Repository navigation
Ios entitlements com. Microsoft. Adalcache #35831
|
Hi I'm building to ios from vs 2026 to a paired mac with physical iPhone attached. This is a dev build with. Net 9 and xcode 26.3 The build to the phone is fine until I add the above entitlement for Ms Entra. Then the deployment to the phone fails with failed to find the signing identity for the executable. Tried many things incl creating a dummy xcode project with the keychain added and named the same as the app id (to force the app provision profile to update) Wondered if anyone seen and found a solution? |
Replies: 3 comments
|
I do not know what is Adalcache, is this similar to AppExtensions, where there is currently some work going on #35765? |
Short AnswerThis is a known issue with MSAL (Microsoft Authentication Library) on iOS. The error occurs because adding the Entitlements.plist for MS Entra introduces keychain access group requirements that your provisioning profile doesn't yet include. The fix: Switch from automatic provisioning to manual provisioning in Visual Studio, and ensure your Entitlements.plist includes the keychain access groups MSAL needs. Root CauseWhen you add MS Entra authentication to a .NET MAUI iOS app, you need an The MSAL library fails with: The Fix: Switch to Manual ProvisioningStep 1: Create or Update Entitlements.plistMake sure your <?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>keychain-access-groups</key>
<array>
<string>$(AppIdentifierPrefix)com.microsoft.adalcache</string>
<string>$(AppIdentifierPrefix)com.yourcompany.yourapp</string>
</array>
</dict>
</plist>
Step 2: Configure Manual Provisioning in Visual Studio
Step 3: Update Your .csproj File (Alternative to GUI)If you prefer editing the project file directly, add this inside a <PropertyGroup Condition="'$(Configuration)' == 'Debug' And '$(TargetFramework)' == 'net9.0-ios'">
<CodesignEntitlements>Platforms/iOS/Entitlements.plist</CodesignEntitlements>
<CodesignKey>Apple Development: Your Name (TEAMID)</CodesignKey>
<CodesignProvision>YOUR_PROVISIONING_PROFILE_UUID</CodesignProvision>
</PropertyGroup>
<PropertyGroup Condition="'$(Configuration)' == 'Release' And '$(TargetFramework)' == 'net9.0-ios'">
<CodesignEntitlements>Platforms/iOS/Entitlements.plist</CodesignEntitlements>
<CodesignKey>Apple Distribution: Your Company Name (TEAMID)</CodesignKey>
<CodesignProvision>YOUR_DISTRIBUTION_PROFILE_UUID</CodesignProvision>
</PropertyGroup>Step 4: Clean and Rebuilddotnet clean
dotnet build -f net9.0-iosOr in Visual Studio: Build → Clean Solution → Rebuild Solution Why the Dummy Xcode Project Didn't WorkYour approach of creating a dummy Xcode project to force the provisioning profile to update was clever, but it didn't solve the core issue. The problem isn't the provisioning profile itself — it's that automatic provisioning in .NET MAUI doesn't properly wire up the Entitlements.plist file during device deployment. Manual provisioning tells the build system exactly which entitlements file to use and which signing identity/profile to apply. Additional TroubleshootingIf you still get the error after switching to manual provisioning: 1. Verify the provisioning profile includes keychain access groups — run this on your Mac: security cms -D -i ~/Library/MobileDevice/Provisioning\ Profiles/YOUR_PROFILE.mobileprovision | grep -A 10 "keychain"2. Ensure the Bundle ID matches — check your 3. Refresh provisioning profiles — in Visual Studio, go to Tools → Options → Xamarin → Apple Accounts, sign out and back in. 4. Delete and re-pair your Mac — In Visual Studio, go to Tools → iOS → Pair to Mac, remove the existing pairing, and pair again. Summary
This should resolve the "failed to find signing identity" error when MS Entra entitlements are added. Let me know if you need help locating your provisioning profile UUID or signing identity names! |
|
Hi many thanks for the lengthy reply. I eventually got it sorted by following a variety of methods from Gemimi including dragging the app file into the devices list in xcode after selecting my phone.
The whole experience was utterly ridiculous as even doing the build on a mac (I started on a paired windows pc) created the error and the solution was still esoteric.
I hope others don't run into it.
Ian
Sent from Outlook for Android<https://aka.ms/AAb9ysg>
…________________________________
From: Zakir Motala ***@***.***>
Sent: Saturday, 13 June 2026 14:12:05
To: dotnet/maui ***@***.***>
Cc: ianpele10-cpu ***@***.***>; Author ***@***.***>
Subject: Re: [dotnet/maui] Ios entitlements com. Microsoft. Adalcache (Discussion #35831)
Short Answer
This is a known issue with MSAL (Microsoft Authentication Library) on iOS. The error occurs because adding the Entitlements.plist for MS Entra introduces keychain access group requirements that your provisioning profile doesn't yet include.
The fix: Switch from automatic provisioning to manual provisioning in Visual Studio, and ensure your Entitlements.plist includes the keychain access groups MSAL needs.
________________________________
Root Cause
When you add MS Entra authentication to a .NET MAUI iOS app, you need an Entitlements.plist file with keychain access groups. The problem is that automatic provisioning doesn't properly handle these entitlements when deploying to a physical device.
The MSAL library fails with:
MsalClientException: missing_entitlements
The application does not have keychain access groups enabled in the Entitlements.plist
________________________________
The Fix: Switch to Manual Provisioning
Step 1: Create or Update Entitlements.plist
Make sure your Platforms/iOS/Entitlements.plist includes the keychain access group. Add this to the file:
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>keychain-access-groups</key>
<array>
<string>$(AppIdentifierPrefix)com.microsoft.adalcache</string>
<string>$(AppIdentifierPrefix)com.yourcompany.yourapp</string>
</array>
</dict>
</plist>
Important: The $(AppIdentifierPrefix) automatically resolves to your Team ID at build time. Replace com.yourcompany.yourapp with your actual bundle identifier.
Step 2: Configure Manual Provisioning in Visual Studio
1. Right-click your .NET MAUI project in Solution Explorer
2. Select Properties → iOS → Bundle Signing
3. Change Provisioning from "Automatic" to "Manual"
4. Select your Signing identity (Apple Development or Apple Distribution)
5. Select your Provisioning Profile (must match your App ID and certificate)
6. Set Custom Entitlements to point to Platforms/iOS/Entitlements.plist
Step 3: Update Your .csproj File (Alternative to GUI)
If you prefer editing the project file directly, add this inside a <PropertyGroup>:
<PropertyGroup Condition="'$(Configuration)' == 'Debug' And '$(TargetFramework)' == 'net9.0-ios'">
<CodesignEntitlements>Platforms/iOS/Entitlements.plist</CodesignEntitlements>
<CodesignKey>Apple Development: Your Name (TEAMID)</CodesignKey>
<CodesignProvision>YOUR_PROVISIONING_PROFILE_UUID</CodesignProvision>
</PropertyGroup>
<PropertyGroup Condition="'$(Configuration)' == 'Release' And '$(TargetFramework)' == 'net9.0-ios'">
<CodesignEntitlements>Platforms/iOS/Entitlements.plist</CodesignEntitlements>
<CodesignKey>Apple Distribution: Your Company Name (TEAMID)</CodesignKey>
<CodesignProvision>YOUR_DISTRIBUTION_PROFILE_UUID</CodesignProvision>
</PropertyGroup>
Step 4: Clean and Rebuild
dotnet clean
dotnet build -f net9.0-ios
Or in Visual Studio: Build → Clean Solution → Rebuild Solution
________________________________
Why the Dummy Xcode Project Didn't Work
Your approach of creating a dummy Xcode project to force the provisioning profile to update was clever, but it didn't solve the core issue. The problem isn't the provisioning profile itself — it's that automatic provisioning in .NET MAUI doesn't properly wire up the Entitlements.plist file during device deployment.
Manual provisioning tells the build system exactly which entitlements file to use and which signing identity/profile to apply.
________________________________
Additional Troubleshooting
If you still get the error after switching to manual provisioning:
1. Verify the provisioning profile includes keychain access groups — run this on your Mac:
security cms -D -i ~/Library/MobileDevice/Provisioning\ Profiles/YOUR_PROFILE.mobileprovision | grep -A 10 "keychain"
2. Ensure the Bundle ID matches — check your Info.plist CFBundleIdentifier matches the App ID in Apple Developer portal.
3. Refresh provisioning profiles — in Visual Studio, go to Tools → Options → Xamarin → Apple Accounts, sign out and back in.
4. Delete and re-pair your Mac — In Visual Studio, go to Tools → iOS → Pair to Mac, remove the existing pairing, and pair again.
________________________________
Summary
Step Action
1 Add keychain access groups to Entitlements.plist
2 Switch from automatic to manual provisioning
3 Select the correct signing identity and profile
4 Set Custom Entitlements to your Entitlements.plist
5 Clean, rebuild, and redeploy
________________________________
This should resolve the "failed to find signing identity" error when MS Entra entitlements are added.
Let me know if you need help locating your provisioning profile UUID or signing identity names!
—
Reply to this email directly, view it on GitHub<#35831?email_source=notifications&email_token=BZVDXZF3LIDYXL3PEEPCV4L47VHKLA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCNZSHA4TKOBYUZZGKYLTN5XKMYLVORUG64VFMV3GK3TUVRTG633UMVZF6Y3MNFRWW#discussioncomment-17289588>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/BZVDXZFLA4KBBZCTCZ363MT47VHKLAVCNFSNUABIKJSXA33TNF2G64TZHMZDMMRTHE2TEMRUHNCGS43DOVZXG2LPNY5TCMBSGI4TOMJTUF3AE>.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS<https://github.com/notifications/mobile/ios/BZVDXZHZ7AABKVBEFFRNLLT47VHKLA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCNZSHA4TKOBYUZZGKYLTN5XKMYLVORUG64VFMV3GK3TUVJTG633UMVZF62LPOM> and Android<https://github.com/notifications/mobile/android/BZVDXZHGUXLP7L3RFRU3JLL47VHKLA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCNZSHA4TKOBYUZZGKYLTN5XKMYLVORUG64VFMV3GK3TUVZTG633UMVZF6YLOMRZG62LE>. Download it today!
You are receiving this because you authored the thread.Message ID: ***@***.***>
|
Short Answer
This is a known issue with MSAL (Microsoft Authentication Library) on iOS. The error occurs because adding the Entitlements.plist for MS Entra introduces keychain access group requirements that your provisioning profile doesn't yet include.
The fix: Switch from automatic provisioning to manual provisioning in Visual Studio, and ensure your Entitlements.plist includes the keychain access groups MSAL needs.
Root Cause
When you add MS Entra authentication to a .NET MAUI iOS app, you need an
Entitlements.plistfile with keychain access groups. The problem is that automatic provisioning doesn't properly handle these entitlements when deploying to a physical device.The MSAL libra…