Hacker News new | past | comments | ask | show | jobs | submit login

That seems like a strange flow, it means the user first has to input his email on your app, then you redirect to Microsoft, user will have to input his Microsoft email and password, and redirect back to your app.

This means the user now has to remember which email he used on your app, which is not very different from remembering which third party provider you used before.

Maybe I'm missing something, but how would you explain why Google does this two step login process?




You often don't have to put in the email again, thanks to eg. the username hint.

And then, if you're already logged in according to the auth provider, you don't have to type your password either.

A good thing about tgis is that the providers can require different kinds of MFA at their discretion though.

But, what would happen to that poor app if I have a live account associated with my gmail and a google account associated with my o365 mail? ....

Come to think of it, I have an email account to which I have associated an ms live account AND an o365 corporate account, and a google account ... Very confusing ...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: