Security

 View Only
Expand all | Collapse all

CPPM Intune Extension

This thread has been viewed 134 times
  • 1.  CPPM Intune Extension

    Posted Dec 02, 2020 03:40 PM
    We're just setting up the CPPM Intune Extension following the latest Integration Guide (2020-01).

    We've double checked permissions and tried to ensure all configuration in Azure is correct however we're experiencing the following error message:

    [2020-12-02T15:25:00.645] [ERROR] Intune - Error getting device list. Request failed with status code 401
    [2020-12-02T15:25:00.646] [ERROR] Intune - {"error":{"code":"UnknownError","message":"{\"ErrorCode\":\"Forbidden\",\"Message\":\"{\\r\\n \\\"_version\\\": 3,\\r\\n \\\"Message\\\": \\\"An error has occurred - Operation ID (for customer support): 00000000-0000-0000-0000-000000000000 - Activity ID: cd4f9083-f950-44......

    Obviously the Forbidden message is a clue, but we've triple checked the Azure settings and can't seem to find anything that would suggest it's configured incorrectly.

    Any pointers before I go through the TAC process?

    ------------------------------
    Victor Castro
    ------------------------------


  • 2.  RE: CPPM Intune Extension

    Posted Dec 02, 2020 04:28 PM
    Victor

    One common issue I've seen people miss a few times is the 'GRANT' option when creating the config.

    ------------------------------
    Danny Jump
    "Passionate about CPPM"
    ------------------------------



  • 3.  RE: CPPM Intune Extension

    Posted Dec 02, 2020 04:59 PM
    Thanks Danny,

    I'm fairly certain we configured it correctly, are these the only permissions that we need to be concerned with?  As far as I can tell they match the documentation.

    Thanks



    ------------------------------
    Victor Castro
    ------------------------------



  • 4.  RE: CPPM Intune Extension

    Posted Dec 02, 2020 10:13 PM
    Thx Victor,

    That looks good, can you confirm you have the v5 of the Intune Extension, and the user you used to create the APP and Permission, was this a Global Admin account?

    ------------------------------
    Danny Jump
    "Passionate about CPPM"
    ------------------------------



  • 5.  RE: CPPM Intune Extension

    Posted Dec 02, 2020 11:18 PM
    Yep, we're running V5.0.0 and the account used to create the app and grant the permissions has Global Admin Access.

    Any other thoughts or should I open a TAC case?

    Thanks again,
    Victor



    ------------------------------
    Victor Castro
    ------------------------------



  • 6.  RE: CPPM Intune Extension

    Posted Dec 03, 2020 01:09 AM
    I'm leaning that way currently.

    ------------------------------
    Danny Jump
    "Passionate about CPPM"
    ------------------------------



  • 7.  RE: CPPM Intune Extension

    Posted Dec 03, 2020 09:25 AM
    One thing that was not clear to me the first time is that you have a client-id in the Application in Azure, and one with the API token when you create that. For ClearPass you need to enter the one in the Application. I took the wrong one the first time, but I think the message that I found in the logs was quite clear that I took the wrong one, and I don't remember it the same as the one you posted.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC.
    ------------------------------



  • 8.  RE: CPPM Intune Extension
    Best Answer

    Posted Dec 03, 2020 10:18 AM
    We figured it out.  When granting permission for the app you can grant Application or Delegated permissions.  We incorrectly granted some permissions as Delegated instead of Application.

    Thanks for your help Danny and Herman!

    Incorrect:


    Correct:



    ------------------------------
    Victor Castro
    ------------------------------



  • 9.  RE: CPPM Intune Extension

    Posted Dec 03, 2020 11:59 AM
    Yeah :-)

    Does the TechNote need an update, or just an error on yourside?

    ------------------------------
    Danny Jump
    "Passionate about CPPM"
    ------------------------------



  • 10.  RE: CPPM Intune Extension

    Posted Dec 03, 2020 01:32 PM

    I think adding it in the documentation wouldn't as there is a choice to be made that is only clear by referencing the images.  I wouldn't re-publish the guide just for this.

    Thanks,
    Victor



    ------------------------------
    Victor Castro
    ------------------------------