# OIDC with Azure not working

**URL:** <https://forums.percona.com/t/oidc-with-azure-not-working/39018>\
**Category:** Percona Everest\
**Created:** [August 7, 2025, 2:03pm UTC](https://forums.percona.com/t/oidc-with-azure-not-working/39018 "2025-08-07T14:03:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Till](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/till/32/21733_2.png) [@Till](https://forums.percona.com/u/Till)\
**Post date:** [August 7, 2025, 2:03pm UTC](https://forums.percona.com/t/oidc-with-azure-not-working/39018/1 "2025-08-07T14:03:18Z")

</div>

```auto
everestctl settings oidc configure \                             
    --issuer-url="https://login.microsoftonline.com/$TENANT/v2.0" \
    --client-id="$APP" \
    --scopes="openid,profile,email,$APP/.default"

```

I setup the application as an SPA with the correct redirect URL. I can “login”, but then then Everest stops with “internal error”.

I’ve inspected the logs:

```auto
{"level":"error","T":"2025-08-07T14:01:51Z","logger":"everest","caller":"session/manager.go:215","msg":"failed to shorten token: could not extract jti"}

```

I think by default the app is using the ID token, do I need access tokens? The docs are not clear on this. I’ve had this problem with 1.7.0 and also 1.8.0.

---

<div class="post-metadata">

**Author:** ![Till](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/till/32/21733_2.png) [@Till](https://forums.percona.com/u/Till)\
**Post date:** [August 8, 2025, 12:06pm UTC](https://forums.percona.com/t/oidc-with-azure-not-working/39018/2 "2025-08-08T12:06:36Z")

</div>

Posted on GitHub, was told it’s fixed by this: [EVEREST-2210 Fix session blockList for MS Entra by maxkondr · Pull Request #1565 · percona/everest · GitHub](https://github.com/percona/everest/pull/1565)
