliLogging.init_command_file_logging at 0x0000018DC84A3A00>] cli.azure.cli.core.azlogging: metadata file logging enabled - writing logs to 'C:\Users\Pedro Lopes\.azure\commands\2026-09-23.09-01-45.login.8552.log'. az_command_data_logger: command args: login --debug cli.knack.cli: Event: CommandInvoker.OnPreArgumentLoad [<function register_global_subscription_argument.<locals>.add_subscription_parameter at 0x0000018DC84AB950>] cli.knack.cli: Event: CommandInvoker.OnPostArgumentLoad [] cli.knack.cli: Event: CommandInvoker.OnPostCommandTableCreate [<function register_ids_argument.<locals>.add_ids_arguments at 0x0000018DC84ABC10>, <function register_global_policy_argument.<locals>.add_global_policy_argument at 0x0000018DC84F05C0>, <function register_cache_arguments.<locals>.add_cache_arguments at 0x0000018DC84F0670>, <function register_upcoming_breaking_change_info.<locals>.update_breaking_change_info at 0x0000018DC84F0720>] cli.knack.cli: Event: CommandInvoker.OnCommandTableLoaded [] cli.knack.cli: Event: CommandInvoker.OnPreParseArgs [] cli.knack.cli: Event: CommandInvoker.OnPostParseArgs [<function OutputProducer.handle_output_argument at 0x0000018DC82C4B40>, <function CLIQuery.handle_query_parameter at 0x0000018DC82F31C0>, <function register_ids_argument.<locals>.parse_ids_arguments at 0x0000018DC84F0510>] cli.azure.cli.core.auth.persistence: build_persistence: location='C:\\Users\\Pedro Lopes\\.azure\\msal_token_cache.bin', encrypt=True cli.azure.cli.core.auth.binary_cache: load: C:\Users\Pedro Lopes\.azure\msal_http_cache.bin urllib3.util.retry: Converted retries value: 1 -> Retry(total=1, connect=None, read=None, redirect=None, status=None) msal.application: Broker enabled? True msal.application: Falls back to broker._signin_interactively() cli.azure.cli.core.auth.identity: Select the account you want to log in with. For more information on login with Azure CLI, see https://go.microsoft.com/fwlink/?linkid=2271136 msal.broker: [MSAL:0001] INFO SetAuthorityUri:80 Initializing authority from URI 'https://login.microsoftonline.com/organizations' without authority type, detected type 'ms_sts' msal.broker: [MSAL:0002] INFO SetCorrelationId:241 Set correlation ID: 51dfcaed-d1a7-48ac-b0cd-d4d963ce6221 msal.broker: [MSAL:0002] INFO ExecuteInteractiveRequest:1404 The original authority is 'https://login.microsoftonline.com/organizations' msal.broker: [MSAL:0002] WARNING TryNormalizeRealm:2599 No HomeAccountId provided to normalize the realm msal.broker: [MSAL:0002] INFO ExecuteInteractiveRequest:1415 The normalized realm is '' msal.broker: [MSAL:0002] INFO ModifyAndValidateAuthParameters:228 Additional query parameter added successfully. Key: 'msal_client_sku' Value: 'MSAL.Python' msal.broker: [MSAL:0002] INFO ModifyAndValidateAuthParameters:228 Additional query parameter added successfully. Key: 'msal_client_ver' Value: '1.36.0' msal.broker: [MSAL:0002] INFO ModifyAndValidateAuthParameters:228 Additional query parameter added successfully. Key: 'msal_gui_thread' Value: 'true' msal.broker: [MSAL:0002] INFO ModifyAndValidateAuthParameters:228 Additional query parameter added successfully. Key: 'msal_request_type' Value: 'consumer_passthrough' msal.broker: [MSAL:0002] INFO ModifyAndValidateAuthParameters:251 Authority Realm: organizations msal.broker: [MSAL:0002] WARNING TryEnqueueMsaDeviceCredentialAcquisitionAndContinue:1297 MsaDeviceOperationProvider is not available. Not attempting to register the device. msal.broker: [MSAL:0003] WARNING ReturnResponseDueToMissingParameter:749 Attempted to read cache with a non-normalized realm, access token and ID token reads will fail msal.broker: [MSAL:0003] WARNING ReturnResponseDueToMissingParameter:777 Missing Required parameters, but found no account to return. msal.broker: [MSAL:0003] WARNING ReadAccountById:652 Account id is empty - account not found msal.broker: [MSAL:0003] INFO GetCurrentWindowHandleForUIFlow:501 Specified brokerWindowHandle is valid. msal.broker: [MSAL:0004] INFO CreateRequestForProviderWithProperties:859 Client-xtra-sku: MSAL.Python|1.36.0,|0.20.6,|,|,|10.1.1 msal.broker: [MSAL:0004] INFO AddClientSystemInfoToRequest:1250 Client-xtra-sku: MSAL.Python|1.36.0,|0.20.6,|,|,|10.1.1- addedRequest X Engineering AgentRequest X Engineering Agent testing and reviewRequest X Engineering Agent testing and review
on Sep 24, 2026 microsoft-github-policy-service commented
on Sep 24, 2026 ContributorMore actions🔔 Routing this issue to @Azure/act-identity-squad.
x-engineering-agent commented
on Sep 24, 2026 ContributorMore actionsBug Analysis
Affected area:
profile/ Azure CLI core authentication, inAzure/azure-cli(not an extension). Target branch:dev.Observed versus expected / reproduction quality
On Windows with no work/school account associated with Windows, run
az loginand select the professional/work account option in the WAM dialog. The reporter observes a stalled modal and CLI, with no account-entry prompt and no traceback. Expected: an account-entry/authentication dialog or browser flow that permits entering the corporate email, completing authentication, or cancelling without an indefinite wait.The original report includes Azure CLI 2.88.0 debug output; the reporter subsequently confirms the same bug after upgrading to 2.90.0, with MSAL 1.36.0 and Windows Python 3.14.6. The exact command, account-state prerequisite, actual behavior, expected behavior, and updated version are sufficient for a focused investigation. This is source-based triage, not an independently reproduced Windows result; no tests were run during triage.
Evidence and inspected source
The supplied trace reaches
Broker enabled? True, MSAL's_signin_interactively(), and the CLI's WAM account-selection message. Broker messages includeMissing Required parameters, but found no account to returnandAccount id is empty - account not found, followed by UI/provider-request activity. The trace also reports a valid broker window handle. These messages localize the reported stall to the broker interactive handoff; they do not by themselves establish that a missing-account warning, window handle, or particular request flag is the root cause.Current source was inspected at
devcommit 152b65e:src/azure-cli/azure/cli/command_modules/profile/__init__.py,ProfileCommandsLoader.load_command_table, lines 23-30 registersloginto the handwrittenprofile.customimplementation. This command is registered in__init__.py, not aprofile/commands.pyfile.profile/custom.py,login, lines 136-244 chooses interactive login when no username is supplied, forwardsuse_device_code/tenant/scopes/claims, and only enters subscription selection afterProfile.loginreturns.src/azure-cli-core/azure/cli/core/_profile.py,Profile.login, lines 144-186 callsIdentity.login_with_auth_codeunless device code is selected. Its existing automatic device-code routing handles unavailable browsers/Codespaces, not a WAM call that never returns. Subscription discovery is downstream of authentication._profile.py,_create_identity_instance, lines 967-991 forwardscore.enable_broker_on_windows(default true), independently of the opt-in macOS broker setting.src/azure-cli-core/azure/cli/core/auth/identity.py,Identity._msal_public_app_kwargs,_msal_app, andlogin_with_auth_code, lines 112-174 creates the MSAL public client with broker configuration, then synchronously callsacquire_token_interactivewithprompt='select_account', the console parent handle,enable_msa_passthrough=True, scopes, and claims.Identity.login_with_device_codeis a distinct path (lines 176-184)._get_authority_urldefaults an unspecified tenant toorganizations(lines 416-433).src/azure-cli-core/azure/cli/core/auth/util.py,check_result, lines 130-160 handles a returned MSAL result. An exception handler or message added only here cannot resolve an interactive call that never returns.- Version boundary:
src/azure-cli-core/setup.py, lines 58-60 currently pins MSAL 1.39.0, including its broker extra on Windows/macOS, rather than the report's 1.36.0. Do not assume the current dependency reproduces the report, blindly downgrade it, or propose an already-present dependency upgrade as the fix.
Scoped suggested fix
- First isolate the no-associated-work-account WAM transition against the reported runtime and the current pinned MSAL/broker combination. Determine whether the defect is in CLI interactive-request construction or the MSAL/WAM provider handoff. Verify supported broker semantics for organizational authority, account selection, and MSA passthrough before changing those arguments; the log is not proof that any one of them is wrong.
- Correct the Windows interactive authentication boundary so the new work-account choice reaches account entry rather than leaving the modal/CLI stuck. Prefer the smallest supported request/API correction or a verified dependency fix if that is where the defect resides. Keep implementation changes in the owning handwritten core-authentication/profile path; do not change extensions, subscription selection, or unrelated authentication flows. If the existing newer dependency already fixes the issue, demonstrate that before proposing further implementation changes.
