Quantcast
Channel: Azure Active Directory forum
Viewing all 16000 articles
Browse latest View live

how to integrate azure advanced App Service Authentication / Authorization to access azure devops API (tasks, pipelines)

$
0
0

 we are trying to make a webpage where user can see all his assigned tasks, pipelines using devops api. The question 

as we know azure supports the advanced app service authentication / authorization (EasyAuth) were tokens generally stored and managed from azure once user authenticates the request with azure AAD. so, how can we integrate this to have access the devops api.

Thanks.


AADSTS65001 error trying to access mt Web API from Angular client

$
0
0

Hi

I have and angular project talking to .Net Core 3.0 Web API, authentication Azure AD.  Apps setup for both, have followed instructions to expose API and then Grant Permissions.  Client app logs in successfully but get this error at the point it trys to call my web api.

Anyone got any ideas?

Regards

Mike

Azure (SAML SSO)

$
0
0

Hi All,

I've added a few apps using Azure as our identity provider and it went fine, this one app I recently added however was working and then all of a sudden I would receive this error upon browsing to the SSO url.  Has anyone come across this before?  I tried using fiddler but I can't make heads or tails of the error message.

Unknown or Unusable Identity Provider

The identity provider supplying your login credentials is not authorized for use with this service or does not support the necessary capabilities.

To report this problem, please contact the site administrator at root@localhost.

Please include the following error message in any email:

Identity provider lookup failed at (https://www.fakeurl.com/Shibboleth.sso/Login)

Thanks,

Conditional access not prompting users for MFA

$
0
0
Hi,

Hoping someone has seen this and can point me in the right direction.

We have a couple of conditional access policies set up in AAD, one that blocks users that arent on a trusted site and another that allows users access from untrusted locations if MFA is applied. Users are assigned one policy or the other not both. The block policy works fine, but the MFA policy allows the user to connect regardles of location.

The What IF tool shows the users getting the policy correctly based on IP:

Windows10_Allow_Untrusted_MFA
Require multi-factor authentication

And according to the sign in log MFA was required and done, the result says:
  • USER
     
    Kathryn Janeway
  • USERNAME
     
    kat.janeway@blahblahblah.com
  • APPLICATION ID
     
    00000006-0000-0ff1-ce00-000000000000
  • APPLICATION
    Microsoft Office 365 Portal
  • CLIENT
     
    ;Windows 10;Edge 16.1629;
  • LOCATION
     
    Somewhere
  • IP ADDRESS
     
    ::Untrusted IP::
  • DATE
     
    5/17/2018, 8:44:37 AM
  • MFA REQUIRED
     
    Yes
  • MFA AUTH METHOD
     
  • MFA AUTH DETAIL
     
  • MFA RESULT
    MFA requirement satisfied by claim in the token
  • SIGN-IN STATUS
     
    Success

I'm obviously missing something but we need the users to be prompted for MFA every time they sign in when not on once of our sites.

Azure SSO Claims Attribute Transformation

$
0
0
I am looking at configuring SSO for a Gallery App, and have hit a upon an issue with the unique identifier.  The preferred unique identifier for the application is email address, but it doesn't accept certain special characters, one of which is apostrophe.  This causes a problem as we have a number of users that utilise this character within their email address.  Is there a way of transforming user.mail Daniel.O'Donnell@Ireland.net to Daniel.ODonnell@Ireland.net (removing the ')?

Roles Missing from Token

$
0
0

I have setup an app and provided delegate permissions for Mail.Read.Shared and Mail.ReadWrite.Shared.  The token I get back from baseUrl/{tokened}/oauth2/v2.0/tokendoes not contain any roles.  Can you tell me what is causing this?

Thanks,

Samuel

Updating user properties in Azure AD B2C from native app

$
0
0

Is there a way to update the custom properties of B2C users from a native application? From what I can find, we should be using the Azure Graph API, but it appears to require a 'normal' AD application registration and using a client secret. We would like to be able to update (custom) user properties from our native application, using a token belonging to the user, not a client secret belonging to the application.

Lost ownership of the Global Admin priveleges of the Azure account

$
0
0

Hello, we have an Azure account which has been created a long time ago by previous IT company, which provided services to our organization. We retained the login information of one account, but it does not seem to have all the permissions needed to fully manage all options in Azure portal. Using powershell we did find 2 accounts listed under "Company Administrator" with email addresses ending with .onmicrosoft.com, however, we are unable to login as any of these accounts. Is there a way to add Global admin privileges for the account we currently use to login to Azure, provided, we can prove the ownership of this account.

Thank you.


enterprise state raoming not working.

$
0
0

I can't seem to get ESR to work.

Setting in azure active directory is enabled for selected.

Able to make te Sync settings in windows 10 Pro

but get errors in eventlog/AAD we have MFA enabled. 

Could it have something to do with MFA.

Any advice where to look or what to do i am lost.

Regards Marcel

Error: 0x80070005 Access is denied.

The target URI is not allowed for token binding public key export
Exception of type 'class WinRTException' at oauthtokenrequestbase.cpp, line: 767, method: OAuthTokenRequestBase::QueryTokenBindingKeyId::<lambda_96afc217c121125f18a3495072ac63ea>::operator ().

Log: 0x8aa5007f Unable to create a Token Binding Key.
Logged at oauthtokenrequestbase.cpp, line: 767, method: OAuthTokenRequestBase::QueryTokenBindingKeyId::<lambda_96afc217c121125f18a3495072ac63ea>::operator ().

Request: authority: https://login.microsoftonline.com/common, client: 22098786-6e16-43cc-a27d-191a01a1e3b5, redirect URI: ms-appx-web://Microsoft.AAD.BrokerPlugin/S-1-15-2-2537927067-2140208811-1083047336-3825492100-1188134376-3459723148-3131426163, resource: https://outlook.office.com, correlation ID (request): 3e6678dd-73e2-4980-a321-b7f9263ca66c

Add AAD DS Wants Me to Setup New Subscription

$
0
0
I inherited an Azure account at work. There is no on-prem server. They originally setup an Admin account that is like “Geotech_admin@geotech.onmicrosoft.com”. I am one of these users listed as a “member”. I am able to log on using my credentials and create VMs. I have Azure Active Directory running with a number of users in it. However, when I try to setup Azure AD Domain Services for multiple logins, I am told “You cannot create a managed domain for this directory because you are not the administrator of this directory.” When logon as the main Admin account and try to create Azure AD Domain Services it wants to force me to create a Free Azure account with a new subscription. How do I work around this to setup Azure AD Domain Services on our Azure Account.

Walter

How to apply corporate Wallpaper, Screensaver and lock Screen in client computers through Intune

$
0
0

Hi,

I want to apply corporate Wallpaper, Screensaver and lock screen in client computers through Intune. Clients are using Windows 10 professional operating system and currently no configuration available for change wallpaper in Intune for Win10-Pro.


That's why I have applied through Powershell script option. below simple commands are run through script file.


For Wallpaper:

Set-ExecutionPolicy Bypass -scope Process -Force
set-itemproperty -path "HKCU:Control Panel\Desktop" -name Wallpaper -Value “c:\Windows\Web\Wallpaper\Windows\wallship.jpg”
rundll32.exe user32.dll, UpdatePerUserSystemParameters, 0, $true


For ScreenSaver:

Set-ExecutionPolicy Bypass -scope Process -Force

New-ItemProperty -Path "HKCU:\Control Panel\Desktop" -Name ScreenSaveActive -Value 1 -PropertyType String
New-ItemProperty -Path "HKCU:\Control Panel\Desktop" -Name ScreenSaverIsSecure -Value 0 -PropertyType String
New-ItemProperty -Path "HKCU:\Control Panel\Desktop" -Name ScreenSaveTimeOut -Value 60 -PropertyType String
New-ItemProperty -Path "HKCU:\Control Panel\Desktop" -Name SCRNSAVE.EXE -Value “c:\windows\Web\Wallpaper\Ethics.scr” -PropertyType String


After run this scripts through intune status is showing successful but not changed anything in Client laptop. Also pls help how to change Lockscreen.


is these correct scripts to change wallpaper, screensaver ? 


Please help

Thanks in advance







Conditional Access Policy and O365 Exchange Online Problem

$
0
0

Hi All,

We have been breaking or brain with the following problem creating Conditional Access Policies to do the following:

  1. Our mail is currently hosted on Office 365
  2. We have Hybrid joined all our internal systems to Azure AD
  3. The problem is with our BYOD Mobile clients:
    1. We currently use VMWare Airwatch and Boxer to allow controlled access to email through this partitioned workspace
    2. While our goal is to strictly allow email to only be accessed to AAD joined inhouse systems and Airwatch Boxer clients, users are still able to use the iOS native client and Outlook mobile client to access email
    3. Everything we have done to remove access to the Outlook mobile and iOS clients results in loss of connectivity through the Boxer app as well.
While I know the ultimate solution would be to force Intuneenrollments and use a controlled deployment of the Outlook client and config with that, this is not an option for the next year (company just signed a 1 year contract). Any help greatly appreciated!


Thanks! Dan

Does AIP included in Azure AD Premium 1?

$
0
0

Hi,

Does Azure information protection included in Azure AD Premium 1?

Regards,

Kavindu.


Is there any way possible to create or delete Users in in bulk using GRAPH API in Azure AD B2C

$
0
0

I am trying to make a console app in C# through which I want to migrate more than 100000 users to Azure AD B2C.

We are using Graph API for this purpose.

My current approach creates a single user account per API call and it takes more than 12 hours to migrate around 50000 users.

To reduce the overall time I want to send data in bulk instead of one by one using the API. But, I am unable to find any solution for it.

Is there an API endpoint available for creating users in batch. Please help.

Also, If I want to delete these users in batch. Is it possible to do that?

Azure AD IdP initiated SSO

$
0
0

I want to use Azure AD for signing in to the Opsgenie application. As far as I found, there are two ways of configuring Opsgenie application on the Azure AD. One of them is from the Application Gallery and the other one is from the application registration menu. I have tried both of them but couldn't successfully sign in to the Opsgenie application from the Access Panel. I am able to successfully log in to the application from the Opsgenie side, so the configuration seems to be correct.

However, when I try to access to the application from Azure, I am not able sign in to the application. Opsgenie shows an error message like "No SAML response was provided". Then I checked the HTTP request sent from Azure to Opsgenie, and I couldn't see any SAML data in the request. I wonder why I am not able to use IdP initiated SSO with Opsgenie and Azure.

I have a few questions about this issue.

- In the Opsgenie configuration tutorial from Azure AD, it is written that Opsgenie supports SP initiated SSO. However, I have seen other apps whose Azure configuration docs say "Both SP and IdP initiated SSO is supported". May I ask why Azure does not support IdP initiated SSO for Opsgenie? I ask this here because it is only written in Azure docs. There is no such information about this on the Opsgenie documentations.
https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/opsgenie-tutorial

- This document says that I need a "Subscription or Azure AD Premium" to use SAML SSO. Does this mean I need an Azure AD premium account to use IdP initiated SSO. Might this be the reason why I am not able to sign in from Access Panel?
https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/configure-single-sign-on-non-gallery-applications

- I saw that legacy app registration menu support will end this month and new one does not support URLs that include query parameters. Thus I have configured my application by using the legacy app registration menu. My question is, will an application continue to work after the legacy support ends, if it is configured with a URL including query parameters. This question is related to already configured applications. I know that new applications will not be configured using URLs with query params.

Thanks!


Cannot elevate my Azure AD domain account ot administrator in Autopilot provisioned computers

$
0
0

When I first tested out Windows Autopilot + Microsoft InTune following the steps in
https://docs.microsoft.com/en-us/windows/deployment/windows-autopilot/demonstrate-deployment-on-vm

I was able to successfully join a Windows 10 Enterprise VM operating in my home computer (Hyper-V), but the deployment profile initially defined new users as standard. I was thus unable to perform any admin-level activities (e.g. System properties config sections)

On a second Windows 10 Vm operating within our company Hyper-V server, the deployment profile was adjusted to let new user be administrator type. My colleague tested the Autopilot process on that VM. Subsequently, I signed into that VM as well, but noted that I being the second user was considered a standard user as well.

My colleague (global administrator for Azure AD) adjusted the domain devices settings, enabling the [Additional local administrators on Azure AD joined devices] policy and declared my user account as part of that group.

It's been nearly 24 hours and the policy does not appear to have flowed through to the computers despite multiple sync attempts. When signed in as my account, I still get challenged for administrator credentials. Are there still additional configuration steps we missed? Or does this particular policy take an awfully long time to sync and take effect?


The melody of logic will always play out the truth. ~ Narumi Ayumu, Spiral

Cannot elevate my Azure AD domain account to administrator in Autopilot provisioned computers

$
0
0

When I first tested out Windows Autopilot + Microsoft InTune following the steps in
https://docs.microsoft.com/en-us/windows/deployment/windows-autopilot/demonstrate-deployment-on-vm

I was able to successfully join a Windows 10 Enterprise VM operating in my home computer (Hyper-V), but the deployment profile initially defined new users as standard. I was thus unable to perform any admin-level activities (e.g. System properties config sections)

On a second Windows 10 Vm operating within our company Hyper-V server, the deployment profile was adjusted to let new user be administrator type. My colleague tested the Autopilot process on that VM. Subsequently, I signed into that VM as well, but noted that I being the second user was considered a standard user as well.

My colleague (global administrator for Azure AD) adjusted the domain devices settings, enabling the [Additional local administrators on Azure AD joined devices] policy and declared my user account as part of that group.

It's been nearly 24 hours and the policy does not appear to have flowed through to the computers despite multiple sync attempts. When signed in as my account, I still get challenged for administrator credentials. Are there still additional configuration steps we missed? Or does this particular policy take an awfully long time to sync and take effect?

Furthermore, with the second VM, I noticed that my account setup procedure isn't fully complete and am not sure why.


The melody of logic will always play out the truth. ~ Narumi Ayumu, Spiral



How Terms of use work in mobile application

$
0
0

Hi,

I am working on terms of use in the Azure portal for my Application, I have few doubts to be clarified.

  1. If I add terms of use for application, what about the the user which is already registered in Azure portal and already logged in to my application. how the existing user will come to know.?
  2. How do I edit the PDF which I have  uploaded, For example I want to change the new version of terms and condition PDF so how can I do that?

On-premise application published on Microsoft Azure AD "Myapps"

$
0
0

What will be the best way to publish a «on-premise» application into Azure AD «MyApps»?

1- Using the Application Proxy?
2- Create a VPN betwenn Azure and customer site?
3- Put the application in front of the Internet through Firewall and WAF? 

We need to consider about 5000 simultaneous users during peak periods.

I know which one is my favotite, but I need the opinions of others... 

Many thanks.

Martin R.

What Azure Devops ?

$
0
0

What Azure Devops ?

what is required to learn it ?

Does it require scripting knowledge ?

It is just a way of working ?

Can you please help me to correct my understanding ?

Viewing all 16000 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>