Quantcast
Channel: Azure Active Directory forum
Viewing all 16000 articles
Browse latest View live

PrincipalNotFound: Principal xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx does not exist in the directory xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx

$
0
0

I am trying to create a role assignment using the Azure Resource Management REST API.

https://management.azure.com/{scope}/providers/Microsoft.Authorization/roleAssignments/{role-assignment-id}?api-version={api-version}

I've verified that the principalID in question does in fact exist. I can also create the assignment using xplat cli and PowerShell using the same PrincipalId. Any ideas why i'm getting this error when attempting this with the REST call?


Phil Jirsa - Senior Consultant | Rackspace


Multi Forest AD Sync

$
0
0

We currently have our student domain, email.mydomain.com, synced to O365 using DirSync.  I am configuring our production domain, production.mydoman.com to use OneDrive as a My Docs redirect.  Will I need a separate tenant apart from my student domain to do this, or is it possible to use the same global admin amount from my student O365 presence?  My planned course of action is to install AAD Connect using only password hash sync on a production domain member server (not a DC) into the current O365 tenant alongside our student domain.  

Am I on the right track?

Tony

SCIMv2 compliance

$
0
0

The new Azure SCIMv2 provisioning uses some parts of the SCIM v2 specification that are optional, namely: -

  • Use of Patch Operations on User & Group is only optional in SCIM v2, so if a service does not support (as many do not), could you also use a GET & PUT (replace)?
  • Use of the User Enterprise extension is also optional, but the patch operation example shows that you query on the manager attribute.
    • Could you elaborate why this is used?
    • What happens if the service does not support the enterprise user extension?
  • We assume the same patch approach is used for groups, can we confirm this?
  • Will there be a conformance suite available for testing?
  • Do we have any pointers on how to validate the Azure Bearer Token?


Having trouble deleting a directory

$
0
0

I'm getting an error when trying to delete a directory.

The error says:

The following issue(s) prevent deletion of this directory:
  • Directory has one or more Multi-Factor Authentication providers.
  • You are signed in as a user for whom 'Second 8th Week' is the home directory
  • Directory is configured for partner administration.
  • Directory provisioning is not yet complete.
  • Directory has one or more subscriptions to Microsoft Online Services.
  • Directory has one or more applications that were added by a user or administrator.
  • Directory contains one or more applications that were added by a user or administrator.

When I go into the directory and list the applications, I see these:

NamePublisherTypeApp URL
Filter
Office 365 Management APIsMicrosoft CorporationWeb application
Visual Studio OnlineMicrosoft CorporationWeb applicationhttps://www.visualstudio.com/

I can't delete either of these so I don't know how to correct this problem. Any ideas on where to start with solving this?

Mixed AD

$
0
0

Hi,

I use Office 365 Sharepoint Online, for all my 240 users.

140 of them don't have a PC, and they only use SharePoint Online.

I use Azure AD Sync, so all 240 have Azure AD Free.

I would like to convert the 140 users to Azure AD Basic, and use password reset.

Anyone know if this is possible, and how ?

Is there an easy way to convert the users from free to basic ?

Thx.


Can't connect to OneDrive

$
0
0

From: Toniolo Consulting @TonioloAus via Twitter

I've joined my Windows 10 computer to the AZ AD, and signed as my work user account. Since doing this however, I can no longer sync with my OneDrive for Business - "We cannot connect to specified SharePoint site". Even after logging into OneDrive f B and clicking sync/copying link. It only seems possible to me that these changes are related - any thoughts?

Thanks,

@AzureSupport

Azure License Assignment

$
0
0

Hello Sir,

I'm using Office 365 RMS powered by Azure Rights Management (Azure Active Directory). Do I have to assign Azure Rights Management license to every user or administrators only? Thanks.

