Entra app registration rejects redirect URI on new domain: "The reply URL includes prohibited words or domains"

Federico Ercole 0 Reputation points
2026-10-01T15:16:10.1666667+00:00

We are moving a consumer web app (sign-in with Xbox Live through the Microsoft identity platform) from xcore.gg to uzora.gg. Adding a redirect URI on the new domain to an app registration fails with:

The reply URL includes prohibited words or domains.

(The portal is in Italian, so the original text is "L'URL di risposta include parole o domini non consentiti.")

What I tried (all on 2026-10-01)

  • Authentication blade > Add redirect URI > Web > https://uzora.gg/api/auth/xbox/callback: fails.
  • The same URI through the manifest editor (replyUrlsWithType, type Web): fails.
  • A brand-new, clean app registration (personal Microsoft accounts only, created without a redirect URI, so creation itself succeeds), then adding https://uzora.gg/api/auth/xbox/callback or https://api.uzora.gg/v1/auth/xbox/callback: both fail (correlation ID OG+bXmS5R0gjmZJ0ixT0gN). Creating the registration with "any Entra ID tenant + personal accounts" and the URI in the creation form failed the same way (correlation ID syi6mWYxGh+1VIxYRP6Tuo).
  • uzora.gg is verified as the publisher domain (via /.well-known/microsoft-identity-association.json) and as a custom domain in the tenant (DNS TXT record). Neither changed the result.
  • The URI follows the documented rules: HTTPS, no query string, no fragment, no wildcard, well under the length limit.

What I could isolate

  • A callback path containing xbox is accepted on the old domain (https://xcore.gg/api/auth/xbox/callback), so the path is not the trigger.
  • Both the apex uzora.gg and the subdomain api.uzora.gg are refused, so the host label uzora itself seems to trigger the check. The domain has been registered since 2025. My guess is a name-similarity or reserved-word rule, but I could not find it documented.

Questions

  1. Is the rule behind "prohibited words or domains" for reply URLs documented anywhere, and which word or pattern does uzora.gg match?
  2. Is there a supported way to request an exemption for a domain I own and have verified?
  3. Is there any registration type or configuration that avoids this check?

Current workaround

I keep the old redirect URI registered on xcore.gg and let it forward to uzora.gg. This works but depends on keeping the old domain and its redirect alive indefinitely, so registering the new host directly would be much better.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.