Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

NEW CMG creation fails

  • Thread starter Thread starter andy0rtiz
  • Start date Start date
  • Replies Replies 3
  • Views Views 5K

andy0rtiz

New Member
Messages
1
Reaction score
0
Points
1
Updated to Current Brach 2309. Tried to upgrade CMG from classic and it failed. We deleted the original CMG from console and Azure. Cloud Service, WebApp and ClientApp creates with no issue. When attempting to create CMG, after clicking sign-in the console crashes. On the SMSAdminUI,log we get a Failed to get permissions for sign in user with status code BadRequest. Attempt to do via PowerShell and it fails with Failed to get permissions for sign in user with status code BadRequest. User account signing is Azure Owner/Contributor and Global Admin via PIM.
 
Solution
Thanks. This is what fixed it for me. In Azure Tenant properties I had to enable:

Access management for Azure resources​

Username can manage access to all Azure subscriptions and management groups in this tenant.
(Yes/No)
Updated to Current Brach 2309. Tried to upgrade CMG from classic and it failed. We deleted the original CMG from console and Azure. Cloud Service, WebApp and ClientApp creates with no issue. When attempting to create CMG, after clicking sign-in the console crashes. On the SMSAdminUI,log we get a Failed to get permissions for sign in user with status code BadRequest. Attempt to do via PowerShell and it fails with Failed to get permissions for sign in user with status code BadRequest. User account signing is Azure Owner/Contributor and Global Admin via PIM.
I have the same issue. Did you ever get this resolved?
 
Be sure to sign in with subscription owner account.
Also, try to update application settings for CMG WebApp.
Find CMG WebApp in SCCM under your tenant, right click on it and update application settings.
 
Thanks. This is what fixed it for me. In Azure Tenant properties I had to enable:

Access management for Azure resources​

Username can manage access to all Azure subscriptions and management groups in this tenant.
(Yes/No)
 
Solution

Forum statistics

Threads
7,135
Messages
27,868
Members
18,159
Latest member
jordysmits
Back
Top