# Vendor facets — Microsoft Entra (External ID, successor to Azure AD B2C). Customer identity with user # flows and custom URL domains fronted by Azure Front Door. Headline: every discovery document is # TENANT-SCOPED (https:////v2.0/.well-known/openid-configuration), and the # harvest probes only host roots, so the served tiers are not reached even on the provider's own domain. # Microsoft states plainly that Entra publishes no RFC 7591 registration endpoint. vendor: microsoft-entra name: Microsoft Entra External ID website: https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-external-id areas: - identity registry_keys: - azure-ad-b2c rubric_schema_version: 0.22.0 generated: '2026-09-25' features_refreshed: '2026-09-25' basis: capability summary: >- Entra External ID lifts almost nothing on the identity dimensions as the rubric reads them today. Its discovery documents live under a tenant path, not at a host root, so a provider using a custom URL domain still is not read as serving discovery; it can earn the OpenAPI fallback tiers only by declaring OAuth in its own contract. There is no dynamic client registration (Microsoft says so for MCP), and no protected-resource metadata. Hosted user flows give a sign-up page the provider can declare. features: - id: custom-url-domains name: Custom URL domains description: >- Brands the sign-in endpoints on a verified subdomain (login.contoso.com) routed through an Azure Front Door profile the customer runs (Standard or Premium); endpoints keep the // path prefix. source: https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-custom-url-domain tier: paid - id: user-flows name: Sign-up and sign-in user flows description: >- Hosted sign-up/sign-in user flows for external tenants, runnable on the default ciamlogin.com domain or the custom URL domain. source: https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-custom-url-domain tier: all - id: tenant-discovery name: Tenant-scoped OIDC discovery description: >- v2.0 discovery documents carry a tenant-templated issuer and advertise private_key_jwt and self_signed_tls_client_auth client authentication; no registration_endpoint. source: https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration tier: all - id: no-dcr name: Static app registration only (no DCR) description: >- Microsoft documents that Entra ID publishes no RFC 7591 registration endpoint, so MCP clients must be registered statically. source: >- https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/plugin-authentication-dynamic-client-registration tier: all maps: - feature: tenant-discovery check: auth_clarity layer: agent_readiness grade: negotiable partial: true partial_note: >- The served tier reads a root /.well-known/openid-configuration on a provider host; Entra's is under //v2.0/, which the root-only harvest never requests. Only the OpenAPI fallback is reachable. provider_must: Declare the Entra-backed oauth2 or openIdConnect scheme in its own OpenAPI. points: 10 baseline_pass_rate: 0.474 - feature: tenant-discovery check: delegated_identity layer: agent_readiness grade: documented partial: true partial_note: >- Same tenant-path reason; the documented tier reads an authorizationCode flow or openIdConnect in the provider's OpenAPI. provider_must: Declare the authorizationCode flow in its own OpenAPI. points: 6 baseline_pass_rate: 0.209 - feature: user-flows check: sign_up_present layer: composite provider_must: Declare the user-flow sign-up URL as a Login or SignUp pointer in apis.yml. catalog_pass_rate: 0.19 facet: access_clarity points: 5 baseline_pass_rate: 0.463 - feature: tenant-discovery check: reg_fapi_profile layer: composite conditional: true condition: >- Banking/open-finance regime only, and only if the provider's own auth documentation states it uses private_key_jwt or certificate-bound client authentication. catalog_pass_rate: 0.196 facet: regulatory points: 6 baseline_pass_rate: 0.463 earns_nothing: - feature: custom-url-domains check: auth_clarity why: >- A custom URL domain puts discovery on the provider's host but still under //v2.0/, so it reads exactly as the ciamlogin.com default does. - feature: tenant-discovery check: well_known_published why: openid-configuration is not one of the well-known documents that check reads. out_of_reach: checks: - dynamic_client_registration - protected_resource_metadata - security_schemes_defined - oauth_scopes_enumerated - consent_identity note: >- No RFC 7591 endpoint by Microsoft's own statement; RFC 9728 and the OpenAPI checks are the provider's resource server and contract. surface: access_clarity: reachable: 5.0 total: 38 regulatory: reachable: 6.0 total: 108 agent_readiness: reachable: 10.5 total: 139 hard_rule: >- A model, not a score. Adopting this vendor changes a provider's Kin Score only when the provider publishes the resulting artifacts on its own surface; nothing here writes a score, and no sponsorship or partnership can. method: searched source: - https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-custom-url-domain - >- https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/plugin-authentication-dynamic-client-registration - https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration measured: cohort: method: vendors-catalog.json detections (CNAME / header / URL shape / markup), never a name match detected: 0 in_baseline: 0 control: basis: providers earning contract_present + documentation_present + api_reference_present, minus the cohort n: 5216 metric: >- cohort_pct / control_pct = mean share of the check's points earned (derived and platform credit weighted), x100 measured_on: '2026-09-25' status: 'not measurable: 0 detected customers clear the baseline (need 20)' simulation: simulated_on: '2026-09-25' rubric: 0.23.0 population: providers publishing a contract (contract_present earned), replayable exactly providers: 8977 providers_unreplayable: 987 providers_moved: 8268 conditional_rows: excluded (they depend on what the API already does) composite_lift: median: 2.4 p75: 2.6 p90: 2.7 max: 2.7 mean_among_movers: 2.3 agent_readiness_lift: median: 5.0 p75: 5.1 p90: 5.9 max: 8.8 mean_among_movers: 5.3 facet_lift_median_among_movers: access_clarity: 13.1 composite_band_moves: thin -> developing: 679 developing -> strong: 189 emerging -> thin: 167 strong -> exemplar: 48 minimal -> emerging: 1 agent_readiness_band_moves: agent-aware -> agent-ready: 2198 agent-ready -> agent-native: 170 method: >- each provider's own kin/checks file, the vendor's maps at their stated credit, the scorer's composite formula; from -> to, nothing written