Fix Microsoft Entra Redirect URI Using the Wrong Registered URL
Question details
The user needs to resolve an issue where an ASP.NET application using Microsoft Entra ID redirects to the wrong registered URL during authentication.

- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Developing or configuring an ASP.NET application with Microsoft Entra ID for authentication using multiple registered redirect URIs.
- Observed behavior
- Microsoft Entra redirects users to an unexpected URI (often the last registered one) instead of the specific URI requested when the sign-in process began.
Ensure you have administrative access to the Microsoft Entra admin center for the specific app registration, and open your ASP.NET application's configuration files (such as appsettings.json) for cross-referencing.
Ensure Exact URI Matching and Clean Configuration
Fix the issue by verifying that the URI requested by the ASP.NET application perfectly matches one of the registered URIs in Entra ID, and remove outdated entries.
Microsoft Entra ID requires an exact string match for redirect URIs for security reasons. If the application requests a URI that differs even slightly (such as a missing trailing slash), Entra ID may fail to match it correctly or fall back to unexpected behavior when multiple URIs are present.
Open your ASP.NET project and check the authentication middleware configuration in your Startup.cs, Program.cs, or appsettings.json file to see exactly what redirect URI is being generated and sent.
Log in to the Microsoft Entra admin center, navigate to 'Identity' > 'Applications' > 'App registrations', and select your application.
Click on 'Authentication' in the left-hand menu and locate the 'Redirect URIs' section under the relevant platform (e.g., Web or Single-page application).
Ensure the URI sent by your application exactly matches one of the URIs in the list. This includes matching the scheme (http vs https), host, port, path, and trailing slash.
Delete any unused or old redirect URIs (such as outdated localhost ports) from the Entra ID portal to prevent conflicts, then click 'Save'.
Clear your web browser's cookies and cache, then retest the authentication flow in your application to confirm the correct redirect URI is now used.

Need a Lightweight Office Suite for Your Development Team?
While troubleshooting complex Microsoft Entra authentication flows, managing your project documentation shouldn't add to your workload. WPS Office provides a free, fast, and fully compatible alternative to Microsoft Office for all your documentation needs.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install WPS Office: Run the downloaded executable file and follow the simple on-screen instructions to complete the setup.
- 3. Open and Edit Documents: Launch WPS Office to seamlessly view, edit, and collaborate on your technical documentation and spreadsheets.

Frequently Asked Questions
Why does Microsoft Entra redirect to localhost instead of the production domain?
This usually happens if the ASP.NET authentication request doesn't explicitly specify the correct redirect URI, or if the environment variables are misconfigured. If the requested URI doesn't perfectly match the production URI, Entra ID might fall back to another registered URI like localhost. Ensure your middleware dynamically sets the correct redirect URI based on the active hosting environment.
Does the trailing slash matter in Microsoft Entra redirect URIs?
Yes, Microsoft Entra enforces exact string matching for redirect URIs. A URI with a trailing slash is considered an entirely different destination from one without it. You must ensure your application's code and the Entra ID registration use the exact same formatting.
How do I handle multiple redirect URIs for different environments in ASP.NET?
You should register all necessary redirect URIs (development, staging, production) in the single Entra ID app registration. Then, configure your ASP.NET application using environment-specific files (like appsettings.Development.json and appsettings.Production.json) so the application sends the correct environment-specific URI during the authentication request.




