See exactly what Azure sends back during OpenID Connect login — including app roles.
response_type=code id_token to work, you must
enable "ID tokens" in Azure Portal → App Registration → Authentication → Implicit grant and hybrid flows.
From: https://login.microsoftonline.com/eff9c4da-84d4-473e-a5ce-df20fb35ca28/v2.0/.well-known/openid-configuration
{
"token_endpoint": "https://login.microsoftonline.com/eff9c4da-84d4-473e-a5ce-df20fb35ca28/oauth2/v2.0/token",
"token_endpoint_auth_methods_supported": [
"client_secret_post",
"private_key_jwt",
"client_secret_basic",
"self_signed_tls_client_auth"
],
"jwks_uri": "https://login.microsoftonline.com/eff9c4da-84d4-473e-a5ce-df20fb35ca28/discovery/v2.0/keys",
"response_modes_supported": [
"query",
"fragment",
"form_post"
],
"subject_types_supported": [
"pairwise"
],
"id_token_signing_alg_values_supported": [
"RS256"
],
"response_types_supported": [
"code",
"id_token",
"code id_token",
"id_token token"
],
"scopes_supported": [
"openid",
"profile",
"email",
"offline_access"
],
"issuer": "https://login.microsoftonline.com/eff9c4da-84d4-473e-a5ce-df20fb35ca28/v2.0",
"request_uri_parameter_supported": false,
"userinfo_endpoint": "https://graph.microsoft.com/oidc/userinfo",
"authorization_endpoint": "https://login.microsoftonline.com/eff9c4da-84d4-473e-a5ce-df20fb35ca28/oauth2/v2.0/authorize",
"device_authorization_endpoint": "https://login.microsoftonline.com/eff9c4da-84d4-473e-a5ce-df20fb35ca28/oauth2/v2.0/devicecode",
"http_logout_supported": true,
"frontchannel_logout_supported": true,
"end_session_endpoint": "https://login.microsoftonline.com/eff9c4da-84d4-473e-a5ce-df20fb35ca28/oauth2/v2.0/logout",
"claims_supported": [
"sub",
"iss",
"cloud_instance_name",
"cloud_instance_host_name",
"cloud_graph_host_name",
"msgraph_host",
"aud",
"exp",
"iat",
"auth_time",
"acr",
"nonce",
"preferred_username",
"name",
"tid",
"ver",
"at_hash",
"c_hash",
"email"
],
"kerberos_endpoint": "https://login.microsoftonline.com/eff9c4da-84d4-473e-a5ce-df20fb35ca28/kerberos",
"mtls_endpoint_aliases": {
"token_endpoint": "https://mtlsauth.microsoft.com/eff9c4da-84d4-473e-a5ce-df20fb35ca28/oauth2/v2.0/token"
},
"tls_client_certificate_bound_access_tokens": true,
"tenant_region_scope": "OC",
"cloud_instance_name": "microsoftonline.com",
"cloud_graph_host_name": "graph.windows.net",
"msgraph_host": "graph.microsoft.com",
"rbac_url": "https://pas.windows.net"
}