Hi all,
I am experiencing the following issue while executing FSM installer using customer provided user.
When checked from the Azure AD level. The user doesn't have assigned roles.
My question is what are the exact assigned roles user should have from the active directory level to execute the installer? Do I have any documentation from RND refer regarding Azure installation user permission to the AD level?
Also, customers are not willing to provide Global or any kind of administrator privilege to the current user.
11/9/2022 3:25:56 PM: Error occurred while creating the service principal to authenticate with ResourceManagement client New-AzADServicePrincipal: The role assignment creation operation failed with the error: 'The client 'ifs@XXXXX.net' with object id '4e83b984-4af8-47a1-99d9-5e6a6cb0063c' does not have authorization to perform action 'Microsoft.Authorization/roleAssignments/write' over scope '/subscriptions/4ed92412-5367-4a99-8f5e-b24346ce976d/providers/Microsoft.Authorization/roleAssignments/e4be2d1c-3417-4740-b661-0e9c231626fc' or the scope is invalid. If access was recently granted, please refresh your credentials.'
This means the role assignment was not able to be created. Please assign a role manually with help of the Service Principal Id
.
11/9/2022 3:25:56 PM: Error occurred while setting Azre subscription.
Microsoft.IdentityModel.Clients.ActiveDirectory.AdalServiceException: AADSTS700016: Application with identifier '4485e2c0-e72e-40f6-a62a-438dd8abe521' was not found in the directory 'XXXXX Flotte s.r.l.'. This can happen if the application has not been installed by the administrator of the tenant or consented to by any user in the tenant. You may have sent your authentication request to the wrong tenant
Thank you,
Best Regards,
Teshan.