Managing external identities to enable secure access for partners, customers, and other non-employees
Hello Josh Dinndorf,
Thank you for posting your query on Microsoft Q&A.
Based on your description I understood that You're asking whether it's possible in Microsoft Entra External ID to disable local sign-up while still allowing user creation via federated identity providers (IdPs), a behavior that works in Azure AD B2C today.
As of now, Entra External ID does not support automatic user creation from federated IdPs when sign-up is disabled.
In Entra External ID, when you set "isSignUpAllowed" to false, it does indeed prevent not just local signups but also the automatic creation of external users when they attempt to log in through identity providers (like your custom OIDC). This is why you're encountering the error stating that the user account does not exist in the tenant.
Unfortunately, as of now, there isn't a direct feature in Entra External ID that permits this configuration without additional handling.
However, you can post your feedback in our Azure feedback portal regarding the feature.
https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789
This channel is directly monitored by our PM's. They will look into this request and revert back to you directly with an update on this feature.
If the answer is helpful, please click "Accept Answer" and kindly upvote it.
Regards,
Monalisha