CiamLogin.com flagged as malicious by browsers

Aleks S 50 Reputation points
2023-08-09T04:54:11.1233333+00:00

When testing Microsoft Entra External Id it uses CIAMLogin dot com which is now been universally flagged as phishing or malicious domain. Also blocked by my company. What is Microsoft position on this? I’ve been using a Trial tenant to setup apps and get sign in and sign up flows working.

Obviously it is a part of msal.js in all of their code and other languages. It’s mentioned in the documentation online. I also understand that it is new and for entra. Domain was created in February 2023. What we need is if we can we find official information that Microsoft owns this domain and it is safe. See attached screenshot from safari even marks it in bright red when going to it. What’s an alternative if this isn’t resolved ?

Test: (from unit testing of msal js: https://test.ciamlogin.com)

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
{count} vote

Accepted answer
  1. Shweta Mathur 30,296 Reputation points Microsoft Employee Moderator
    2023-08-10T06:15:04.7366667+00:00

    Hi @Aleks S ,

    Thanks for bringing this up.

    We have identified that this domain is flagged as blacklist in SURBL. We have already raised the IcM for this and are working on it to remove this from the blacklist.

    I will update the status here once it has been resolved.

    Hope this will help.

    Thanks,

    Shweta


    Please remember to "Accept Answer" if answer helped you.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Eli Marvin 0 Reputation points
    2024-09-24T13:23:24.8633333+00:00

    We are experiencing this issue with HP Wolf. I thought it was resolved.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.