Skip to content

Az login on Web Account Manager (WAM) does nto work for professional accounts #34121

Description

@arctumn

Describe the bug

When using the new WAM if you select a professional account when there is none associated on windows the modal where you select a professional account you are not being redirected to select which professional/corporate email, it just hangs forcing you to pass the device code command to have an alternative way to connect to azure on cli

Related command

az login

Errors

There is no traceback, it just hangs with nothing happening

Issue script & Debug output

PS C:\Users\Pedro Lopes\source\repos\gs1pt-mono-associated-area> az login --debug
cli.knack.cli: Command arguments: ['login', '--debug']
cli.knack.cli: __init__ debug log:
Enable color in terminal.
Enable VT mode.
cli.knack.cli: Event: Cli.PreExecute []
cli.knack.cli: Event: CommandParser.OnGlobalArgumentsCreate [<function CLILogging.on_global_arguments at 0x000002294CA89B10>, <function OutputProducer.on_global_arguments at 0x000002294CF90A90>, <function CLIQuery.on_global_arguments at 0x000002294CFBF110>]
cli.knack.cli: Event: CommandInvoker.OnPreCommandTableCreate []
cli.azure.cli.core: Using packaged command index for profile 'latest'.
cli.azure.cli.core: Found installed extension 'automation' (azext_automation).
cli.azure.cli.core: Blending packaged core index with local extension index.
cli.azure.cli.core: Modules found from index for 'login': ['azure.cli.command_modules.profile']
cli.azure.cli.core: Loading command modules...
cli.azure.cli.core: Name                  Load Time    Groups  Commands
cli.azure.cli.core: profile                   0.004         2         8
cli.azure.cli.core: Loaded command modules:
cli.azure.cli.core: Total (1)                 0.004         2         8
cli.azure.cli.core: These extensions are not installed and will be skipped: ['azext_ai_examples', 'azext_next']
cli.azure.cli.core: Loading extensions:
cli.azure.cli.core: Name                  Load Time    Groups  Commands  Directory
cli.azure.cli.core: Total (0)                 0.000         0         0
cli.azure.cli.core: Loaded 2 groups, 8 commands.
cli.azure.cli.core: Found a match in the command table.
cli.azure.cli.core: Raw command  : login
cli.azure.cli.core: Command table: login
cli.knack.cli: Event: CommandInvoker.OnPreCommandTableTruncate [<function AzCliLogging.init_command_file_logging at 0x000002294D1838A0>]
cli.azure.cli.core.azlogging: metadata file logging enabled - writing logs to 'C:\Users\Pedro Lopes\.azure\commands\2026-09-23.08-54-49.login.16468.log'.
az_command_data_logger: command args: login --debug
cli.knack.cli: Event: CommandInvoker.OnPreArgumentLoad [<function register_global_subscription_argument.<locals>.add_subscription_parameter at 0x000002294D095A60>]
cli.knack.cli: Event: CommandInvoker.OnPostArgumentLoad []
cli.knack.cli: Event: CommandInvoker.OnPostCommandTableCreate [<function register_ids_argument.<locals>.add_ids_arguments at 0x000002294D096090>, <function register_global_policy_argument.<locals>.add_global_policy_argument at 0x000002294D1D0460>, <function register_cache_arguments.<locals>.add_cache_arguments at 0x000002294D1D0510>, <function register_upcoming_breaking_change_info.<locals>.update_breaking_change_info at 0x000002294D1D05C0>]
cli.knack.cli: Event: CommandInvoker.OnCommandTableLoaded []
cli.knack.cli: Event: CommandInvoker.OnPreParseArgs []
cli.knack.cli: Event: CommandInvoker.OnPostParseArgs [<function OutputProducer.handle_output_argument at 0x000002294CF90B40>, <function CLIQuery.handle_query_parameter at 0x000002294CFBF1C0>, <function register_ids_argument.<locals>.parse_ids_arguments at 0x000002294D1D03B0>]
cli.azure.cli.core.auth.persistence: build_persistence: location='C:\\Users\\Pedro Lopes\\.azure\\msal_token_cache.bin', encrypt=True
cli.azure.cli.core.auth.binary_cache: load: C:\Users\Pedro Lopes\.azure\msal_http_cache.bin
urllib3.util.retry: Converted retries value: 1 -> Retry(total=1, connect=None, read=None, redirect=None, status=None)
msal.application: Broker enabled? True
msal.application: Falls back to broker._signin_interactively()
cli.azure.cli.core.auth.identity: Select the account you want to log in with. For more information on login with Azure CLI, see https://go.microsoft.com/fwlink/?linkid=2271136
msal.broker: [MSAL:0001]        INFO    SetAuthorityUri:80      Initializing authority from URI 'https://login.microsoftonline.com/organizations' without authority type, detected type 'ms_sts'
msal.broker: [MSAL:0002]        INFO    SetCorrelationId:241    Set correlation ID: a5a9b17a-95f9-4086-a386-7273e16ede1a
msal.broker: [MSAL:0002]        INFO    ExecuteInteractiveRequest:1404  The original authority is 'https://login.microsoftonline.com/organizations'
msal.broker: [MSAL:0002]        WARNING TryNormalizeRealm:2599  No HomeAccountId provided to normalize the realm
msal.broker: [MSAL:0002]        INFO    ExecuteInteractiveRequest:1415  The normalized realm is ''
msal.broker: [MSAL:0002]        INFO    ModifyAndValidateAuthParameters:228     Additional query parameter added successfully. Key: 'msal_client_sku' Value: 'MSAL.Python'
msal.broker: [MSAL:0002]        INFO    ModifyAndValidateAuthParameters:228     Additional query parameter added successfully. Key: 'msal_client_ver' Value: '1.36.0'
msal.broker: [MSAL:0002]        INFO    ModifyAndValidateAuthParameters:228     Additional query parameter added successfully. Key: 'msal_gui_thread' Value: 'true'
msal.broker: [MSAL:0002]        INFO    ModifyAndValidateAuthParameters:228     Additional query parameter added successfully. Key: 'msal_request_type' Value: 'consumer_passthrough'
msal.broker: [MSAL:0002]        INFO    ModifyAndValidateAuthParameters:251     Authority Realm: organizations
msal.broker: [MSAL:0002]        WARNING TryEnqueueMsaDeviceCredentialAcquisitionAndContinue:1297        MsaDeviceOperationProvider is not available. Not attempting to register the device.
msal.broker: [MSAL:0003]        WARNING ReturnResponseDueToMissingParameter:749 Attempted to read cache with a non-normalized realm, access token and ID token reads will fail
msal.broker: [MSAL:0003]        WARNING ReturnResponseDueToMissingParameter:777 Missing Required parameters, but found no account to return.
msal.broker: [MSAL:0003]        WARNING ReadAccountById:652     Account id is empty - account not found
msal.broker: [MSAL:0003]        INFO    GetCurrentWindowHandleForUIFlow:501     Specified brokerWindowHandle is valid.
msal.broker: [MSAL:0004]        INFO    CreateRequestForProviderWithProperties:859      Client-xtra-sku: MSAL.Python|1.36.0,|0.20.6,|,|,|10.1.1
msal.broker: [MSAL:0004]        INFO    AddClientSystemInfoToRequest:1250       Client-xtra-sku: MSAL.Python|1.36.0,|0.20.6,|,|,|10.1.1

