Description
My company began enforcing device compliance to access certain URLs. I don't know all the technical aspects, but essentially the browser reached out to the OS to authenticate (automatically) the session. When I look at my registry they enabled CloudAPIAuthEnabled for Chrome and WindowsSSO for Firefox. I noticed Firefox can access those sites in the default context, but not from a container. When I enable CloudAPIAuthEnabled for Brave, SSO is bypassed (uses the OS authentication) in the default context AND in a temporary container. I would imagine containers should NOT use device authentication (matching Firefox's behavior.)
Steps to reproduce
Prerequisite, access to a site that uses Microsoft EntraID (maybe works with Azure?)
- Enable CloudAPIAuthEnabled
- Navigate to the Microsoft SSO login in a default container. SSO should automatically use OS Authentication.
- Navigate to the Microsoft SSO login in a temporary container. SSO should NOT automatically use OS Authentication, but does.
Actual result
login.microsoftonline.com automatically authenticates using OS credentials (without prompting for login) in a container tab.
Expected result
Login should prompt for credentials (not automatically use OS credentials) in a container tab (not using OS Auth). If the site requires OS credentials, it might also fail and give an error like the following:
Reproduces how often
Easily reproduced
Brave version (brave://version info)
1.93.129 Chromium: 151.0.7922.71 (Official Build) (64-bit)
Windows 11 Version 25H2 (Build 26200.8893)
Channel information
Reproducibility
Miscellaneous information
No response
Description
My company began enforcing device compliance to access certain URLs. I don't know all the technical aspects, but essentially the browser reached out to the OS to authenticate (automatically) the session. When I look at my registry they enabled CloudAPIAuthEnabled for Chrome and WindowsSSO for Firefox. I noticed Firefox can access those sites in the default context, but not from a container. When I enable CloudAPIAuthEnabled for Brave, SSO is bypassed (uses the OS authentication) in the default context AND in a temporary container. I would imagine containers should NOT use device authentication (matching Firefox's behavior.)
Steps to reproduce
Prerequisite, access to a site that uses Microsoft EntraID (maybe works with Azure?)
Actual result
login.microsoftonline.com automatically authenticates using OS credentials (without prompting for login) in a container tab.
Expected result
Login should prompt for credentials (not automatically use OS credentials) in a container tab (not using OS Auth). If the site requires OS credentials, it might also fail and give an error like the following:
Reproduces how often
Easily reproduced
Brave version (brave://version info)
1.93.129 Chromium: 151.0.7922.71 (Official Build) (64-bit)
Windows 11 Version 25H2 (Build 26200.8893)
Channel information
Reproducibility
Miscellaneous information
No response