Domainless SAML federation in Microsoft Entra External ID
If you’ve ever set up direct federation with a SAML Identity Provider in Microsoft Entra External ID, you’ll know the pain. You configure everything correctly, invite a guest user, and then they hit a cryptic error at sign-in: AADSTS5000819: SAML Assertion is invalid. Email address claim is missing or does not match domain from an external realm. The root cause? Traditional SAML federation in Entra requires the domain in the user’s email claim to match the domain you’ve associated with…









