Short summary
Windows Copilot Desktop fails to sign in to an Entra-protected MCP server with ENTRA_CONFIG 2002, while VS Code and standalone Copilot CLI work
Affected version or release
v1.1.26
Installation context
Locally installed GitHub Copilot Desktop on Windows, connecting to a remote Streamable HTTP MCP server protected by Microsoft Entra ID. This is an MCP authentication issue, not a GitHub repository installation issue.
What happened?
Signing in to the MCP server from Desktop fails with:
RPC error -32603: Request session.mcp.oauth.login failed:
ENTRA_CONFIG: the authenticator rejected the configuration
[code 2002, tag 7q6cl].
Fully quitting and restarting Desktop does not resolve it. The same MCP endpoint works in VS Code and standalone Copilot CLI.
Launching Desktop with COPILOT_ENTRA_DISABLE_ONEAUTH=1 set only for that process allows browser sign-in. No server or Entra permission changes were required.
With multiple MCP servers enabled, browser sign-in was followed by a reconnect loop: the sign-in button repeatedly appeared and disappeared. Logs showed successful authentication, repeated HTTP 401 challenges, and “MCP OAuth was cancelled because its original requester or configuration changed.”
After disabling the other MCP servers and restarting Desktop in browser mode, the connection appeared stable and an MCP tool successfully. The exact trigger for the reconnect loop is not yet established.
Expected: Desktop completes Entra authentication, or falls back to browser sign-in when OneAuth rejects the configuration, and maintains a stable MCP connection.
Possibly related to #3743, marked fixed in 1.1.24, although the underlying cause may differ.
Steps to reproduce
- On Windows, open GitHub Copilot Desktop 1.1.26 normally.
- Configure a remote Streamable HTTP MCP server protected by Microsoft Entra ID, without a manual Authorization header.
- Attempt to sign in to the MCP server.
- Observe ENTRA_CONFIG: “the authenticator rejected the configuration [code 2002, tag 7q6cl].”
- Fully quit and restart Desktop, then retry. The error persists.
- Connect to the same endpoint using VS Code or standalone Copilot CLI 1.0.92-0. Authentication and tool calls succeed.
Workaround comparison:
7. Fully quit Desktop and launch it with COPILOT_ENTRA_DISABLE_ONEAUTH=1 set only for the new process.
8. Retry MCP sign-in. Browser authentication succeeds.
Secondary observation:
With multiple MCP servers enabled, Desktop then repeatedly showed and hid the sign-in button. Disabling the other servers and restarting Desktop in browser mode produced an apparently stable connection. The exact conditions triggering this reconnect loop are not yet isolated.
Expected behavior
Desktop should successfully authenticate to the Entra-protected MCP server, as VS Code and standalone Copilot CLI do.
If OneAuth cannot handle the configuration, Desktop should fall back to browser authentication without requiring an environment override.
After authentication, Desktop should maintain a stable MCP connection. Refreshing other MCP servers should not cancel authentication or repeatedly toggle the sign-in button.
Additional context
- Desktop version: 1.1.26 on Windows.
- Desktop bundled CLI runtime: 1.0.90-0.
- Working standalone CLI version: 1.0.92-0.
- The MCP server also works in VS Code.
- COPILOT_ENTRA_AUTH_AUD was absent from the inspected CLI process and persisted Windows user/machine settings.
- No Entra permissions or server configuration were changed for the browser-mode comparison.
- The server’s protected-resource metadata and unauthenticated HTTP 401 challenge were checked and matched the configured endpoint, tenant authority, and API scope.
- A Databricks connection-test tool succeeded after the connection became stable.
Logs during the reconnect loop included:
“MCP status session connected after authentication; refreshing live session MCP hosts”
“MCP OAuth non-first-party server; cancelling host-token and kicking daemon-owned reconnect”
“MCP OAuth was cancelled because its original requester or configuration changed.”
The runtime recorded 162 HTTP 401 challenges for this MCP server during the loop. These logs do not establish whether credentials were omitted, lost, or invalidated.
Possibly related to #3743, marked fixed in Desktop 1.1.24. The underlying cause may differ. The reconnect loop may be a separate issue.
Short summary
Windows Copilot Desktop fails to sign in to an Entra-protected MCP server with ENTRA_CONFIG 2002, while VS Code and standalone Copilot CLI work
Affected version or release
v1.1.26
Installation context
Locally installed GitHub Copilot Desktop on Windows, connecting to a remote Streamable HTTP MCP server protected by Microsoft Entra ID. This is an MCP authentication issue, not a GitHub repository installation issue.
What happened?
Signing in to the MCP server from Desktop fails with:
RPC error -32603: Request session.mcp.oauth.login failed:
ENTRA_CONFIG: the authenticator rejected the configuration
[code 2002, tag 7q6cl].
Fully quitting and restarting Desktop does not resolve it. The same MCP endpoint works in VS Code and standalone Copilot CLI.
Launching Desktop with COPILOT_ENTRA_DISABLE_ONEAUTH=1 set only for that process allows browser sign-in. No server or Entra permission changes were required.
With multiple MCP servers enabled, browser sign-in was followed by a reconnect loop: the sign-in button repeatedly appeared and disappeared. Logs showed successful authentication, repeated HTTP 401 challenges, and “MCP OAuth was cancelled because its original requester or configuration changed.”
After disabling the other MCP servers and restarting Desktop in browser mode, the connection appeared stable and an MCP tool successfully. The exact trigger for the reconnect loop is not yet established.
Expected: Desktop completes Entra authentication, or falls back to browser sign-in when OneAuth rejects the configuration, and maintains a stable MCP connection.
Possibly related to #3743, marked fixed in 1.1.24, although the underlying cause may differ.
Steps to reproduce
Workaround comparison:
7. Fully quit Desktop and launch it with COPILOT_ENTRA_DISABLE_ONEAUTH=1 set only for the new process.
8. Retry MCP sign-in. Browser authentication succeeds.
Secondary observation:
With multiple MCP servers enabled, Desktop then repeatedly showed and hid the sign-in button. Disabling the other servers and restarting Desktop in browser mode produced an apparently stable connection. The exact conditions triggering this reconnect loop are not yet isolated.
Expected behavior
Desktop should successfully authenticate to the Entra-protected MCP server, as VS Code and standalone Copilot CLI do.
If OneAuth cannot handle the configuration, Desktop should fall back to browser authentication without requiring an environment override.
After authentication, Desktop should maintain a stable MCP connection. Refreshing other MCP servers should not cancel authentication or repeatedly toggle the sign-in button.
Additional context
Logs during the reconnect loop included:
“MCP status session connected after authentication; refreshing live session MCP hosts”
“MCP OAuth non-first-party server; cancelling host-token and kicking daemon-owned reconnect”
“MCP OAuth was cancelled because its original requester or configuration changed.”
The runtime recorded 162 HTTP 401 challenges for this MCP server during the loop. These logs do not establish whether credentials were omitted, lost, or invalidated.
Possibly related to #3743, marked fixed in Desktop 1.1.24. The underlying cause may differ. The reconnect loop may be a separate issue.