Skip to content

Windows Desktop 1.1.26: Entra MCP sign-in fails with ENTRA_CONFIG 2002 while CLI works #4390

Description

@ptrstpp950

Short summary

Windows Copilot Desktop fails to sign in to an Entra-protected MCP server with ENTRA_CONFIG 2002, while VS Code and standalone Copilot CLI work

Affected version or release

v1.1.26

Installation context

Locally installed GitHub Copilot Desktop on Windows, connecting to a remote Streamable HTTP MCP server protected by Microsoft Entra ID. This is an MCP authentication issue, not a GitHub repository installation issue.

What happened?

Signing in to the MCP server from Desktop fails with:

RPC error -32603: Request session.mcp.oauth.login failed:
ENTRA_CONFIG: the authenticator rejected the configuration
[code 2002, tag 7q6cl].

Fully quitting and restarting Desktop does not resolve it. The same MCP endpoint works in VS Code and standalone Copilot CLI.

Launching Desktop with COPILOT_ENTRA_DISABLE_ONEAUTH=1 set only for that process allows browser sign-in. No server or Entra permission changes were required.

With multiple MCP servers enabled, browser sign-in was followed by a reconnect loop: the sign-in button repeatedly appeared and disappeared. Logs showed successful authentication, repeated HTTP 401 challenges, and “MCP OAuth was cancelled because its original requester or configuration changed.”

After disabling the other MCP servers and restarting Desktop in browser mode, the connection appeared stable and an MCP tool successfully. The exact trigger for the reconnect loop is not yet established.

Expected: Desktop completes Entra authentication, or falls back to browser sign-in when OneAuth rejects the configuration, and maintains a stable MCP connection.

Possibly related to #3743, marked fixed in 1.1.24, although the underlying cause may differ.

Steps to reproduce

  1. On Windows, open GitHub Copilot Desktop 1.1.26 normally.
  2. Configure a remote Streamable HTTP MCP server protected by Microsoft Entra ID, without a manual Authorization header.
  3. Attempt to sign in to the MCP server.
  4. Observe ENTRA_CONFIG: “the authenticator rejected the configuration [code 2002, tag 7q6cl].”
  5. Fully quit and restart Desktop, then retry. The error persists.
  6. Connect to the same endpoint using VS Code or standalone Copilot CLI 1.0.92-0. Authentication and tool calls succeed.

Workaround comparison:
7. Fully quit Desktop and launch it with COPILOT_ENTRA_DISABLE_ONEAUTH=1 set only for the new process.
8. Retry MCP sign-in. Browser authentication succeeds.

Secondary observation:
With multiple MCP servers enabled, Desktop then repeatedly showed and hid the sign-in button. Disabling the other servers and restarting Desktop in browser mode produced an apparently stable connection. The exact conditions triggering this reconnect loop are not yet isolated.

Expected behavior

Desktop should successfully authenticate to the Entra-protected MCP server, as VS Code and standalone Copilot CLI do.

If OneAuth cannot handle the configuration, Desktop should fall back to browser authentication without requiring an environment override.

After authentication, Desktop should maintain a stable MCP connection. Refreshing other MCP servers should not cancel authentication or repeatedly toggle the sign-in button.

Additional context

  • Desktop version: 1.1.26 on Windows.
  • Desktop bundled CLI runtime: 1.0.90-0.
  • Working standalone CLI version: 1.0.92-0.
  • The MCP server also works in VS Code.
  • COPILOT_ENTRA_AUTH_AUD was absent from the inspected CLI process and persisted Windows user/machine settings.
  • No Entra permissions or server configuration were changed for the browser-mode comparison.
  • The server’s protected-resource metadata and unauthenticated HTTP 401 challenge were checked and matched the configured endpoint, tenant authority, and API scope.
  • A Databricks connection-test tool succeeded after the connection became stable.

Logs during the reconnect loop included:
“MCP status session connected after authentication; refreshing live session MCP hosts”
“MCP OAuth non-first-party server; cancelling host-token and kicking daemon-owned reconnect”
“MCP OAuth was cancelled because its original requester or configuration changed.”

The runtime recorded 162 HTTP 401 challenges for this MCP server during the loop. These logs do not establish whether credentials were omitted, lost, or invalidated.

Possibly related to #3743, marked fixed in Desktop 1.1.24. The underlying cause may differ. The reconnect loop may be a separate issue.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions