Skip to content

Az login on Web Account Manager (WAM) does nto work for professional accounts #34121

Description

@arctumn

Describe the bug

When using the new WAM if you select a professional account when there is none associated on windows the modal where you select a professional account you are not being redirected to select which professional/corporate email, it just hangs forcing you to pass the device code command to have an alternative way to connect to azure on cli

Related command

az login

Errors

There is no traceback, it just hangs with nothing happening

Issue script & Debug output

PS C:\Users\Pedro Lopes\source\repos\gs1pt-mono-associated-area> az login --debug
cli.knack.cli: Command arguments: ['login', '--debug']
cli.knack.cli: __init__ debug log:
Enable color in terminal.
Enable VT mode.
cli.knack.cli: Event: Cli.PreExecute []
cli.knack.cli: Event: CommandParser.OnGlobalArgumentsCreate [<function CLILogging.on_global_arguments at 0x000002294CA89B10>, <function OutputProducer.on_global_arguments at 0x000002294CF90A90>, <function CLIQuery.on_global_arguments at 0x000002294CFBF110>]
cli.knack.cli: Event: CommandInvoker.OnPreCommandTableCreate []
cli.azure.cli.core: Using packaged command index for profile 'latest'.
cli.azure.cli.core: Found installed extension 'automation' (azext_automation).
cli.azure.cli.core: Blending packaged core index with local extension index.
cli.azure.cli.core: Modules found from index for 'login': ['azure.cli.command_modules.profile']
cli.azure.cli.core: Loading command modules...
cli.azure.cli.core: Name                  Load Time    Groups  Commands
cli.azure.cli.core: profile                   0.004         2         8
cli.azure.cli.core: Loaded command modules:
cli.azure.cli.core: Total (1)                 0.004         2         8
cli.azure.cli.core: These extensions are not installed and will be skipped: ['azext_ai_examples', 'azext_next']
cli.azure.cli.core: Loading extensions:
cli.azure.cli.core: Name                  Load Time    Groups  Commands  Directory
cli.azure.cli.core: Total (0)                 0.000         0         0
cli.azure.cli.core: Loaded 2 groups, 8 commands.
cli.azure.cli.core: Found a match in the command table.
cli.azure.cli.core: Raw command  : login
cli.azure.cli.core: Command table: login
cli.knack.cli: Event: CommandInvoker.OnPreCommandTableTruncate [<function AzCliLogging.init_command_file_logging at 0x000002294D1838A0>]
cli.azure.cli.core.azlogging: metadata file logging enabled - writing logs to 'C:\Users\Pedro Lopes\.azure\commands\2026-09-23.08-54-49.login.16468.log'.
az_command_data_logger: command args: login --debug
cli.knack.cli: Event: CommandInvoker.OnPreArgumentLoad [<function register_global_subscription_argument.<locals>.add_subscription_parameter at 0x000002294D095A60>]
cli.knack.cli: Event: CommandInvoker.OnPostArgumentLoad []
cli.knack.cli: Event: CommandInvoker.OnPostCommandTableCreate [<function register_ids_argument.<locals>.add_ids_arguments at 0x000002294D096090>, <function register_global_policy_argument.<locals>.add_global_policy_argument at 0x000002294D1D0460>, <function register_cache_arguments.<locals>.add_cache_arguments at 0x000002294D1D0510>, <function register_upcoming_breaking_change_info.<locals>.update_breaking_change_info at 0x000002294D1D05C0>]
cli.knack.cli: Event: CommandInvoker.OnCommandTableLoaded []
cli.knack.cli: Event: CommandInvoker.OnPreParseArgs []
cli.knack.cli: Event: CommandInvoker.OnPostParseArgs [<function OutputProducer.handle_output_argument at 0x000002294CF90B40>, <function CLIQuery.handle_query_parameter at 0x000002294CFBF1C0>, <function register_ids_argument.<locals>.parse_ids_arguments at 0x000002294D1D03B0>]
cli.azure.cli.core.auth.persistence: build_persistence: location='C:\\Users\\Pedro Lopes\\.azure\\msal_token_cache.bin', encrypt=True
cli.azure.cli.core.auth.binary_cache: load: C:\Users\Pedro Lopes\.azure\msal_http_cache.bin
urllib3.util.retry: Converted retries value: 1 -> Retry(total=1, connect=None, read=None, redirect=None, status=None)
msal.application: Broker enabled? True
msal.application: Falls back to broker._signin_interactively()
cli.azure.cli.core.auth.identity: Select the account you want to log in with. For more information on login with Azure CLI, see https://go.microsoft.com/fwlink/?linkid=2271136
msal.broker: [MSAL:0001]        INFO    SetAuthorityUri:80      Initializing authority from URI 'https://login.microsoftonline.com/organizations' without authority type, detected type 'ms_sts'
msal.broker: [MSAL:0002]        INFO    SetCorrelationId:241    Set correlation ID: a5a9b17a-95f9-4086-a386-7273e16ede1a
msal.broker: [MSAL:0002]        INFO    ExecuteInteractiveRequest:1404  The original authority is 'https://login.microsoftonline.com/organizations'
msal.broker: [MSAL:0002]        WARNING TryNormalizeRealm:2599  No HomeAccountId provided to normalize the realm
msal.broker: [MSAL:0002]        INFO    ExecuteInteractiveRequest:1415  The normalized realm is ''
msal.broker: [MSAL:0002]        INFO    ModifyAndValidateAuthParameters:228     Additional query parameter added successfully. Key: 'msal_client_sku' Value: 'MSAL.Python'
msal.broker: [MSAL:0002]        INFO    ModifyAndValidateAuthParameters:228     Additional query parameter added successfully. Key: 'msal_client_ver' Value: '1.36.0'
msal.broker: [MSAL:0002]        INFO    ModifyAndValidateAuthParameters:228     Additional query parameter added successfully. Key: 'msal_gui_thread' Value: 'true'
msal.broker: [MSAL:0002]        INFO    ModifyAndValidateAuthParameters:228     Additional query parameter added successfully. Key: 'msal_request_type' Value: 'consumer_passthrough'
msal.broker: [MSAL:0002]        INFO    ModifyAndValidateAuthParameters:251     Authority Realm: organizations
msal.broker: [MSAL:0002]        WARNING TryEnqueueMsaDeviceCredentialAcquisitionAndContinue:1297        MsaDeviceOperationProvider is not available. Not attempting to register the device.
msal.broker: [MSAL:0003]        WARNING ReturnResponseDueToMissingParameter:749 Attempted to read cache with a non-normalized realm, access token and ID token reads will fail
msal.broker: [MSAL:0003]        WARNING ReturnResponseDueToMissingParameter:777 Missing Required parameters, but found no account to return.
msal.broker: [MSAL:0003]        WARNING ReadAccountById:652     Account id is empty - account not found
msal.broker: [MSAL:0003]        INFO    GetCurrentWindowHandleForUIFlow:501     Specified brokerWindowHandle is valid.
msal.broker: [MSAL:0004]        INFO    CreateRequestForProviderWithProperties:859      Client-xtra-sku: MSAL.Python|1.36.0,|0.20.6,|,|,|10.1.1
msal.broker: [MSAL:0004]        INFO    AddClientSystemInfoToRequest:1250       Client-xtra-sku: MSAL.Python|1.36.0,|0.20.6,|,|,|10.1.1

Expected behavior

When the modal showes up and you select a professional/corporate email, a new window on the borwser or on a new modal should ask which professional/corporate you want to use to authenticate to azure.

Environment Summary

azure-cli 2.88.0 *

core 2.88.0 *
telemetry 1.1.0

Extensions:
automation 1.0.0b2
azure-devops 1.0.6
ml 2.42.0

Dependencies:
msal 1.36.0
azure-mgmt-resource 24.0.0

Python location 'C:\Program Files\Microsoft SDKs\Azure\CLI2\python.exe'
Config directory 'C:\Users\Pedro Lopes.azure'
Extensions directory 'C:\Users\Pedro Lopes.azure\cliextensions'

Python (Windows) 3.14.5 (tags/v3.14.5:5607950, May 10 2026, 10:43:50) [MSC v.1944 64 bit (AMD64)]

Legal docs and information: aka.ms/AzureCliLegal

Additional context

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Accountaz login/accountAuto-AssignAuto assign by botAuto-ResolveAuto resolve by botAzure CLI TeamThe command of the issue is owned by Azure CLI teamRequest X Engineering AgentRequest X Engineering Agent testing and reviewact-identity-squadbugThis issue requires a change to an existing behavior in the product in order to be resolved.customer-reportedIssues that are reported by GitHub users external to the Azure organization.

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions