Quantcast
Channel: Azure Active Directory forum
Viewing all 16000 articles
Browse latest View live

Certificate authority

$
0
0

We have Internal Windows 2012 R2 CA. Since we are planning to move our infrastructure to Azure cloud we would like to architect certificate authentication for infrastructure access. As a newbie in azure I would like to know the best way to achieve this. What and how I can implement within Azure to accommodate this scenario. Parallel implementation, migration and decommission legacy On-Prem infrastructure. 

Thanks for any guidance. 


Azure role assignment Alerts

$
0
0

how to configure the alert when someone changes any roles in azure for the user.

For example if currently my user is Global Admin now somebody changed him to som other admin

So how we can configure that alert whenever there is a change in any role

AADSTS50020 Error installing Office 365 on Android

$
0
0

I am using the default application that comes with my Samsung SM-G930V, Android v8.0.0 running the latest patch.  I am attempting to use the default mail app that comes with the phone and to ensure security have enabled the use of Microsoft Authenticator.  I am able to input my email address, get prompted and successfully authenticate and approve my credentials.  I immediately then receive the following:

AADSTS50020: User account 'xxx@outlook.com' from identity provider 'live.com' does not exist in tenant 'Test" and cannot access the application xxx-xxx-xxxx-(email) in that tenant.  the account needs to be added as an external user in the tenant first.  Sign out and sign in again with a different azure active directory user account.

This is my account and I am successful logging in on all other devices cept the phone.  So how do I enable this to work.  I would like to be able to access my emails without having to sign into a web version if possible.

Mark

This passwordreset . microsoftonline . com page can’t be found

$
0
0
I integrated Identity Server 4 with Azure Active Directory. It works fine. However, when I follow the below flow, I get not found page for password recovery.

Goto Identity Server
Click to Login with Azure AD button => Redirects to login page of microsoft
Enter user name => Redirects to enter password page
In the Enter password page click on Forgot my password button. I get not found error
The url of the page is : https://passwordreset.microsoftonline.com/? ru=https%3a%2f%2flogin.microsoftonline.com%2f3b6647ee-a17a-45ff-ac15-6c9fb73006f2%2freprocess%3fctx%3drQIIAc1WO6skCRWeO3dmdmZwcV1WMRxxAnGpe-v9GBCtV1fX-9ndVZ0U9e56V1dV33pEIgZGKkaL4YYbGumCIAgGi-AmGhgaiSA-QNDMHn-FyYHDOZzgfOc73_fyHewOuQPvwG_ewnfgm9cEgSRECpJAjIckgJJBDJAkAQJJHCNolCAYAqL9-y_f-yhfjX989K_td6dfwb_-218__uTm-zenceyGN_f3eZw0Yz4ud2MyjHdpnw9DVLWX-C5q6_soqKowiMr7No-j-yHPGiBv7gksiJIAJQAKjmEATYkUIKkkAlA8jJMEpCIQRO6JNMAgHAwBlAIRAI3DBAhwBAcwlCITJIkJisB-fnPz-c3Nn29uPnk8XGsUAeI4gUMojIM4Qtyp6ynXit2kCeKoOzSq2SCoOeWsONmiFtHo1SriwfvaW3eQV1iFWmTQUZDe5uPR4VFvufYLKqIcxFk9mKN-8JDjwVs9J8OO9f70x8df1OnLeILfhrbP1-Sfj1-kbV_7XTuMP739zbtsykmk5homji2Q1Rm9BhYDwOLKRvGRLRHr8qkg2BTHTxugFutkVgU_sYPjegwRZntBwXqzWaKz4Ue5aIiopcyZp_LgMcAPoL0LBpZww3yDNEZhBW6XFzSZSUMg2DQo7oqCAxBxYA6m5I8jRzUWzkdmtIKee94Mvcd6xfKAmxkpRaLEnb2g9UFlG2esoAVumm1DhDU3UuZQ29JeY58bYTpcH7KepI2jxFiNOIq8dRDrrqZzE1GWiwjDG5KJOYXZZVDDe-HYyxRvMg3ollgjcKRMgDYoRZ0Hhsv-UFgg7Eb65B19iICs2SLji1-7YvngGwhshj7ZuwLSZ_waV469s9OwKmO0r4VS76wAqBpibh6ACA_buAkkQKTZdIcw1MlwBUAbQIeK7U088TPJtTM9gEB5gVJT4gHQ8s5Bb847mlcrPbtMFBRHILYI2XiMa3MZrH6hNhFVcREgKyTFkfQEC06b77BVd1S8d12Gb5Q-oDbGjDpSWiDGjq1Qpcl6uK63ETjOLglNxxNiF_uds4XNzsRnvhu3ptUexx25iizWJ3oQrWjLFD52OsahaPgw1Z57qKelTKaOY5bzHnWFih7KPUau0wTga6mfWpY68IQdOodyi29bYwsn-AKpw7Hf6E7cK1yUd7rGg7VU42v-UBvnOdrTrit5udfj4cpkCU87qegHiUZb3agcEKCng1TInaQ0Z2bHUFFv2zW1gCUtlHS3hBay06FOpYx0cueLjen-WcP5ilcIy6HBqYBIAwLoWqRblz5qkH-ASbl2jhxH06NX1ACeHLt9OvN-eLbIdEXssEKrBM0qxzTjkzbqBs9jmt660gPdyHw4eePM7wZsjxPMSQPIgmzVfhl4NhLdOQ-55bg4O99JRpcN4_lBbbfsmtnr8QITfq6oMIwfUlIUIDyEQGITXWGY5F0H8xXKO0u-XRPa3Kyan-vuyd2yaXj2FpTZt3GxhXfgXkP1-NBSzKQeXEGt_CHpLWI7aKrIw_3JKMJJpmRb9tHe1g1GafRQXhFqH2aZINfXX6emG9NKs1yzhESs5K518iV2WvUs2pgJHLROVxfd7N3xjGwkvWbUtJDlTA0aKskNf9c26ogOII7hcjVVJqjShEOBrNcBmW5KCc5sJIjVCrwJH-IOKzzYOZlV5FwnNRrYlMhhgjZNmZ9ArNe6UTtdicOcXOTKo9WUvUGhmeZ4PrZx9oBXFj_UApAHfn8R5_K0IPKoXBdLEz68sLrQBrwIdB5pYQgUk_gOjAvb83eU7SM1PVGHlKsx85KIFw8Z-K1sNJCL2Q5T2V0TQDNxTsx5O6vBIiBtsj9VVyKNsC5YkF9rYs0xXNFARQCtAtuavIGQ3tRvlPB6K7hotj1TsLYvevRwmfiN0sHyYVubBFrbajrranlmkoC6uHCn6pcW3T3g6irV_WmfiLzbEBORCKIIxWIeS02TUxbihgjcnPOgw8IJZ-CAUyCago6XJLjI5DkpqObij1eiDiUYQtpuTgMpvW6sGcA-XnhOGtiDe0HojYUmB50fES1rYXPrnGFOshfHKphi4GHkWHYuc5xjxS_WYplRcz4btacqg0-CaXqpzvyxQyRnkHCVf9ikHlz4B06vyq1a7hyTHrXE0MhZLRVmjfNWHdmuE8jRCAwrKSVl08NI71XKIodCH8rDWqo8RmBGUJ3ktNH2YurgXC-EV8APB3TbE33bo_SGlMfErb1sp8d7gJiGAyDRXdlHG46NBqtsOYVKcTS49lnbahkBMLdgQgzRh_N0CILzFpl-dvsaCXEcJZKrBkNEAKBYmgJBBGEAHlFpSCAgiKfwp7evozjCghCLARyDcQBFA_gq2igJYAiSwvBV5xCE-uz2g7ZLmjx-1fVtmlfJq6QO8upPt1-egipu78qqbfvv_M9IvPUQnz-5-cuTrzx_-t7tVx-9evSND8DbN8-fv3zv0dvs309uPn569SdfZ3_L_vDbj9Sf_PIXv3M__Nqjz57eV3jJVChjfihLyYcXVpBZrqYFWozsUVpbaaptQtyT5F4to29hb6AfP3v22bMviZyv8Y7t0BpHWxzsg39_9vQH7zz-9MX_h9353hfeff7o_Rcvfs-PP-r_84ftfwE1&mkt=en-US&hosted=0&device_platform=Windows+10&username=myemail@secret.com

How to connect Azure LDAPS

$
0
0

Hello,

I have setup the Azure LDAPs site and azure firewal as well.

The question now is it is not clear for me that how to connect and search the result.   Such as what bind, base search, password (DN, CN structure etc)?

Thanks in advance. 

AAD Connect vs FFL and DFL

$
0
0

Dear team,

I would like to know if i setup AAD Connect with 2008R2 today and after few months upgrade my domain controllers to 2016 and thus update forest functional level and domain functional level to 2016.

Does that impact my AAD Connect synchronization? IF yes, what would be effected?

#AADConnect #AzureAD #Domainfunctionallevel #forestfunctionallevel #AD #Active #DirectoryWRG

az ad sp create-for-rbac failed with error "ImportError: cannot import name AppRol"

$
0
0

i get for all az ad sp create-for-rbac comands , even for 

az ad sp create-for-rbac --help


this error 

ImportError: cannot import name AppRole

full trackback i get : 

The command failed with an unexpected error. Here is the traceback:

cannot import name AppRole
Traceback (most recent call last):
  File "/usr/local/lib/python2.7/dist-packages/knack/cli.py", line 206, in invoke
    cmd_result = self.invocation.execute(args)
  File "/usr/local/lib/python2.7/dist-packages/azure/cli/core/commands/__init__.py", line 496, in execute
    self.commands_loader.load_arguments(command)
  File "/usr/local/lib/python2.7/dist-packages/azure/cli/core/__init__.py", line 276, in load_arguments
    self.command_table[command].load_arguments()  # this loads the arguments via reflection
  File "/usr/local/lib/python2.7/dist-packages/azure/cli/core/commands/__init__.py", line 290, in load_arguments
    super(AzCliCommand, self).load_arguments()
  File "/usr/local/lib/python2.7/dist-packages/knack/commands.py", line 97, in load_arguments
    cmd_args = self.arguments_loader()
  File "/usr/local/lib/python2.7/dist-packages/azure/cli/core/__init__.py", line 473, in default_arguments_loader
    op = handler or self.get_op_handler(operation, operation_group=kwargs.get('operation_group'))
  File "/usr/local/lib/python2.7/dist-packages/azure/cli/core/__init__.py", line 513, in get_op_handler
    op = import_module(mod_to_import)
  File "/usr/lib/python2.7/importlib/__init__.py", line 37, in import_module
    __import__(name)
  File "/usr/local/lib/python2.7/dist-packages/azure/cli/command_modules/role/custom.py", line 29, in <module>
    from azure.graphrbac.models import (ApplicationCreateParameters, ApplicationUpdateParameters, AppRole,
ImportError: cannot import name AppRole

i am using ubuntu 16.04 virtual machine , this is the version (instaled via apt):

 az --version
azure-cli                         2.0.68

command-modules-nspkg               2.0.3
core                              2.0.68
nspkg                              3.0.4
telemetry                          1.0.3

Python location '/usr/bin/python'
Extensions directory '/home/ubuntu/.azure/cliextensions'

Python (Linux) 2.7.16 (default, Mar 26 2019, 10:00:46)
[GCC 5.4.0 20160609]

Legal docs and information: aka.ms/AzureCliLegal


Your CLI is up-to-date.

msExchHideFromAddressLists attribute isnt syncing across to Azure

$
0
0

We were using dirsync before and upgraded to AD Azure Sync.  Before the upgrade, the attribute "MsExchHideFromAddressLists" was syncing across.  After the upgrade, it is no longer syncing.  What I'm curious of - do I need to check the box for Hybrid Exchange in the Directory Sync Config tool for that attribute to sync? We aren't using exchange on premise anymore, but haven't retired it yet until mid march to make sure everyone was successfully migrated to O365.

Any help would be greatly appreciated! Microsoft support has been scratching their head at the first level for the last 4 days..

Thanks!


Unable to disconnect Azure DevOps from Azure Active Directory

$
0
0

We've moved all resources from one Azure account to another, including our Azure DevOps resource. I'm trying to disconnect our Azure DevOps organization from the old Azure Active Directory so that I can re-connect it to the new Azure Active Directory. I am following the instructions at https://docs.microsoft.com/en-us/azure/devops/organizations/accounts/change-azure-ad-connection?view=azure-devops

I have changed the owner of the organization to a personal Microsoft account and added it to the Project Collection Administrator group. I have Global Admin in Azure AD. When I attempt to disconnect the directory inside of Azure DevOps, I get the following error:

Disconnect Failed

Your organization <ORGANIZATION CENSORED> failed to disconnect from the Default Directory Azure Active Directory.

System.Data.SqlClient.SqlError: %error="400101";%:a0lxyx27co.Sps_spsprodch1su1_3beb3fe6-ef89-47f5-b9a7-6e80c5d6f82f..prc_UpdateIdentityIdTranslations: new translations have a record that may corrupt the existing translation data

What further can I do to get this switched over?


Join Windows Server 2016 VM to Azure AD

$
0
0

Hi Everyone,

I have a Windows Server VM and Azure AD under same resource group. I can't join the Server to the AD because it can't find the AD.

My server IP address is: 10.0.0.4 and Azure AD IP address is: 10.1.0.4 so this is most likely cause but I haven't been able to fix this issue.

Any help will be appreciated.

Regards

Ruhi 

How can on-premise workstations/users join to domain of ADDS in Windows Server in a VM in Azure?

$
0
0

Hi,

How can on-premise workstations/users join to domain of ADDS in Windows Server in a VM in Azure?

Is it possible? Does it require on-premise ADDS to connect to ADDS in Windows Server VM in Azure?

PS: Not referring to Azure AD Connect.

Thanks!!


No tenant found in the context

$
0
0
Firstly I login to the azure with the cmd "Connect-AzAccount" through the powershell console  installed on my local machine. But when I use the command "New-AzResourceGroup", it returned error "No tenant found in the context.  Please ensure that the credentials you provided are authorized to access an Azure subscription, then run Connect-AzAccount to login." How should I solve this problem ?

What happened to the urn:ietf:wg:oauth:2.0:oob Redirect URI in the Azure portal?

$
0
0
This Redirect URI is needed for an app to access the Microsoft Graph Security API with PowerShell.

Aleksandar Nikolić http://powershellers.blogspot.com http://twitter.com/alexandair

Azure Active Directory integration with JIRA \ Confluence SAML SSO by Microsoft

$
0
0

Hi All, 

I would like to ask if adding azure SSO authentication in Jira \ Confluence works when having other other 2 AD User Directories for Authentication.  At he moment we have 2 AD User Directories from two separate trusted AD domains which is working fine. However, I would like to ask if we can add another authentication method from a separate azure AD using the SAML SSO azure Ad-on. As per MS tutorial for this plugin, azure AD and Jira has a common domain, which in our case is a different domain too. 

Thanks all for your help. 

Azure AD Connect Setup

$
0
0

Hi Team,

When I am modifying Azure AD connect configuration under customize synchronization options -->  directory extension attribute Sync.it is getting below error.

I am using Global admin account and Domain admin account also I have added my domain admin account under"ADsynadmin,ADSyncoprtation" group.

Please help me it is too urgent.



Thanks & Regards,


Thanks Devendra B2-Consulate(Capgemini)


Audience validation failed.

$
0
0

Something wrong with my token???

Failed to validate access token with following errors.

{
    "code": 401,
    "message": "IDX10214: Audience validation failed. Audiences: '[PII is hidden]'. Did not match: validationParameters.ValidAudience: '[PII is hidden]' or validationParameters.ValidAudiences: '[PII is hidden]'."
}

Azure AD Password Reset Fails - ADAdminActionRequired ( Writeback & Pass Through AuthN Mode )

$
0
0

When i try to reset password for on-prem account from azure ad, it fails with reason stating -ADAdminActionRequired

This is happening inconsistently for few accounts. Any solution would be appreciated.

Thanks in Advance

Azure role assignment Alerts

$
0
0

how to configure the alert when someone changes any roles in azure for the user.

For example if currently my user is Global Admin now somebody changed him to som other admin

So how we can configure that alert whenever there is a change in any role

Get-AzRoleAssignment : Exception of type 'Microsoft.Rest.Azure.CloudException' was thrown.

$
0
0

I am trying to use the cmdlet Get-AzRoleAssignment using a service principal as advised. But I am receiving an error when doing this: Exception of type 'Microsoft.Rest.Azure.CloudException' was thrown. 

I tried to add API Graph permission but that did not help, maybe I am missing something but I can't find the requirments for this cmdlet.

I already added:
Besides the API permissions the account is owner and is able to perform other cmdlets without error.

Version:

CommandType     Name                                               Version    Source
-----------     ----                                               -------    ------
Cmdlet          Get-AzRoleAssignment                               1.3.0      Az.Resources

Bart Scheltinga | www.bartsp34ks.nl | MCSA


Location based Azure Conditional Access policy doesn't work properly

$
0
0
I have some problems in configuring Azure Conditional Access.

I would like to restrict logon capabilities to one location (one external IP) - this is the case when users can only logon to their O365 accounts while being inside their office. And it works, but only partially.

1. Browser session. Let's say that the user bas logged in in the office and went home - to be precise: changed his external IP on which the policy is based. The user should not be now allowed to use O365 account, any of the functionality. And after some testing performed in my office this doesn't work properly. I can still access some of the applications after switching to another external IP. Some of them are blocked after a few seconds, some after a few minutes and some never (Outlook, Calendar) - while every app is included in CA policy.

I have a feeling that it depends on the auth tokens used in O365. Is there any possibility to force checking external IP every time a user does something on his account? How to configure CA in a way that prevents situations I described above? I tried session policy settings in CA but their does not seem to work.

If it helps, test users are assigned Azure AD Premium P2 licences.

Do you have any ideas?
Viewing all 16000 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>