A cloud-based identity and access management service for securing user authentication and resource access
Entra app registration rejects redirect URI on new domain: "The reply URL includes prohibited words or domains"
We are moving a consumer web app (sign-in with Xbox Live through the Microsoft identity platform) from xcore.gg to uzora.gg. Adding a redirect URI on the new domain to an app registration fails with:
The reply URL includes prohibited words or domains.
(The portal is in Italian, so the original text is "L'URL di risposta include parole o domini non consentiti.")
What I tried (all on 2026-10-01)
- Authentication blade > Add redirect URI > Web >
https://uzora.gg/api/auth/xbox/callback: fails. - The same URI through the manifest editor (
replyUrlsWithType, typeWeb): fails. - A brand-new, clean app registration (personal Microsoft accounts only, created without a redirect URI, so creation itself succeeds), then adding
https://uzora.gg/api/auth/xbox/callbackorhttps://api.uzora.gg/v1/auth/xbox/callback: both fail (correlation IDOG+bXmS5R0gjmZJ0ixT0gN). Creating the registration with "any Entra ID tenant + personal accounts" and the URI in the creation form failed the same way (correlation IDsyi6mWYxGh+1VIxYRP6Tuo). -
uzora.ggis verified as the publisher domain (via/.well-known/microsoft-identity-association.json) and as a custom domain in the tenant (DNS TXT record). Neither changed the result. - The URI follows the documented rules: HTTPS, no query string, no fragment, no wildcard, well under the length limit.
What I could isolate
- A callback path containing
xboxis accepted on the old domain (https://xcore.gg/api/auth/xbox/callback), so the path is not the trigger. - Both the apex
uzora.ggand the subdomainapi.uzora.ggare refused, so the host labeluzoraitself seems to trigger the check. The domain has been registered since 2025. My guess is a name-similarity or reserved-word rule, but I could not find it documented.
Questions
- Is the rule behind "prohibited words or domains" for reply URLs documented anywhere, and which word or pattern does
uzora.ggmatch? - Is there a supported way to request an exemption for a domain I own and have verified?
- Is there any registration type or configuration that avoids this check?
Current workaround
I keep the old redirect URI registered on xcore.gg and let it forward to uzora.gg. This works but depends on keeping the old domain and its redirect alive indefinitely, so registering the new host directly would be much better.