Clicking Sign Up Using Identifier First Profile Will Not Trigger HRD for Azure AD/ADFS Connections

Overview

When using an Azure AD/ADFS connection with Home Realm Discovery (HRD) and the Identifier First authentication profile, if a user tries to SIGN UP with an email domain configured in HRD, they are redirected to sign up for a DB connection rather than redirecting the user to log in with the Identity Provider (IdP) configured for that domain.

For other Enterprise connections, like SAML or OIDC, it works as expected.

Applies To

  • Entra ID / Azure Active Directory (AD) / Azure Active Directory Federated Services (ADFS)
  • Home Realm Discovery (HRD)
  • OpenID Connect (OIDC)

Solution

As a workaround, create a SAML or OIDC connection to the Azure AD tenant instead. Instructions for creating those Enterprise connections can be found here:

 

Recommended content

No recommended content found...