Expected behavior

When the modal showes up and you select a professional/corporate email, a new window on the borwser or on a new modal should ask which professional/corporate you want to use to authenticate to azure.

Environment Summary

azure-cli 2.88.0 *

core 2.88.0 *
telemetry 1.1.0

Extensions:
automation 1.0.0b2
azure-devops 1.0.6
ml 2.42.0

Dependencies:
msal 1.36.0
azure-mgmt-resource 24.0.0

Python location 'C:\Program Files\Microsoft SDKs\Azure\CLI2\python.exe'
Config directory 'C:\Users\Pedro Lopes.azure'
Extensions directory 'C:\Users\Pedro Lopes.azure\cliextensions'

Python (Windows) 3.14.5 (tags/v3.14.5:5607950, May 10 2026, 10:43:50) [MSC v.1944 64 bit (AMD64)]

Legal docs and information: aka.ms/AzureCliLegal

Additional context

No response

Activity

  1. added
    bugThis issue requires a change to an existing behavior in the product in order to be resolved.
    on Sep 23, 2026
  2. azure-client-tools-bot-prd commented on Sep 23, 2026

    @azure-client-tools-bot-prd

    Hi arctumn (@arctumn),

    2.88.0 is not the latest Azure CLI(2.90.0).

    If you haven't already attempted to do so, please upgrade to the latest Azure CLI version by following https://learn.microsoft.com/en-us/cli/azure/update-azure-cli.

  3. added
    customer-reportedIssues that are reported by GitHub users external to the Azure organization.
    Accountaz login/account
    Azure CLI TeamThe command of the issue is owned by Azure CLI team
    questionThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
    on Sep 23, 2026
  4. yonzhan commented on Sep 23, 2026

    @yonzhan
    Collaborator

    Thank you for opening this issue, we will look into it.

  5. arctumn commented on Sep 23, 2026

    @arctumn
    Author

    Hi arctumn (@arctumn),

    2.88.0 is not the latest Azure CLI(2.90.0).

    If you haven't already attempted to do so, please upgrade to the latest Azure CLI version by following https://learn.microsoft.com/en-us/cli/azure/update-azure-cli.

    This might be an issue if the user does not have permissions to manage their apps upgrades.

  6. removed
    questionThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
    on Sep 23, 2026
  7. added this to the Backlog milestone on Sep 23, 2026
  8. arctumn commented on Sep 23, 2026

    @arctumn
    Author

    Just upgraded to 2.90.0 cli the bug remains.

    Version

    PS C:\Users\Pedro Lopes\source\repos\gs1pt-mono-associated-area> az --version
    azure-cli                         2.90.0
    
    core                              2.90.0
    telemetry                          1.1.0
    
    Extensions:
    automation                       1.0.0b2
    azure-devops                       1.0.6
    ml                                2.42.0
    
    Dependencies:
    msal                              1.36.0
    azure-mgmt-resource               24.0.0
    
    Python location 'C:\Program Files\Microsoft SDKs\Azure\CLI2\python.exe'
    Config directory 'C:\Users\Pedro Lopes\.azure'
    Extensions directory 'C:\Users\Pedro Lopes\.azure\cliextensions'
    
    Python (Windows) 3.14.6 (tags/v3.14.6:c63aec6, Jun 10 2026, 10:26:10) [MSC v.1944 64 bit (AMD64)]
    
    Legal docs and information: aka.ms/AzureCliLegal
    
    
    Your CLI is up-to-date.
    

    Trace

    PS C:\Users\Pedro Lopes\source\repos\gs1pt-mono-associated-area> az login --debug
    cli.knack.cli: Command arguments: ['login', '--debug']
    cli.knack.cli: __init__ debug log:
    Enable color in terminal.
    Enable VT mode.
    cli.knack.cli: Event: Cli.PreExecute []
    cli.knack.cli: Event: CommandParser.OnGlobalArgumentsCreate [<function CLILogging.on_global_arguments at 0x0000018DC7DB9B10>, <function OutputProducer.on_global_arguments at 0x0000018DC82C4A90>, <function CLIQuery.on_global_arguments at 0x0000018DC82F3110>]
    cli.knack.cli: Event: CommandInvoker.OnPreCommandTableCreate []
    cli.azure.cli.core: Using packaged command index for profile 'latest'.
    cli.azure.cli.core: Found installed extension 'automation' (azext_automation).
    cli.azure.cli.core: Blending packaged core index with local extension index.
    cli.azure.cli.core: Modules found from index for 'login': ['azure.cli.command_modules.profile']
    cli.azure.cli.core: Loading command modules...
    cli.azure.cli.core: Name                  Load Time    Groups  Commands
    cli.azure.cli.core: profile                   0.003         2         8
    cli.azure.cli.core: Loaded command modules:
    cli.azure.cli.core: Total (1)                 0.004         2         8
    cli.azure.cli.core: These extensions are not installed and will be skipped: ['azext_ai_examples', 'azext_next']
    cli.azure.cli.core: Loading extensions:
    cli.azure.cli.core: Name                  Load Time    Groups  Commands  Directory
    cli.azure.cli.core: Total (0)                 0.000         0         0
    cli.azure.cli.core: Loaded 2 groups, 8 commands.
    cli.azure.cli.core: Found a match in the command table.
    cli.azure.cli.core: Raw command  : login
    cli.azure.cli.core: Command table: login
    cli.knack.cli: Event: CommandInvoker.OnPreCommandTableTruncate [<function AzCliLogging.init_command_file_logging at 0x0000018DC84A3A00>]
    cli.azure.cli.core.azlogging: metadata file logging enabled - writing logs to 'C:\Users\Pedro Lopes\.azure\commands\2026-09-23.09-01-45.login.8552.log'.
    az_command_data_logger: command args: login --debug
    cli.knack.cli: Event: CommandInvoker.OnPreArgumentLoad [<function register_global_subscription_argument.<locals>.add_subscription_parameter at 0x0000018DC84AB950>]
    cli.knack.cli: Event: CommandInvoker.OnPostArgumentLoad []
    cli.knack.cli: Event: CommandInvoker.OnPostCommandTableCreate [<function register_ids_argument.<locals>.add_ids_arguments at 0x0000018DC84ABC10>, <function register_global_policy_argument.<locals>.add_global_policy_argument at 0x0000018DC84F05C0>, <function register_cache_arguments.<locals>.add_cache_arguments at 0x0000018DC84F0670>, <function register_upcoming_breaking_change_info.<locals>.update_breaking_change_info at 0x0000018DC84F0720>]
    cli.knack.cli: Event: CommandInvoker.OnCommandTableLoaded []
    cli.knack.cli: Event: CommandInvoker.OnPreParseArgs []
    cli.knack.cli: Event: CommandInvoker.OnPostParseArgs [<function OutputProducer.handle_output_argument at 0x0000018DC82C4B40>, <function CLIQuery.handle_query_parameter at 0x0000018DC82F31C0>, <function register_ids_argument.<locals>.parse_ids_arguments at 0x0000018DC84F0510>]
    cli.azure.cli.core.auth.persistence: build_persistence: location='C:\\Users\\Pedro Lopes\\.azure\\msal_token_cache.bin', encrypt=True
    cli.azure.cli.core.auth.binary_cache: load: C:\Users\Pedro Lopes\.azure\msal_http_cache.bin
    urllib3.util.retry: Converted retries value: 1 -> Retry(total=1, connect=None, read=None, redirect=None, status=None)
    msal.application: Broker enabled? True
    msal.application: Falls back to broker._signin_interactively()
    cli.azure.cli.core.auth.identity: Select the account you want to log in with. For more information on login with Azure CLI, see https://go.microsoft.com/fwlink/?linkid=2271136
    msal.broker: [MSAL:0001]        INFO    SetAuthorityUri:80      Initializing authority from URI 'https://login.microsoftonline.com/organizations' without authority type, detected type 'ms_sts'
    msal.broker: [MSAL:0002]        INFO    SetCorrelationId:241    Set correlation ID: 51dfcaed-d1a7-48ac-b0cd-d4d963ce6221
    msal.broker: [MSAL:0002]        INFO    ExecuteInteractiveRequest:1404  The original authority is 'https://login.microsoftonline.com/organizations'
    msal.broker: [MSAL:0002]        WARNING TryNormalizeRealm:2599  No HomeAccountId provided to normalize the realm
    msal.broker: [MSAL:0002]        INFO    ExecuteInteractiveRequest:1415  The normalized realm is ''
    msal.broker: [MSAL:0002]        INFO    ModifyAndValidateAuthParameters:228     Additional query parameter added successfully. Key: 'msal_client_sku' Value: 'MSAL.Python'
    msal.broker: [MSAL:0002]        INFO    ModifyAndValidateAuthParameters:228     Additional query parameter added successfully. Key: 'msal_client_ver' Value: '1.36.0'
    msal.broker: [MSAL:0002]        INFO    ModifyAndValidateAuthParameters:228     Additional query parameter added successfully. Key: 'msal_gui_thread' Value: 'true'
    msal.broker: [MSAL:0002]        INFO    ModifyAndValidateAuthParameters:228     Additional query parameter added successfully. Key: 'msal_request_type' Value: 'consumer_passthrough'
    msal.broker: [MSAL:0002]        INFO    ModifyAndValidateAuthParameters:251     Authority Realm: organizations
    msal.broker: [MSAL:0002]        WARNING TryEnqueueMsaDeviceCredentialAcquisitionAndContinue:1297        MsaDeviceOperationProvider is not available. Not attempting to register the device.
    msal.broker: [MSAL:0003]        WARNING ReturnResponseDueToMissingParameter:749 Attempted to read cache with a non-normalized realm, access token and ID token reads will fail
    msal.broker: [MSAL:0003]        WARNING ReturnResponseDueToMissingParameter:777 Missing Required parameters, but found no account to return.
    msal.broker: [MSAL:0003]        WARNING ReadAccountById:652     Account id is empty - account not found
    msal.broker: [MSAL:0003]        INFO    GetCurrentWindowHandleForUIFlow:501     Specified brokerWindowHandle is valid.
    msal.broker: [MSAL:0004]        INFO    CreateRequestForProviderWithProperties:859      Client-xtra-sku: MSAL.Python|1.36.0,|0.20.6,|,|,|10.1.1
    msal.broker: [MSAL:0004]        INFO    AddClientSystemInfoToRequest:1250       Client-xtra-sku: MSAL.Python|1.36.0,|0.20.6,|,|,|10.1.1
    
