<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication Provider Error with Azure AD connection in ArcGIS Pro Questions</title>
    <link>https://community.esri.com/t5/arcgis-pro-questions/authentication-provider-error-with-azure-ad/m-p/1414239#M82280</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/3223"&gt;@danbecker&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please confirm that you configured the redirect uri as "arcgis-pro://auth"? It doesn't need to be https since&amp;nbsp;"arcgis-pro://auth" is not a localhost redirect uri.&lt;/P&gt;&lt;P&gt;Jonah&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Apr 2024 16:40:20 GMT</pubDate>
    <dc:creator>JonahLay</dc:creator>
    <dc:date>2024-04-23T16:40:20Z</dc:date>
    <item>
      <title>Authentication Provider Error with Azure AD connection</title>
      <link>https://community.esri.com/t5/arcgis-pro-questions/authentication-provider-error-with-azure-ad/m-p/1413829#M82247</link>
      <description>&lt;P&gt;Our Azure tenant is deployed in Azure Government.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Followed these steps:&amp;nbsp;&lt;A href="https://pro.arcgis.com/en/pro-app/latest/get-started/connect-to-authentication-providers-from-arcgis-pro.htm" target="_blank" rel="noopener"&gt;Connect to authentication providers from ArcGIS Pro—ArcGIS Pro | Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;When I attempt to sign into the connection in Pro, I get this error:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 375px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/101766i549EE6F5EA4DF215/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I assigned demo_user permission to access the ArcGIS Pro Azure Enterprise app.&lt;/P&gt;&lt;P&gt;I also edited our conditional access policies to exclude demo_user from any policies requiring MFA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even with MFA, I complete the MS Authenticator prompt and still see this error in Pro.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Azure enterprise app sign-in log shows successful login attempts with both MFA/not, no issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone have any ideas?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's my concern:&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/entra/identity-platform/reply-url" target="_blank" rel="noopener"&gt;Redirect URI (reply URL) restrictions - Microsoft identity platform | Microsoft Learn&lt;/A&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;Redirect URIs must begin with the scheme&amp;nbsp;&lt;/SPAN&gt;https&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;From the first link, step #1C when you register Pro as an Azure app:&lt;/P&gt;&lt;OL class=""&gt;&lt;LI&gt;&lt;BLOCKQUOTE&gt;&lt;SPAN&gt;For&amp;nbsp;&lt;SPAN class=""&gt;Redirect URI&lt;/SPAN&gt;, choose&amp;nbsp;&lt;SPAN class=""&gt;Mobile and desktop applications&lt;/SPAN&gt;&amp;nbsp;as the platform and enter the URI:&amp;nbsp;&lt;SPAN class=""&gt;arcgis-pro://auth&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Could this error be caused by the authorization server (Microsoft) not allowing demo_user to be redirected back to Pro because the arcgis-pro:// schema doesn't match the required https:// schema that MS requires?&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 00:00:52 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-pro-questions/authentication-provider-error-with-azure-ad/m-p/1413829#M82247</guid>
      <dc:creator>danbecker</dc:creator>
      <dc:date>2024-04-23T00:00:52Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Provider Error with Azure AD connection</title>
      <link>https://community.esri.com/t5/arcgis-pro-questions/authentication-provider-error-with-azure-ad/m-p/1414239#M82280</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/3223"&gt;@danbecker&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please confirm that you configured the redirect uri as "arcgis-pro://auth"? It doesn't need to be https since&amp;nbsp;"arcgis-pro://auth" is not a localhost redirect uri.&lt;/P&gt;&lt;P&gt;Jonah&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 16:40:20 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-pro-questions/authentication-provider-error-with-azure-ad/m-p/1414239#M82280</guid>
      <dc:creator>JonahLay</dc:creator>
      <dc:date>2024-04-23T16:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Provider Error with Azure AD connection</title>
      <link>https://community.esri.com/t5/arcgis-pro-questions/authentication-provider-error-with-azure-ad/m-p/1414252#M82281</link>
      <description>&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/190407"&gt;@JonahLay&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, that redirect URI is what I have.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We can close this thread, the problem was a CA policy in InTune scoped to demo_user requiring "All users terms of use". This is odd because demo_user has already accepted our all users Terms of Use policy. So, it seems like the ESRI auth. connection doesnt' support that CA grant control.&amp;nbsp;&lt;/P&gt;&lt;P&gt;After excluding demo_user from that CA policy, everything works as expected both with/without MFA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is great progress ESRI, thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 16:46:17 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-pro-questions/authentication-provider-error-with-azure-ad/m-p/1414252#M82281</guid>
      <dc:creator>danbecker</dc:creator>
      <dc:date>2024-04-23T16:46:17Z</dc:date>
    </item>
  </channel>
</rss>