Regards,

Ryan

Creating a Client Key from the new Azure Portal or PowerShell

$
0
0

I am developing an application that uses AD single organization authentication and AD RBAC roles in an MVC Web App.  Using the old Azure Portal, I was able to create a new Application and register the groups/users and client key (secret), however I cannot seems to find this option using the new Azure Portal.  I cannot access the old portal with this particular subscription.  Is there a way to do this from the new portal or using PowerShell?  I have been able to create an app using the following:

$azureAdApplication = New-AzureADApplication -DisplayName $applicationName -HomePage $applicationHomePage -IdentifierUris $applicationHomePage -Password $applicationPassword

And assign roles to users using:

New-AzureRoleAssignment -ResourceGroupName $resourceGroupName -SignInName $signinName -RoleDefinitionName 'Contributor'

How do I create the customer key?


David Downing


Can I use our organizational AD with multiple Azure subscriptions?

$
0
0

First, it's important to note that we're 100% Azure based with no on-premises network or servers.

We currently have a bunch of VMs in our virtual network on Azure. Our organizational AD which runs on a VM is linked to our Azure AD and Office 365 AD via ADFS and DirSync which are also running in the same virtual network on Azure.

Here's what I want to do next:

We have a second Azure subscription where we're developing a new web based product. The developers who are building this new product are members of the same organization that owns the first subscription and it would make a lot of sense to extend our organizational AD to this second subscription so that we can continue to manage all our resources from the same AD and have single sign-on in the second subscription as well.

  1. Can I connect multiple Azure subscriptions to one organizational AD that resides in a VM in our first Azure subscription?
  2. If yes, what do I need to set up in the second, third, etc Azure subscriptions?

Thanks, Sam


AAD Connect tool Error

$
0
0

Hi All,

I have successfully synchronized from all users of on premise  ADDS  to office 365 ( SPO) and can login in SPO.

But I have been experiencing issue in AAD connect tool when ever I run sometime of  after reboot machine or after couple of days.   When I uninstall then install it works fine  but same issue occurs again and again.

Below is the Error log. ( My on premise environment  has all components SP13, SQL , ADDS so all components on single machine )  

During setup , I provide Admin accounts of both environment ( on-premise , SPO ) but SP services  are running  under another service account including both FIM service.  Also , MS Azure AD sync is running under new service account created by tool setup.

Here is complete log :- 

[04:24:26.629] [  1] [INFO ] 