  9. microsoft-github-policy-service commented on Sep 24, 2026

    @microsoft-github-policy-service
    Contributor

    🔔 Routing this issue to @Azure/act-identity-squad.

  10. x-engineering-agent commented on Sep 24, 2026

    @x-engineering-agent
    Contributor

    Bug Analysis

    Affected area: profile / Azure CLI core authentication, in Azure/azure-cli (not an extension). Target branch: dev.

    Observed versus expected / reproduction quality

    On Windows with no work/school account associated with Windows, run az login and select the professional/work account option in the WAM dialog. The reporter observes a stalled modal and CLI, with no account-entry prompt and no traceback. Expected: an account-entry/authentication dialog or browser flow that permits entering the corporate email, completing authentication, or cancelling without an indefinite wait.

    The original report includes Azure CLI 2.88.0 debug output; the reporter subsequently confirms the same bug after upgrading to 2.90.0, with MSAL 1.36.0 and Windows Python 3.14.6. The exact command, account-state prerequisite, actual behavior, expected behavior, and updated version are sufficient for a focused investigation. This is source-based triage, not an independently reproduced Windows result; no tests were run during triage.

    Evidence and inspected source

    The supplied trace reaches Broker enabled? True, MSAL's _signin_interactively(), and the CLI's WAM account-selection message. Broker messages include Missing Required parameters, but found no account to return and Account id is empty - account not found, followed by UI/provider-request activity. The trace also reports a valid broker window handle. These messages localize the reported stall to the broker interactive handoff; they do not by themselves establish that a missing-account warning, window handle, or particular request flag is the root cause.

    Current source was inspected at dev commit 152b65e:

    Scoped suggested fix

    1. First isolate the no-associated-work-account WAM transition against the reported runtime and the current pinned MSAL/broker combination. Determine whether the defect is in CLI interactive-request construction or the MSAL/WAM provider handoff. Verify supported broker semantics for organizational authority, account selection, and MSA passthrough before changing those arguments; the log is not proof that any one of them is wrong.
    2. Correct the Windows interactive authentication boundary so the new work-account choice reaches account entry rather than leaving the modal/CLI stuck. Prefer the smallest supported request/API correction or a verified dependency fix if that is where the defect resides. Keep implementation changes in the owning handwritten core-authentication/profile path; do not change extensions, subscription selection, or unrelated authentication flows. If the existing newer dependency already fixes the issue, demonstrate that before proposing further implementation changes.
    3. Any recovery path must use supported broker cancellation/completion semantics and provide a clear, recoverable outcome with explicit browser/device-code guidance when authentication cannot proceed. Merely adding a warning or catching only returned errors is not a hang fix. Do not abandon a live native broker operation in an unmanaged background thread, introduce a retry loop, silently retry after user cancellation, or globally disable WAM. Preserve tenant/scopes/claims and existing account support; never bypass organizational MFA, Conditional Access, or device-compliance requirements.

    Focused regression and compatibility coverage

    • Extend src/azure-cli-core/azure/cli/core/auth/tests/test_identity.py, TestIdentity at the mocked MSAL/public-client boundary for the corrected no-associated-work-account transition, successful account entry, cancellation, and the specific recoverable broker failure used by the fix. Assert prompt/authority/scopes/claims/parent-handle behavior and that no second login remains active. If bounded recovery is introduced, use controlled completion/clock primitives rather than a real hanging call or sleeps.
    • Extend the existing src/azure-cli-core/azure/cli/core/tests/test_profile.py, TestProfile.test_login_with_auth_code, test_login_with_device_code, and device-code fallback tests. These currently mock the Identity entry points; retain that routing coverage and add assertions for any new recovery behavior, including no subscription discovery or persistence after cancelled/failed authentication.
    • If command forwarding or user-facing behavior changes, add focused coverage in src/azure-cli/azure/cli/command_modules/profile/tests/latest/test_profile_custom.py, ProfileCommandTest. Preserve explicit --use-device-code, broker opt-out, tenant/scopes/claims forwarding, and non-interactive credential paths.
    • Validate the actual Windows UI scenario both without and with an associated work account. Check personal Microsoft accounts as well as work accounts before altering MSA passthrough. Keep browser login/non-Windows behavior, macOS broker opt-in, explicit tenant/ADFS handling, service principals, managed identity, and existing subscription selection compatible. Report exactly which unit and Windows/manual checks were performed; a mocked success alone does not prove a native WAM hang is resolved.

    Impact and workaround

    This blocks normal interactive Azure CLI sign-in for the reported Windows/work-account state. The reporter identifies device-code login as a working alternative: az login --use-device-code, where organizational policy permits. The evidence does not establish a general authentication outage or affected population beyond this scenario; no broad severity escalation is inferred.

    Generation applicability: the inspected login registration and implementation are handwritten, not AAZ-generated. Keep this fix there. The required generation guidance below is a guard for any generated target actually encountered, not a request to create a profile AAZ model or a profile/commands.py file.

    Mandatory Codegen execution protocol

    Before editing implementation files, determine whether the affected profile command is AAZ-generated. Files under aaz/<profile>/ are generated output and must never be patched directly, including by an AI agent. Check out Azure/aaz beside Azure/azure-rest-api-specs, Azure/aaz-dev-tools, and the downstream repository. API-schema defects start in the specification; command naming, grouping, arguments, API-version selection, help, and examples belong in the durable Azure/aaz command model; non-modelable client behavior belongs in a handwritten subclass or wrapper in custom.py, registered from commands.py. X Engineering Agent creates and promotes the corresponding durable Azure/aaz source pull request before it promotes downstream generated output.

    Follow the Azure CLI repository's Codegen workflow and the aaz-dev setup documentation. Set up the checked-out repositories with azdev setup. Use generate only when importing or redesigning command models from Swagger/TypeSpec. For an existing module whose durable Azure/aaz model has been updated, render that model with regenerate:

    aaz-dev cli regenerate --name profile --cli-path <azure-cli>
    
    # New/imported command model only:
    aaz-dev cli generate --spec <specification-name> --module profile

    You MUST actually run the generator; do not merely describe it or imitate its output. If the AAZ/specification checkout, local source change, credentials, or generator is unavailable, stop and report the blocker instead of editing generated files. Inspect _aaz_info provenance and the complete regenerated diff, then run focused azdev style, azdev linter, and azdev test validation. For an extension, also update its version and HISTORY.rst, preserve azext_metadata.json compatibility, and let release automation update src/index.json.

    PR title & description format (required)

    This repo enforces a PR format (guide). Please author the PR exactly as follows or CI's Check the Format of Pull Request Title and Content will fail.

    Use this EXACT PR title (copy verbatim, do not reword):

    [Profile] Fix #34121: `az login`: Prevent WAM hangs when adding work accounts
    

    Keep the backticks around the command and the Fix #34121: prefix. You may only adjust the wording after the command (the final summary) if the fix changes; the [Profile] prefix, issue link, and backticked command must stay.

    Description — follow the PR template and fill in:

    • Link the issue — start the Description with a closing keyword so the PR auto-links and closes it: Fixes #34121.
    • Related command — the az ... command this affects.
    • Description (mandatory) — why the bug happens, what you changed, and the resulting behavior.
    • Testing Guide — example command(s) showing the fix works.
    • History Notes — leave the title to drive the history note, or add extra lines in the same format (component in brackets + the command in backticks), e.g. [Profile] `az <command>`: <note>.
    • Keep the template checklist and tick the items you've satisfied.
  11. x-engineering-agent commented on Sep 24, 2026

    @x-engineering-agent
    Contributor

    Implementation Result

    No pull request was opened because the implementation run completed without a validated code change.

    The source analysis above identified the WAM/MSAL broker boundary, but the implementation run could not establish a safe Azure CLI code change from the available evidence. In particular, the report used MSAL 1.36.0 while current dev pins MSAL 1.39.0, and the native Windows WAM behavior was not reproducible in the Linux execution environment. A maintainer should confirm the behavior against current dev and determine whether the fix belongs in Azure CLI or the upstream WAM/MSAL broker before another implementation request.

  12. isra-fel commented on Sep 29, 2026

    @isra-fel
    Member

    Hi arctumn (@arctumn) thanks for the feedback. Could you elaborate on the followings:

    1. By "professional accounts" do you mean "Work or school account" or "Microsoft account"? If possible, could you share the domain of the account e.g. @outlook.com?
    2. Version of Windows
    3. If possible could you share a screenshot of the frozen WAM window?
  13. arctumn commented on Sep 30, 2026

    @arctumn
    Author

    Hi arctumn (@arctumn) thanks for the feedback. Could you elaborate on the followings:

    1. By "professional accounts" do you mean "Work or school account" or "Microsoft account"? If possible, could you share the domain of the account e.g. @outlook.com?
    2. Version of Windows
    3. If possible could you share a screenshot of the frozen WAM window?
    1. Work accounts like "email@gs1pt.org, email@conkord.com"
    2. Windows 11 Pro 25H2 26200.9457
    3. I'll record a video of the issue happening since is not "screenshotable"
  14. x-engineering-agent commented on Sep 30, 2026

    @x-engineering-agent
    Contributor

    Automated sensitive-information remediation ran on this issue.

    • Detected categories: email address
    • Replaced with typed [REDACTED:category] placeholders in: no editable issue fields
    • Comment owners notified because X Engineering Agent cannot edit another user's comment: arctumn (@arctumn)

    If a credential was exposed, rotate or revoke it immediately. Detected values are never copied into this comment.

    ✅ Confirm the finding · ❌ Dispute the finding

    GitHub only supports a fixed reaction set, so 👍 represents ✅ and 👎 represents ❌. The bot-created reactions are only poll choices.

  15. x-engineering-agent commented on Sep 30, 2026

    @x-engineering-agent
    Contributor

    ❌ Redaction disputed by arctumn (@arctumn).

    Automation is paused for maintainer review. X Engineering Agent will not restore the suspected value because doing so would publish it again. A maintainer can replace the placeholder with confirmed non-sensitive text after review.

  16. arctumn commented on Sep 30, 2026

    @arctumn
    Author

    Yeming Liu (@isra-fel) somehow the bug no longer is happening....
    I will send a video of what happened, to give context the last part of retrieving tenants did never load when I submitted this issue.

    screen-capture.webm
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Accountaz login/accountAuto-AssignAuto assign by botAuto-ResolveAuto resolve by botAzure CLI TeamThe command of the issue is owned by Azure CLI teamRequest X Engineering AgentRequest X Engineering Agent testing and reviewact-identity-squadbugThis issue requires a change to an existing behavior in the product in order to be resolved.customer-reportedIssues that are reported by GitHub users external to the Azure organization.

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions