Skip to content

[Core] az login: honor AZURE_CLI_DISABLE_CONNECTION_VERIFICATION for MSAL requests - #33725

Draft
Yash (notyashhh) with Copilot wants to merge 2 commits into
devfrom
copilot/fix-azure-cli-login-verification
Draft

[Core] az login: honor AZURE_CLI_DISABLE_CONNECTION_VERIFICATION for MSAL requests#33725
Yash (notyashhh) with Copilot wants to merge 2 commits into
devfrom
copilot/fix-azure-cli-login-verification

Conversation

Copilot AI commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Related command
az login

Description

AZURE_CLI_DISABLE_CONNECTION_VERIFICATION=1 had no effect on az login. The env var only patched post-auth API sessions (via _debug.py), while MSAL's initial OIDC discovery request to login.microsoftonline.com always ran with verify=True. Behind TLS inspection proxies (e.g. Zscaler), login failed with SSLCertVerificationError.

Root cause: Identity._msal_app_kwargs never set MSAL's verify parameter.

  • identity.py: _msal_app_kwargs now passes verify=False when should_disable_connection_verify() is true (reusing the existing core/util.py helper). This propagates to PublicClientApplication/ConfidentialClientApplication/SP credentials, covering the login discovery request.
  • Tests: added coverage asserting no verify kwarg by default, and verify=False when the env var is set.
if should_disable_connection_verify():
    kwargs["verify"] = False

Testing Guide

export AZURE_CLI_DISABLE_CONNECTION_VERIFICATION=1
az login --use-device-code   # no longer fails at OIDC discovery behind a TLS proxy

Unit tests: python -m unittest azure.cli.core.auth.tests.test_identity.TestIdentity

Note: On Python 3.13, a separate urllib3 2.6.0 issue (VERIFY_X509_STRICT, urllib3/urllib3#5110) can still render verify=False ineffective at the OpenSSL level. That is upstream and out of scope here.

History Notes

[Core] az login: Pass verify=False to MSAL when AZURE_CLI_DISABLE_CONNECTION_VERIFICATION is set, so login works behind TLS inspection proxies


This checklist is used to make sure that common guidelines for a pull request are followed.

