Try Connection Fails for Windows Live Social Connection with Business Accounts
Last Updated:
Overview
When using the Try Connection feature for a Windows Live social connection, the authentication fails if a Microsoft 365 (M365) business account is used. However, the authentication flow functions correctly when initiated directly from the application. This article explains the behavior of Windows Live social connections regarding business accounts.
Applies To
- Windows Live Social Connection
- Microsoft 365 Business Accounts
Cause
The default Windows Live connection is configured as a Social Connection designed for Business to Consumer (B2C) audiences using personal Microsoft accounts via the login.live.com endpoint. Business accounts require the login.microsoftonline.com endpoint. The application login works because it correctly routes business users to the organizational endpoint, whereas the Try Connection tester for the Social Connection does not.
Solution
Social connections are designed for personal accounts, while enterprise connections are designed for organizational accounts and business endpoints. To support business users, use a dedicated Azure Active Directory (Azure AD) enterprise connection.
Related References
- Enterprise Identity Providers
- Connect to Microsoft Azure Active Directory (Enterprise)
- Video Guide: Setting up Azure AD as a SAML Enterprise Connection