[04:24:26.754] [  1] [INFO ] ================================================================================
[04:24:26.754] [  1] [INFO ] Application starting
[04:24:26.754] [  1] [INFO ] ================================================================================
[04:24:26.977] [  1] [INFO ] Application Version: 1.0.0.0-1440008509
[04:24:28.816] [  1] [INFO ] App Properties/Metrics:
[04:24:28.816] [  1] [INFO ]    Runtime.Start=2015-11-23T04:24:26+00:00
[04:24:28.816] [  1] [INFO ]    Application.Version=1.0.0.0-1440008509
[04:24:28.816] [  1] [INFO ]    Application.IsDebugBuild=False
[04:24:28.816] [  1] [INFO ]    Environment.OperatingSystem.VersionString=Microsoft Windows NT 6.2.9200.0
[04:24:28.816] [  1] [INFO ]    Environment.OperatingSystem.Platform=Win32NT
[04:24:28.816] [  1] [INFO ]    Environment.OperatingSystem.ServicePack=
[04:24:28.816] [  1] [INFO ]    Environment.OperatingSystem.ProductType=DomainController
[04:24:28.816] [  1] [INFO ]    Environment.OperatingSystem.Sku=8
[04:24:28.816] [  1] [INFO ]    Environment.OperatingSystem.Language=0409
[04:24:28.816] [  1] [INFO ]    Environment.OperatingSystem.IsDomainJoined=True
[04:24:28.816] [  1] [INFO ]    Runtime.EncodedPageNavigationBytes=
[04:24:28.816] [ 10] [INFO ] Starting Telemetry Send
[04:24:29.894] [  1] [INFO ] RootPageViewModel.GetInitialPages: Beginning detection for creating initial pages.
[04:24:30.004] [  1] [INFO ] Found existing persisted state context.
[04:24:30.363] [  1] [INFO ] DetectInstalledComponents stage: Checking install context.
[04:24:30.379] [  1] [INFO ] Performing direct lookup of upgrade codes for: Microsoft Online Services Sign-In Assistant for IT Professionals
[04:24:30.551] [  1] [VERB ] Getting list of installed packages by upgrade code
[04:24:30.568] [  1] [INFO ] GetInstalledPackagesByUpgradeCode {03c97135-0e31-4334-9215-63827d4f07d4}: verified product code {d8ab93b0-6fbf-44a0-971f-c0669b5ae6dd}.
[04:24:30.568] [  1] [VERB ] Package=Microsoft Online Services Sign-in Assistant, Version=7.250.4556.0, ProductCode=d8ab93b0-6fbf-44a0-971f-c0669b5ae6dd, UpgradeCode=03c97135-0e31-4334-9215-63827d4f07d4
[04:24:30.582] [  1] [INFO ] Determining installation action for Microsoft Online Services Sign-In Assistant for IT Professionals (03c97135-0e31-4334-9215-63827d4f07d4)
[04:24:30.582] [  1] [INFO ] Product Microsoft Online Services Sign-In Assistant for IT Professionals (version 7.250.4556.0) is installed.
[04:24:30.582] [  1] [INFO ] Performing direct lookup of upgrade codes for: Microsoft Azure Active Directory Module for Windows PowerShell
[04:24:30.582] [  1] [VERB ] Getting list of installed packages by upgrade code
[04:24:30.582] [  1] [INFO ] GetInstalledPackagesByUpgradeCode {bbf5d0bf-d8ae-4e66-91ab-b7023c1f288c}: verified product code {43cc9c53-a217-4850-b5b2-8c347920e500}.
[04:24:30.582] [  1] [VERB ] Package=Windows Azure Active Directory Module for Windows PowerShell, Version=1.0.0, ProductCode=43cc9c53-a217-4850-b5b2-8c347920e500, UpgradeCode=bbf5d0bf-d8ae-4e66-91ab-b7023c1f288c
[04:24:30.582] [  1] [INFO ] Determining installation action for Microsoft Azure Active Directory Module for Windows PowerShell (bbf5d0bf-d8ae-4e66-91ab-b7023c1f288c)
[04:24:30.582] [  1] [INFO ] Product Microsoft Azure Active Directory Module for Windows PowerShell (version 1.0.0) is installed.
[04:24:30.582] [  1] [INFO ] Performing direct lookup of upgrade codes for: Microsoft Visual C++ 2013 Redistributable Package
[04:24:30.582] [  1] [VERB ] Getting list of installed packages by upgrade code
[04:24:30.582] [  1] [INFO ] GetInstalledPackagesByUpgradeCode {20400cf0-de7c-327e-9ae4-f0f38d9085f8}: verified product code {a749d8e6-b613-3be3-8f5f-045c84eba29b}.
[04:24:30.582] [  1] [VERB ] Package=Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005, Version=12.0.21005, ProductCode=a749d8e6-b613-3be3-8f5f-045c84eba29b, UpgradeCode=20400cf0-de7c-327e-9ae4-f0f38d9085f8
[04:24:30.582] [  1] [INFO ] Determining installation action for Microsoft Visual C++ 2013 Redistributable Package (20400cf0-de7c-327e-9ae4-f0f38d9085f8)
[04:24:30.582] [  1] [INFO ] Product Microsoft Visual C++ 2013 Redistributable Package (version 12.0.21005) is installed.
[04:24:30.582] [  1] [INFO ] Performing direct lookup of upgrade codes for: Microsoft Directory Sync Tool
[04:24:30.597] [  1] [VERB ] Getting list of installed packages by upgrade code
[04:24:30.597] [  1] [INFO ] GetInstalledPackagesByUpgradeCode {bef7e7d9-2ac2-44b9-abfc-3335222b92a7}: no registered products found.
[04:24:30.597] [  1] [INFO ] GetInstalledPackagesByUpgradeCode {dc9e604e-37b0-4efc-b429-21721cf49d0d}: no registered products found.
[04:24:30.597] [  1] [INFO ] Determining installation action for Microsoft Directory Sync Tool UpgradeCodes {bef7e7d9-2ac2-44b9-abfc-3335222b92a7}, {dc9e604e-37b0-4efc-b429-21721cf49d0d}
[04:24:30.597] [  1] [INFO ] DirectorySyncComponent: Product Microsoft Directory Sync Tool is not installed.
[04:24:30.597] [  1] [INFO ] Performing direct lookup of upgrade codes for: Azure AD Sync Engine
[04:24:30.597] [  1] [VERB ] Getting list of installed packages by upgrade code
[04:24:30.597] [  1] [INFO ] GetInstalledPackagesByUpgradeCode {545334d7-13cd-4bab-8da1-2775fa8cf7c2}: verified product code {d160c994-0bfb-44fa-bf51-750cd607427f}.
[04:24:30.597] [  1] [INFO ] GetInstalledPackagesByUpgradeCode {dc9e604e-37b0-4efc-b429-21721cf49d0d}: no registered products found.
[04:24:30.597] [  1] [INFO ] GetInstalledPackagesByUpgradeCode {bef7e7d9-2ac2-44b9-abfc-3335222b92a7}: no registered products found.
[04:24:30.597] [  1] [VERB ] Package=Microsoft Azure AD Connect synchronization services, Version=1.0.8667.0, ProductCode=d160c994-0bfb-44fa-bf51-750cd607427f, UpgradeCode=545334d7-13cd-4bab-8da1-2775fa8cf7c2
[04:24:30.613] [  1] [INFO ] Determining installation action for Azure AD Sync Engine (545334d7-13cd-4bab-8da1-2775fa8cf7c2)
[04:24:31.769] [  1] [INFO ] Product Azure AD Sync Engine (version 1.0.8667.0) is installed.
[04:24:31.957] [  1] [ERROR] AzureADSyncEngineComponent: unexpected value retrieved for upgrade mode (0)
[04:24:31.957] [  1] [INFO ] Performing direct lookup of upgrade codes for: Azure AD Sync Engine Health Agent
[04:24:31.957] [  1] [VERB ] Getting list of installed packages by upgrade code
[04:24:31.957] [  1] [INFO ] GetInstalledPackagesByUpgradeCode {114fb294-8aa6-43db-9e5c-4ede5e32886f}: no registered products found.
[04:24:31.957] [  1] [INFO ] Determining installation action for Azure AD Sync Engine Health Agent (114fb294-8aa6-43db-9e5c-4ede5e32886f)
[04:24:31.957] [  1] [INFO ] Product Azure AD Sync Engine Health Agent is not installed.
[04:24:31.957] [  1] [INFO ] Performing direct lookup of upgrade codes for: Microsoft SQL Server 2012 Command Line Utilities
[04:24:31.957] [  1] [VERB ] Getting list of installed packages by upgrade code
[04:24:31.957] [  1] [INFO ] GetInstalledPackagesByUpgradeCode {52446750-c08e-49ef-8c2e-1e0662791e7b}: verified product code {58fed865-4f13-408d-a5bf-996019c4b936}.
[04:24:31.957] [  1] [VERB ] Package=Microsoft SQL Server 2012 Command Line Utilities , Version=11.1.3000.0, ProductCode=58fed865-4f13-408d-a5bf-996019c4b936, UpgradeCode=52446750-c08e-49ef-8c2e-1e0662791e7b
[04:24:31.957] [  1] [INFO ] Determining installation action for Microsoft SQL Server 2012 Command Line Utilities (52446750-c08e-49ef-8c2e-1e0662791e7b)
[04:24:31.957] [  1] [INFO ] Product Microsoft SQL Server 2012 Command Line Utilities (version 11.1.3000.0) is installed.
[04:24:31.957] [  1] [INFO ] Performing direct lookup of upgrade codes for: Microsoft SQL Server 2012 Express LocalDB
[04:24:31.957] [  1] [VERB ] Getting list of installed packages by upgrade code
[04:24:31.957] [  1] [INFO ] GetInstalledPackagesByUpgradeCode {c3593f78-0f11-4d8d-8d82-55460308e261}: verified product code {4f640a82-635e-431a-856a-f43e5eaac130}.
[04:24:31.957] [  1] [VERB ] Package=Microsoft SQL Server 2012 Express LocalDB , Version=11.1.3156.0, ProductCode=4f640a82-635e-431a-856a-f43e5eaac130, UpgradeCode=c3593f78-0f11-4d8d-8d82-55460308e261
[04:24:31.957] [  1] [INFO ] Determining installation action for Microsoft SQL Server 2012 Express LocalDB (c3593f78-0f11-4d8d-8d82-55460308e261)
[04:24:31.957] [  1] [INFO ] Product Microsoft SQL Server 2012 Express LocalDB (version 11.1.3156.0) is installed.
[04:24:31.957] [  1] [INFO ] Performing direct lookup of upgrade codes for: Microsoft SQL Server 2012 Native Client
[04:24:31.957] [  1] [VERB ] Getting list of installed packages by upgrade code
[04:24:31.957] [  1] [INFO ] GetInstalledPackagesByUpgradeCode {1d2d1fa0-e158-4798-98c6-a296f55414f9}: verified product code {d411e9c9-ce62-4dbf-9d92-4cb22b750ed5}.
[04:24:31.957] [  1] [VERB ] Package=Microsoft SQL Server 2012 Native Client , Version=11.1.3000.0, ProductCode=d411e9c9-ce62-4dbf-9d92-4cb22b750ed5, UpgradeCode=1d2d1fa0-e158-4798-98c6-a296f55414f9
[04:24:31.957] [  1] [INFO ] Determining installation action for Microsoft SQL Server 2012 Native Client (1d2d1fa0-e158-4798-98c6-a296f55414f9)
[04:24:31.957] [  1] [INFO ] Product Microsoft SQL Server 2012 Native Client (version 11.1.3000.0) is installed.
[04:24:31.957] [  1] [INFO ] Performing direct lookup of upgrade codes for: Microsoft Azure AD Connect Azure AD Connector
[04:24:31.957] [  1] [VERB ] Getting list of installed packages by upgrade code
[04:24:31.957] [  1] [INFO ] GetInstalledPackagesByUpgradeCode {fb3feca7-5190-43e7-8d4b-5eec88ed9455}: verified product code {706efae8-26a7-4e27-bbd0-2c3c1d7c194d}.
[04:24:31.957] [  1] [VERB ] Package=Microsoft Azure AD Connect Azure AD Connector, Version=1.0.8667.0, ProductCode=706efae8-26a7-4e27-bbd0-2c3c1d7c194d, UpgradeCode=fb3feca7-5190-43e7-8d4b-5eec88ed9455
[04:24:31.957] [  1] [INFO ] Determining installation action for Microsoft Azure AD Connect Azure AD Connector (fb3feca7-5190-43e7-8d4b-5eec88ed9455)
[04:24:31.957] [  1] [INFO ] Product Microsoft Azure AD Connect Azure AD Connector (version 1.0.8667.0) is installed.
[04:24:31.972] [  1] [INFO ] Determining installation action for Microsoft Azure AD Connection Tool.
[04:24:32.160] [  1] [WARN ] Failed to read DisplayName registry key: An error occurred while executing the 'Get-ItemProperty' command. Cannot find path 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MicrosoftAzureADConnectionTool' because it does not exist.
[04:24:32.160] [  1] [INFO ] Product Microsoft Azure AD Connection Tool is not installed.
[04:24:32.160] [  1] [INFO ] Performing direct lookup of upgrade codes for: Azure Active Directory Connect
[04:24:32.160] [  1] [VERB ] Getting list of installed packages by upgrade code
[04:24:32.160] [  1] [INFO ] GetInstalledPackagesByUpgradeCode {d61eb959-f2d1-4170-be64-4dc367f451ea}: verified product code {dd19288c-0faa-4336-a52c-e1d1f1395a64}.
[04:24:32.160] [  1] [VERB ] Package=Microsoft Azure AD Connect, Version=1.0.8667.0, ProductCode=dd19288c-0faa-4336-a52c-e1d1f1395a64, UpgradeCode=d61eb959-f2d1-4170-be64-4dc367f451ea
[04:24:32.160] [  1] [INFO ] Determining installation action for Azure Active Directory Connect (d61eb959-f2d1-4170-be64-4dc367f451ea)
[04:24:32.160] [  1] [INFO ] Product Azure Active Directory Connect (version 1.0.8667.0) is installed.
[04:24:32.160] [  1] [INFO ] DetectInstalledComponents stage: Sync engine is already installed and meets version requirement.
[04:24:32.160] [  1] [INFO ] DetectInstalledComponents: Marking Sync Engine as successfully installed.
[04:27:16.610] [  1] [ERROR] Caught an exception while creating the initial page set on the root page.
Exception Data (Raw): System.Management.ManagementException: Generic failure 
   at System.Management.ManagementException.ThrowWithExtendedInfo(ManagementStatus errorCode)
   at System.Management.ManagementObjectCollection.ManagementObjectEnumerator.MoveNext()
   at System.Linq.Enumerable.<CastIterator>d__b1`1.MoveNext()
   at Microsoft.Azure.ActiveDirectory.Synchronization.SyncServiceProvider.SyncServiceProvider.IsRunInProgress(String& connectorName)
   at Microsoft.Online.Deployment.OneADWizard.Runtime.Stages.DetectInstalledComponents.ValidateConfigChangesArePermitted()
   at Microsoft.Online.Deployment.OneADWizard.Runtime.Stages.DetectInstalledComponents.Execute(String& message)
   at Microsoft.Online.Deployment.OneADWizard.UI.WizardPages.RootPageViewModel.GetInitialPagesCore()
   at Microsoft.Online.Deployment.OneADWizard.UI.WizardPages.RootPageViewModel.GetInitialPages()
[04:50:48.996] [  1] [INFO ] Opened log file at path C:\Users\Setup Account\AppData\Local\AADConnect\trace-20151123-042425.log

 


Anupam soni

Howto connect Azure AD with sharepoint online

$
0
0

Hi all,

I have successfully set up a small azure box and set up VPN to my on premise AD. Then I installed AD connect to this virtual box and successfully synced users.

Then, I successfully registered for a test version of SharePoint online.

But I cannot get these two work together. The domains from AD connect and Office 365 are different, and I do not know how to sync these.

From my point of view, it doesn't make much sense to now again add the Azure domain to the Office 365 domains, and even if I would this does not work, because I cannot make the TXT record in the Azure AD.

So, I think I missed something. I assume I would have to somehow generate the sharepoint / office 365 out of Azure portal, so that these two are automatically tight together, but I did not find a way.

So, anyone with a guide out there on what to do in which order?

Tanks, Sebastian

P.S. I had to install the AD connect on an Azure box, because in the final state I will have to sync multiple Domains to this Azure AD, so the only way to have access to all these on premise domains is VPN tunnels from a cloud box.

Tutorial: Azure AD Integration with Citrix ShareFile

current revision is not working

Need of Reply URL/ Redirect URL , Sign On URL , APP ID URL while creating Application in Active Directory

$
0
0

Hi,

I need some clarity of Reply URL or Redirect URI. As per MSDN document, My understanding is, After azure AD authenticate user, AD sends back response along with token if success. But when we create Application which is of type WEB APplication and or WEB API, documentation or every one says we can give dummy url for sign-in url or App ID URL which is dummy or really exists, If that is the case, after authenticating, Azure AD will send response to above mentioned dummy URL which doesnot exists, how does client either native or webapi gets the token

Update-MSOLFederatedDomain doesn't work

$
0
0

Hi,

I'm trying to set up a federated domain with a third party IDP. I synchronised the local AD with Azure AD, but I'm getting an 80041317 error on login. While following the instructions on how to fix that I have to run Update-MSOLFederatedDomain, which fails. This is how I run the command:

PS C:\Users\Administrator>Update-MSOLFederatedDomain -Domain ggdevelop.com

Update-MSOLFederatedDomain : 'ggdevelop.com' is not a valid domain name.

At line:1 char:1

+ Update-MSOLFederatedDomain -Domain ggdevelop.com

+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

+ CategoryInfo       : NotSpecified: (:) [Update-MsolFederatedDomain], FederationException

+ FullyQualifiedErrorId: InvalidDomainName,Microsoft.Online.Identity.Federation.Powershell.UpdateFederatedDomainCommand


The domain is definitely a valid domain name, since I can see it by running Get-MSOLDomain:

PS C:\Users\Administrator>Get-MSOLDomain

Name                                                                                 Status       Authentication

----                                                                                 ------       --------------

ggdevelop.com                                                                        Verified     Federated


I can provide additional information if required. I would appreciate any suggestion on how to fix this, since I'm not sure where to go from here.


Importing users from contract company tenant

$
0
0

Hello, 

I was wondering if anyone could point me in the direction of finding out how to do a couple things. 

It was presented to us that Azure could import users from another Azure Directory Tenant, 

Then we could put that user as an on-prem but Azure managed user. So if they get deleted from the contractors Azure we could replicate the delete or disable down to our on-prem. 

Does anyone know where I can find docs how to

A. trust a different companies Azure tenant

B. Import users from one Azure director to another

C. provision users down from Azure. 

Thanks

Russ


Russell Lema

Office 365 account hacked (referred here from Office 365 forums)

$
0
0

Okay, so quick rundown of the situation:

Wednesday night I log into my school email (through Office 365/outlook), and notice I have an email sent from myself to myself with personal threats. I then check my sent email folder and see they messaged two of my instructors (I have since cleared this up with them).

I'd like to mention that I was not phished nor keylogged, and yes I know that for a fact. The person (and I know who did it) had no idea of any information besides my email address for my school email. Yet, they were able to break in and attempt to mess things up for me.

Why was my Office 365 account hacked so easily? I have since changed my password. My old password was only nine numbers. Is bruteforcing an Office 365 account that simple? 

---

I was referred here from the Office 365 forums:

"As for your question about the reason of your account being hacked, I would suggest that you post the question to Azure Active Directory forum for expert help since this topic is not supported in our forum."

Connect device to admin account in Azure AD?

$
0
0

Hello,

I'm test driving Azure AD. I've created the default directory and added a domain, which I set as primary. Then I've created an AD user and on a Windows 10 device, when I booted it up for the first time, successfully connected that user.

Now I'm on the second Windows 10 device, which is my own, and I wanted to do the same thing. Unfortunately it says that it doesn't recognize my user ID.

I can connect any AD users that I create for my domain, but no luck with my admin account, which is sourced from a Microsoft account.

Any idea what's wrong?

Could not verify this domain because it was previously configured for your tenant or for another tenant.

$
0
0

Hi all,

I'm one of three admins for our domain, and we are getting the "Could not verify this domain because it was previously configured for your tenant or for another tenant" error when trying to add a custom domain to our Azure subscription for DirSync.

Is there a method to find out where exactly?

It's certainly not registered in Azure, so maybe an office 365 account?


Neil Rawlinson

Problem to assign contributor role by API to CSP Azure customer tenant admin

$
0
0

We are trying to create an automation tool to provide CSP Azure service to the customers. We are able to create customer account and provide Azure subscription to the customers by using CSP crest API. But customer will not be able to use CSP Azure service until contributor role for the provisioned subscription is assigned to that customer tenant admin. We  are using Role assignment but the API is failing with following error message which indicated authentication problem. How to automate contributor role assignment?

"{"error":{"code":"AuthenticationFailed", "message":"The access token is from the wrong issuer 'https://sts.windows.net/4373c423-e185-4710-9230-b75cb44d9783/'.  It must match the tenant 'https://sts.windows.net/62bcc712-d922-44f3-8c28-a4bfbe15dd65/' associated with this subscription.  Please use the authority (URL) 'https://login.windows.net/62bcc712-d922-44f3-8c28-a4bfbe15dd65' to get the token.  Note, if the subscription is transferred to another tenant there is no impact to the services,  but information about new tenant could take time to propagate (up to an hour).  If you just transferred your subscription and see this error message, please try back later."}}"

We have a azure account where we have created a project in 'manage.windowsazure.com. I have followed the steps on that project which are mentioned in "Set up authentication using the Management Portal" from link 'https://msdn.microsoft.com/en-us/library/azure/dn790557.aspx' . Partner account does not have direct access to login on that portal.

Now we have created the token by authenticating that project (passed client Id & client Secret of that project) with partner’s account credentials programmatically and called that role assignment API and got that error.

Can you please tell me what we are missing? 

Thanks

Arunava

Viewing all 16000 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>