Intel vPro® Platform
Intel Manageability Forum for Intel® EMA, AMT, SCS & Manageability Commander
3051 Discussions

Intel EMA New AD Group Error

Yauheni
Beginner
2,473 Views

Hello,

I have installed and configured Intel EMA server and use Azure SSO to login users from my organization. It works well. I see there is an option to add whole AD groups to server and use them to manage access rights. But I encounter a problem (Internal server Error) when I try to add any group from Azure AD. Is it even possible or I do some mistakes during setup process?

0 Kudos
8 Replies
Yauheni
Beginner
2,443 Views

It happens due to lack of api permissions for groups for appRegistration for Azure. It is confusing because I didn't find any information about this permissions in intel-ema-server-installation-and-maintenance-guide.

0 Kudos
Tristan_T_Intel
Employee
1,793 Views

Could you share a screenshot or details on what permission change?

0 Kudos
Yauheni
Beginner
1,782 Views

Yes, to work with AD groups via Azure SSO you need to add group permissions for App registration in Azure.

Yauheni_0-1739257054332.png

It is confusing because in intel-ema-server-installation-and-maintenance-guide manual they mention only "User.Read.All" permission

Yauheni_1-1739257286740.png

 



 

 

0 Kudos
vij1
Employee
2,417 Views

Hello Yauheni,

 

Greetings!

 

Could you please share the details below:

 

OS version of the Server

SQL version

Location of both; (physical, virtual)

Will they be on the same server machine?

Authentication mode: Local, Azure AD, or Windows AD

Intel® EMA software version:

 

Regards,

Vijay N

Intel Customer Support.

intel.com/vpro

 


0 Kudos
vij1
Employee
2,354 Views

Hello Yauheni,

 

I am following up on the case and wondering if I can help you with anything else. Look forward to your response.

 

Regards,

Vijay N


0 Kudos
Yauheni
Beginner
2,346 Views

As I mentioned earlier I fixed my problem by adding additional API permissions for appRegistarion.

0 Kudos
vij1
Employee
2,326 Views

Hello Yauheni,

 

Greetings!

 

Thank you for your response.

 

Please find the Intel® Endpoint Management Assistant (Intel® EMA) Deployment Guide for Microsoft Azure at the link below:

Intel® EMA Deployment Guide for Azure


https://www.google.com/url?sa=i&url=https%3A%2F%2Fcdrdv2-public.intel.com%2F841816%2Fintel-ema-web-deployment-guide-fo-azue.pdf&psig=AOvVaw1Y1i8yI1CIqqx_X7fr5w44&ust=1734630578669000&source=images&cd=vfe&opi=89978449&ved=0CAYQrpoMahcKEwiAsIjN8LGKAxUAAAAAHQAAAAAQBA

  

If you need any assistance in the future, please feel free to reach out to us.

 

Best regards,

Vijay N


0 Kudos
Chrisatwork
Beginner
1,313 Views

I have the same error using standard on prem AD and LDAP, when trying to add AD Groups using the EMA tool and AD distinguished name.
(Internal Server Error)

What could cause that.
Very frustrating.

 

0 Kudos
Reply