Why does azure auth-required app service insist on initiating a hybrid flow (response_type=code id-token)
02:09 23 Nov 2025

I have an Azure linux_web_app set up with so-called "Easy Auth" set that authentication is required and unauthenticated hits are redirected to login.

When I log in after hitting /, I'm redirected back to the /.auth/login/aad/callback route with errors that response_type id_token is not allowed. I KNOW THIS. I don't want to allow the hybrid flow. But I cannot figure out why the hybrid flow is being demanded.

If I set implicit_id_token_issuance_enabled = true, yes I can log in, but that shouldn't be necessary for this type = "Web"-only redirect_uris:

Implicit grant and hybrid flows

The implicit grant allows an application to request a token directly from the authorization endpoint.  It is only recommended for browser-based single-page applications (SPAs).​

-- azure portal

I've tried setting the following, which works to override the initial call, but then in the auth callback instead of an error we go into a loop where aad says "you're logged in" but easyauth says "I don't have everything I want (the id_token) so redirect to aad":

active_directory_v2 { ...

 login_parameters = {
   response_type="code"
 }

I just want authorization code flow, please.

azure azure-web-app-service easy-auth