Skip to content

Commit 5f68d66

Browse files
committed
AB#3605: Convert blog post
1 parent 584b513 commit 5f68d66

2 files changed

Lines changed: 47 additions & 0 deletions

File tree

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
---
2+
title: Error AADSTS900439 - USGClientNotSupportedOnPublicEndpoint
3+
description: Describes a problem in which you receive the error AADSTS900439 when signing in to an application registered in Azure Government cloud using a public endpoint.
4+
ms.date: 03/17/2025
5+
ms.reviewer: bernawy
6+
ms.service: entra-id
7+
ms.custom: sap:Issues Signing In to Applications
8+
---
9+
# Error AADSTS900439 - USGClientNotSupportedOnPublicEndpoint
10+
11+
This article provides a solution to the error AADSTS900439 (USGClientNotSupportedOnPublicEndpoint) that occurs when you try to sign in to an application registered in the Azure Government cloud using a public cloud endpoint.
12+
13+
## Symptoms
14+
15+
When trying to sign in to an application registered in Azure Government cloud using a public endpoint, the sign-in fails and you receive the AADSTS900439 (USGClientNotSupportedOnPublicEndpoint) error.
16+
17+
## Cause
18+
19+
Microsoft Entra authority for Azure Government has been updated to from `https://login-us.microsoftonline.com` to `https://login.microsoftonline.us`. This change also applies to Microsoft 365 GCC High and M365 DoD environments, which Microsoft Entra authority for Azure Government also services. Microsoft Entra ID enforces the correct endpoint for sign-in operations. You can no longer sign in to an application registered in the Azure Government cloud using the public `https://login-us.microsoftonline.com` endpoint.
20+
21+
For more information, see [Endpoint Update - Microsoft Entra Authority for Azure Government](https://devblogs.microsoft.com/azuregov/azure-government-aad-authority-endpoint-update)
22+
23+
## Solution
24+
25+
To resolve this issue, ensure you use the correct Azure Government endpoint for sign-in operations. Here are the mappings between Azure services and Azure Government endpoints:
26+
27+
| Name | Azure Government Endpoint |
28+
| --- | --- |
29+
| Portal | `https://portal.azure.us` |
30+
| Microsoft Graph API | `https://graph.microsoft.us` |
31+
| Active Directory Endpoint and Authority | `https://login.microsoftonline.us` |
32+
33+
For more information, see [Azure Government endpoint mappings](/azure/azure-government/documentation-government-developer-guide#endpoint-mapping).
34+
35+
## More information
36+
37+
Each national cloud environment differs from the global Microsoft environment. When you develop applications for these environments, it's important to understand key differences. For example, registering applications, acquiring tokens and calling the Microsoft Graph API can be different.
38+
39+
For more information about registering applications in a national cloud, see [App registration endpoints](/entra/identity-platform/authentication-national-cloud#app-registration-endpoints).
40+
41+
For more information about acquire tokens in a national cloud, see [Microsoft Entra authentication endpoints](/entra/identity-platform/authentication-national-cloud#azure-ad-authentication-endpoints).
42+
43+
For more information about the different Microsoft Graph national cloud deployments and the capabilities that are available to developers within each, see [Microsoft Graph national cloud deployments](/graph/deployments). Here is a sample for implementation: [Configure .Net Application to call Microsoft Graph in a National Cloud Tenant](https://blogs.aaddevsup.xyz/2020/06/configure-net-application-to-call-microsoft-graph-in-a-national-cloud-tenant).
44+
45+
[!INCLUDE [Azure Help Support](../../../includes/azure-help-support.md)]

support/entra/entra-id/toc.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -114,6 +114,8 @@
114114
href: app-integration/error-code-aadsts7000110-request-is-ambiguous.md
115115
- name: Error AADSTS7000112 - application is disabled
116116
href: app-integration/error-code-aadsts7000112-application-is-disabled.md
117+
- name: EError AADSTS900439 - USGClientNotSupportedOnPublicEndpoint
118+
href: app-integration/error-aadsts900439-usgclientnotsupportedonpublicendpoint.md
117119
- name: Troubleshoot signing in to SAML-based single sign-on configured apps
118120
href: app-integration/troubleshoot-sign-in-saml-based-apps.md
119121
- name: Troubleshooting infinite redirection between OIDC app and Entra ID

0 commit comments

Comments
 (0)