Skip to content

Windows: MCP Entra sign-in fails with "this server's advertised scopes could not be safely validated for the account broker" #5068

Description

@markwtwjeffries

Describe the bug

On Windows, authenticating to an Entra ID–protected MCP server (Microsoft's hosted Azure DevOps MCP server,  https://mcp.dev.azure.com/{org} , server type  http ) fails on every fresh interactive sign-in attempt with:

Authentication failed: MCPOAuthError: Microsoft Entra sign-in for https://mcp.dev.azure.com/{org} failed: this server's advertised scopes could not be safely validated for the account broker

 /mcp auth   does not open the login/account-picker dialog at all — it fails immediately with the above error.

Affected version

GitHub Copilot CLI 1.0.93-2

Steps to reproduce the behavior

  1. Configure an MCP server pointing at  https://mcp.dev.azure.com/{org}  (type  http ) via a Copilot CLI plugin.
  2. Start a new Copilot CLI session.
  3. Run  /mcp auth ado  (or whatever the server is named).
  4. Expected: Windows account picker / browser OAuth dialog opens for Entra sign-in.
  5. Actual: Dialog never appears; command fails instantly with the "advertised scopes could not be safely validated for the account broker" error.

Expected behavior

when the native broker cannot safely validate a server's advertised scopes, the CLI should fall back to standard browser-based OAuth instead of failing outright, consistent with the documented fallback behavior for "no broker available."

Additional context

  • This started suddenly with no local configuration changes on the user's part. CLI terminals that were already open and authenticated from the day before continue to work fine (silent token renewal via  acquireTokenSilent  still succeeds). Only brand-new sessions attempting a fresh interactive sign-in ( acquireTokenInteractive ) hit this error — suggesting the issue is specific to the interactive WAM/native-broker code path, not silent renewal.
  • Deleting all cached OAuth token files under  %USERPROFILE%.copilot\mcp-oauth-config*.tokens.json  for this server did not resolve the issue.
  • The exact error string does not appear anywhere in the CLI's JS bundle ( cli-main.js ), indicating it originates from the native Windows MSAL broker/WAM component ( msalruntime.dll  /  msal-node-runtime.node ), which performs its own scope-safety validation before invoking the Windows account picker.
  • Reproduces identically on CLI 1.0.92 (stable) and 1.0.93-2 (prerelease), which rules out a simple JS-level regression introduced between those versions.
    was added, ~1.0.81) that is only now being triggered.
  • The CLI's own changelog (bundled  changelog.json ) mentions related recent changes: "Entra-protected MCP servers can silently renew access-token-only credentials" and "Entra sign-in falls back to browser auth when no broker is available" — but in this case it is not falling back to browser auth; it hard-fails instead.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:mcpMCP server configuration, discovery, connectivity, OAuth, policy, and registryarea:platform-windowsWindows-specific: PowerShell, cmd, Git Bash, WSL, Windows Terminal

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions