- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
I have installed and configured Intel EMA server and use Azure SSO to login users from my organization. It works well. I see there is an option to add whole AD groups to server and use them to manage access rights. But I encounter a problem (Internal server Error) when I try to add any group from Azure AD. Is it even possible or I do some mistakes during setup process?
Link Copied
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It happens due to lack of api permissions for groups for appRegistration for Azure. It is confusing because I didn't find any information about this permissions in intel-ema-server-installation-and-maintenance-guide.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Could you share a screenshot or details on what permission change?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, to work with AD groups via Azure SSO you need to add group permissions for App registration in Azure.
It is confusing because in intel-ema-server-installation-and-maintenance-guide manual they mention only "User.Read.All" permission
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Yauheni,
Greetings!
Could you please share the details below:
OS version of the Server
SQL version
Location of both; (physical, virtual)
Will they be on the same server machine?
Authentication mode: Local, Azure AD, or Windows AD
Intel® EMA software version:
Regards,
Vijay N
Intel Customer Support.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Yauheni,
I am following up on the case and wondering if I can help you with anything else. Look forward to your response.
Regards,
Vijay N
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As I mentioned earlier I fixed my problem by adding additional API permissions for appRegistarion.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Yauheni,
Greetings!
Thank you for your response.
Please find the Intel® Endpoint Management Assistant (Intel® EMA) Deployment Guide for Microsoft Azure at the link below:
Intel® EMA Deployment Guide for Azure
If you need any assistance in the future, please feel free to reach out to us.
Best regards,
Vijay N
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have the same error using standard on prem AD and LDAP, when trying to add AD Groups using the EMA tool and AD distinguished name.
(Internal Server Error)
What could cause that.
Very frustrating.
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page