@azure-client-tools-bot-prd

azure-client-tools-bot-prd Bot commented Jul 14, 2026

Copy link
Copy Markdown
️✔️AzureCLI-FullTest
️✔️acr
️✔️latest
️✔️3.12
️✔️3.14
️✔️acs
️✔️latest
️✔️3.12
️✔️3.14
️✔️advisor
️✔️latest
️✔️3.12
️✔️3.14
️✔️ams
️✔️latest
️✔️3.12
️✔️3.14
️✔️apim
️✔️latest
️✔️3.12
️✔️3.14
️✔️appconfig
️✔️latest
️✔️3.12
️✔️3.14
️✔️appservice
️✔️latest
️✔️3.12
️✔️3.14
️✔️aro
️✔️latest
️✔️3.12
️✔️3.14
️✔️backup
️✔️latest
️✔️3.12
️✔️3.14
️✔️batch
️✔️latest
️✔️3.12
️✔️3.14
️✔️batchai
️✔️latest
️✔️3.12
️✔️3.14
️✔️billing
️✔️latest
️✔️3.12
️✔️3.14
️✔️botservice
️✔️latest
️✔️3.12
️✔️3.14
️✔️cloud
️✔️latest
️✔️3.12
️✔️3.14
️✔️cognitiveservices
️✔️latest
️✔️3.12
️✔️3.14
️✔️compute_recommender
️✔️latest
️✔️3.12
️✔️3.14
️✔️computefleet
️✔️latest
️✔️3.12
️✔️3.14
️✔️config
️✔️latest
️✔️3.12
️✔️3.14
️✔️configure
️✔️latest
️✔️3.12
️✔️3.14
️✔️consumption
️✔️latest
️✔️3.12
️✔️3.14
️✔️container
️✔️latest
️✔️3.12
️✔️3.14
️✔️containerapp
️✔️latest
️✔️3.12
️✔️3.14
️✔️core
️✔️latest
️✔️3.12
️✔️3.14
️✔️cosmosdb
️✔️latest
️✔️3.12
️✔️3.14
️✔️databoxedge
️✔️latest
️✔️3.12
️✔️3.14
️✔️dls
️✔️latest
️✔️3.12
️✔️3.14
️✔️dms
️✔️latest
️✔️3.12
️✔️3.14
️✔️eventgrid
️✔️latest
️✔️3.12
️✔️3.14
️✔️eventhubs
️✔️latest
️✔️3.12
️✔️3.14
️✔️feedback
️✔️latest
️✔️3.12
️✔️3.14
️✔️find
️✔️latest
️✔️3.12
️✔️3.14
️✔️hdinsight
️✔️latest
️✔️3.12
️✔️3.14
️✔️identity
️✔️latest
️✔️3.12
️✔️3.14
️✔️iot
️✔️latest
️✔️3.12
️✔️3.14
️✔️keyvault
️✔️latest
️✔️3.12
️✔️3.14
️✔️lab
️✔️latest
️✔️3.12
️✔️3.14
️✔️managedservices
️✔️latest
️✔️3.12
️✔️3.14
️✔️maps
️✔️latest
️✔️3.12
️✔️3.14
️✔️marketplaceordering
️✔️latest
️✔️3.12
️✔️3.14
️✔️monitor
️✔️latest
️✔️3.12
️✔️3.14
️✔️mysql
️✔️latest
️✔️3.12
️✔️3.14
️✔️netappfiles
️✔️latest
️✔️3.12
️✔️3.14
️✔️network
️✔️latest
️✔️3.12
️✔️3.14
️✔️policyinsights
️✔️latest
️✔️3.12
️✔️3.14
️✔️postgresql
️✔️latest
️✔️3.12
️✔️3.14
️✔️privatedns
️✔️latest
️✔️3.12
️✔️3.14
️✔️profile
️✔️latest
️✔️3.12
️✔️3.14
️✔️rdbms
️✔️latest
️✔️3.12
️✔️3.14
️✔️redis
️✔️latest
️✔️3.12
️✔️3.14
️✔️relay
️✔️latest
️✔️3.12
️✔️3.14
️✔️resource
️✔️latest
️✔️3.12
️✔️3.14
️✔️role
️✔️latest
️✔️3.12
️✔️3.14
️✔️search
️✔️latest
️✔️3.12
️✔️3.14
️✔️security
️✔️latest
️✔️3.12
️✔️3.14
️✔️servicebus
️✔️latest
️✔️3.12
️✔️3.14
️✔️serviceconnector
️✔️latest
️✔️3.12
️✔️3.14
️✔️servicefabric
️✔️latest
️✔️3.12
️✔️3.14
️✔️signalr
️✔️latest
️✔️3.12
️✔️3.14
️✔️sql
️✔️latest
️✔️3.12
️✔️3.14
️✔️sqlvm
️✔️latest
️✔️3.12
️✔️3.14
️✔️storage
️✔️latest
️✔️3.12
️✔️3.14
️✔️synapse
️✔️latest
️✔️3.12
️✔️3.14
️✔️telemetry
️✔️latest
️✔️3.12
️✔️3.14
️✔️util
️✔️latest
️✔️3.12
️✔️3.14
️✔️vm
️✔️latest
️✔️3.12
️✔️3.14

@azure-client-tools-bot-prd

azure-client-tools-bot-prd Bot commented Jul 14, 2026

Copy link
Copy Markdown
️✔️AzureCLI-BreakingChangeTest
️✔️Non Breaking Changes

Copilot AI changed the title [WIP] Fix az login to pass verify=False to MSAL [Core] az login: honor AZURE_CLI_DISABLE_CONNECTION_VERIFICATION for MSAL requests Jul 14, 2026
Copilot AI requested a review from Yash (notyashhh) July 14, 2026 00:54
@yonzhan

Copy link
Copy Markdown
Collaborator

az login

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Account az login/account act-identity-squad Auto-Assign Auto assign by bot

Projects

None yet

Development

Successfully merging this pull request may close these issues.

AZURE_CLI_DISABLE_CONNECTION_VERIFICATION does not pass verify=False to MSAL, breaking az login behind TLS proxies

3 participants