- Any recovery path must use supported broker cancellation/completion semantics and provide a clear, recoverable outcome with explicit browser/device-code guidance when authentication cannot proceed. Merely adding a warning or catching only returned errors is not a hang fix. Do not abandon a live native broker operation in an unmanaged background thread, introduce a retry loop, silently retry after user cancellation, or globally disable WAM. Preserve tenant/scopes/claims and existing account support; never bypass organizational MFA, Conditional Access, or device-compliance requirements.
Focused regression and compatibility coverage
- Extend
src/azure-cli-core/azure/cli/core/auth/tests/test_identity.py,TestIdentityat the mocked MSAL/public-client boundary for the corrected no-associated-work-account transition, successful account entry, cancellation, and the specific recoverable broker failure used by the fix. Assert prompt/authority/scopes/claims/parent-handle behavior and that no second login remains active. If bounded recovery is introduced, use controlled completion/clock primitives rather than a real hanging call or sleeps. - Extend the existing
src/azure-cli-core/azure/cli/core/tests/test_profile.py,TestProfile.test_login_with_auth_code,test_login_with_device_code, and device-code fallback tests. These currently mock theIdentityentry points; retain that routing coverage and add assertions for any new recovery behavior, including no subscription discovery or persistence after cancelled/failed authentication. - If command forwarding or user-facing behavior changes, add focused coverage in
src/azure-cli/azure/cli/command_modules/profile/tests/latest/test_profile_custom.py,ProfileCommandTest. Preserve explicit--use-device-code, broker opt-out, tenant/scopes/claims forwarding, and non-interactive credential paths. - Validate the actual Windows UI scenario both without and with an associated work account. Check personal Microsoft accounts as well as work accounts before altering MSA passthrough. Keep browser login/non-Windows behavior, macOS broker opt-in, explicit tenant/ADFS handling, service principals, managed identity, and existing subscription selection compatible. Report exactly which unit and Windows/manual checks were performed; a mocked success alone does not prove a native WAM hang is resolved.
Impact and workaround
This blocks normal interactive Azure CLI sign-in for the reported Windows/work-account state. The reporter identifies device-code login as a working alternative:
az login --use-device-code, where organizational policy permits. The evidence does not establish a general authentication outage or affected population beyond this scenario; no broad severity escalation is inferred.Generation applicability: the inspected
loginregistration and implementation are handwritten, not AAZ-generated. Keep this fix there. The required generation guidance below is a guard for any generated target actually encountered, not a request to create aprofileAAZ model or aprofile/commands.pyfile.Mandatory Codegen execution protocol
Before editing implementation files, determine whether the affected
profilecommand is AAZ-generated. Files underaaz/<profile>/are generated output and must never be patched directly, including by an AI agent. Check outAzure/aazbesideAzure/azure-rest-api-specs,Azure/aaz-dev-tools, and the downstream repository. API-schema defects start in the specification; command naming, grouping, arguments, API-version selection, help, and examples belong in the durableAzure/aazcommand model; non-modelable client behavior belongs in a handwritten subclass or wrapper incustom.py, registered fromcommands.py. X Engineering Agent creates and promotes the corresponding durableAzure/aazsource pull request before it promotes downstream generated output.Follow the Azure CLI repository's Codegen workflow and the aaz-dev setup documentation. Set up the checked-out repositories with
azdev setup. Usegenerateonly when importing or redesigning command models from Swagger/TypeSpec. For an existing module whose durableAzure/aazmodel has been updated, render that model withregenerate:aaz-dev cli regenerate --name profile --cli-path <azure-cli> # New/imported command model only: aaz-dev cli generate --spec <specification-name> --module profile
You MUST actually run the generator; do not merely describe it or imitate its output. If the AAZ/specification checkout, local source change, credentials, or generator is unavailable, stop and report the blocker instead of editing generated files. Inspect
_aaz_infoprovenance and the complete regenerated diff, then run focusedazdev style,azdev linter, andazdev testvalidation. For an extension, also update its version andHISTORY.rst, preserveazext_metadata.jsoncompatibility, and let release automation updatesrc/index.json.PR title & description format (required)
This repo enforces a PR format (guide). Please author the PR exactly as follows or CI's Check the Format of Pull Request Title and Content will fail.
Use this EXACT PR title (copy verbatim, do not reword):
[Profile] Fix #34121: `az login`: Prevent WAM hangs when adding work accountsKeep the backticks around the command and the
Fix #34121:prefix. You may only adjust the wording after the command (the final summary) if the fix changes; the[Profile]prefix, issue link, and backticked command must stay.Description — follow the PR template and fill in:
- Link the issue — start the Description with a closing keyword so the PR auto-links and closes it:
Fixes #34121. - Related command — the
az ...command this affects. - Description (mandatory) — why the bug happens, what you changed, and the resulting behavior.
- Testing Guide — example command(s) showing the fix works.
- History Notes — leave the title to drive the history note, or add extra lines in the same format (component in brackets + the command in backticks), e.g.
[Profile] `az <command>`: <note>. - Keep the template checklist and tick the items you've satisfied.
x-engineering-agent commented
on Sep 24, 2026 ContributorMore actionsImplementation Result
No pull request was opened because the implementation run completed without a validated code change.
The source analysis above identified the WAM/MSAL broker boundary, but the implementation run could not establish a safe Azure CLI code change from the available evidence. In particular, the report used MSAL 1.36.0 while current
devpins MSAL 1.39.0, and the native Windows WAM behavior was not reproducible in the Linux execution environment. A maintainer should confirm the behavior against currentdevand determine whether the fix belongs in Azure CLI or the upstream WAM/MSAL broker before another implementation request.Hi arctumn (@arctumn) thanks for the feedback. Could you elaborate on the followings:
- By "professional accounts" do you mean "Work or school account" or "Microsoft account"? If possible, could you share the domain of the account e.g.
@outlook.com? - Version of Windows
- If possible could you share a screenshot of the frozen WAM window?
- By "professional accounts" do you mean "Work or school account" or "Microsoft account"? If possible, could you share the domain of the account e.g.
Hi arctumn (@arctumn) thanks for the feedback. Could you elaborate on the followings:
- By "professional accounts" do you mean "Work or school account" or "Microsoft account"? If possible, could you share the domain of the account e.g.
@outlook.com? - Version of Windows
- If possible could you share a screenshot of the frozen WAM window?
- Work accounts like "email@gs1pt.org, email@conkord.com"
- Windows 11 Pro 25H2 26200.9457
- I'll record a video of the issue happening since is not "screenshotable"
- By "professional accounts" do you mean "Work or school account" or "Microsoft account"? If possible, could you share the domain of the account e.g.
x-engineering-agent commented
on Sep 30, 2026 ContributorMore actionsAutomated sensitive-information remediation ran on this issue.
- Detected categories: email address
- Replaced with typed
[REDACTED:category]placeholders in: no editable issue fields - Comment owners notified because X Engineering Agent cannot edit another user's comment: arctumn (@arctumn)
If a credential was exposed, rotate or revoke it immediately. Detected values are never copied into this comment.
✅ Confirm the finding · ❌ Dispute the finding
GitHub only supports a fixed reaction set, so 👍 represents ✅ and 👎 represents ❌. The bot-created reactions are only poll choices.
Reacted by x-engineering-agentReacted by x-engineering-agent and arctumnx-engineering-agent commented
on Sep 30, 2026 ContributorMore actions❌ Redaction disputed by arctumn (@arctumn).
Automation is paused for maintainer review. X Engineering Agent will not restore the suspected value because doing so would publish it again. A maintainer can replace the placeholder with confirmed non-sensitive text after review.
Yeming Liu (@isra-fel) somehow the bug no longer is happening....
I will send a video of what happened, to give context the last part of retrieving tenants did never load when I submitted this issue.screen-capture.webm
Describe the bug
When using the new WAM if you select a professional account when there is none associated on windows the modal where you select a professional account you are not being redirected to select which professional/corporate email, it just hangs forcing you to pass the device code command to have an alternative way to connect to azure on cli
Related command
az loginErrors
There is no traceback, it just hangs with nothing happening
Issue script & Debug output
Expected behavior
When the modal showes up and you select a professional/corporate email, a new window on the borwser or on a new modal should ask which professional/corporate you want to use to authenticate to azure.
Environment Summary
azure-cli 2.88.0 *
core 2.88.0 *
telemetry 1.1.0
Extensions:
automation 1.0.0b2
azure-devops 1.0.6
ml 2.42.0
Dependencies:
msal 1.36.0
azure-mgmt-resource 24.0.0
Python location 'C:\Program Files\Microsoft SDKs\Azure\CLI2\python.exe'
Config directory 'C:\Users\Pedro Lopes.azure'
Extensions directory 'C:\Users\Pedro Lopes.azure\cliextensions'
Python (Windows) 3.14.5 (tags/v3.14.5:5607950, May 10 2026, 10:43:50) [MSC v.1944 64 bit (AMD64)]
Legal docs and information: aka.ms/AzureCliLegal
Additional context
No response