See update at the end.  This is no longer an issue.

Customer configures the following redirect URLs for his registered application in Azure AD


and issues the following request to authenticate to Azure AD:

GET<tenant id>/oauth2/authorize?client_id=<app id>&redirect_uri=https%3a%2f%2flocalhost%3a44396%2fbac%2faad%3freqId%3dA123&response_mode=form_post&….

After logging in he is redirected to https://localhost:44396/bac/aad instead of https://localhost:44396/bac/aad?reqId=A123.

The redirected URL does not have anything after the query string.

Root Cause:

The behavior is by design.  This is an Azure AD’s security feature to prevent Covert Redirect attack.


We recommend customer to make use of the ‘state’ parameter instead of using query string to preserve the state of the request.

Update 8/15/2019

Azure AD now can accept reply URLs with query string.  This can be done by modifying the manifest file in the App Registration portal like the following.  This functionality is currently not available in the UI yet.

“publisherDomain”: “”,
“replyUrlsWithType”: [
“url”: “https://localhost”,
“type”: “Web”
          “url”: “”,
          “type”: “Web”

“requiredResourceAccess”: [


Update 8/23/2019 – You now can enter reply URL with query string in the App Registration UI

0 0 vote
Article Rating
Notify of
Newest Most Voted
Inline Feedbacks
View all comments
November 1, 2018 2:07 pm

but i created one api in azure , i am using that api as redirect uri in token endpoint, it showing Access denied due to missing subscription key. Make sure to include subscription key when making requests to an API. error. how to pass key to that redirect uri

Brent Edds
Brent Edds
April 6, 2020 6:17 pm

Does this no longer work? I get an error when adding in UI or manifest

George Martinez
George Martinez
November 19, 2020 5:59 pm

This is not working for me