I have been working on automation for a particular client, and ran into an interesting issue with adding Azure AD administrators to an Azure SQL instance. The purpose of this post is to chat a little more about how to debug this issue and ultimately fix it.
As part of my process, I generally create automation and test it using my own account and on my local machine. Once I feel like I have something working, I move that to Azure automation. In general, the service account that Azure Automation automatically has the same permissions as my own account (unless changed from the default). This is true for Azure, but not true for some of the API access that may be inherently required.
The command that I am using to add a SQL Admin is Set-AzureRmSqlServerActiveDirectoryAdministrator. Unfortunately, the MSDN docs do a pretty poor job of describing the minimum set of permissions required to run these commands. In my automation tests, I received a cryptic "Access Denied". At first I thought this had to do with Azure access, but that didn't make much sense. Running the above command with the verbose flag and the debug flag yielded the following:
As you can see from the body of the response, I do not have sufficient privileges with the automation service account. The Request is going out to the graph API and seems to be verifying that the display name actually exists in AAD before adding it.
Granting permissions to the service account is quite easy, can can be done via the Azure portal. Navigate to AAD, click App Registrations, select the appropriate one and then click on Required Permissions. As these permissions need to be done by the service account itself, click add and then select the Graph API. I selected Read All Groups and Read Directory Data from the Application Permissions section.
After this, ensure to hit the Grant Permissions button at the top to make the changes permanent. After these changes, I was finally able to add an Azure AD Admin to an Azure SQL server via script with an Azure Automation service account.
I'm really enjoyed this article. I hope it is useful for others. Thanking you.
ReplyDeleteAppium Training in Chennai
Mobile Appium Coaching in Chennai
Appium Training in OMR
JMeter Training Course
JMeter Course
core java training in chennai
C C++ Training in Chennai
javascript training in chennai
Great Article Cloud Computing Projects
DeleteNetworking Projects
Final Year Projects for CSE
JavaScript Training in Chennai
JavaScript Training in Chennai
The Angular Training covers a wide range of topics including Components, Angular Directives, Angular Services, Pipes, security fundamentals, Routing, and Angular programmability. The new Angular TRaining will lay the foundation you need to specialise in Single Page Application developer. Angular Training
Great collection and thanks for sharing this info with us. Waiting for more updates.
ReplyDeleteDevOps Training in Chennai
DevOps Certification in Chennai
AWS Training in Chennai
AWS course in Chennai
Cloud Computing Training in Chennai
Cloud Computing courses in Chennai
DevOps Training in Velachery
DevOps course in Chennai
Really wonderful blog! Thanks for taking your valuable time to share this with us. Keep us updated with more such blogs.
ReplyDeleteAWS Training in Chennai
AWS Training
DevOps certification in Chennai
VMware Training in Chennai
Azure Training in Chennai
Cloud Computing Training in Chennai
AWS course in Chennai
AWS Certification in Chennai
AWS Training in Chennai
This was helpful to me thanks for sharing this useful information. Kindly continue the work.
ReplyDeleteSpoken English Class in Chennai
Spoken English in Chennai
IELTS Training in Chennai
IELTS Chennai
Best English Speaking Classes in Mumbai
Spoken English Classes in Mumbai
IELTS Mumbai
IELTS Center in Mumbai
ReplyDeleteGreat Blog!!! Was an interesting blog with a clear concept. And will surely help many to update them.
Machine Learning course in Chennai
Machine Learning Training in Chennai
Data Science Course in Chennai
DevOps Training in Chennai
RPA Training in Chennai
AWS Training in Chennai
This is the first & best article to make me satisfied by presenting good content. I feel so happy and delighted. Thank you so much for this article.
ReplyDeleteLearn Best Digital Marketing Course in Chennai
Digital Marketing Course Training with Placement in Chennai
Learn Digital Marketing Course Training in Chennai
Digital Marketing Training with Placement Institute in Chennai
I have been reading for the past two days about your blogs and topics, still on fetching! Wondering about your words on each line was massively effective.
ReplyDeletephp online training in chennai
php programming center in chennai
php class in chennnai
php certification course
php developer training institution chennai
php training in chennnai
php mysql course in chennai
php institute in chennnai
php course in chennnai
php training with placement in chennnai
php developer course
Nice post. Thanks for sharing! I want people to know just how good this information is in your article. It’s interesting content and Great work.
ReplyDeleteappium online training
appium training centres in chennai
best appium training institute in chennnai
apppium course
mobile appium in chennnai
mobile training in chennnai
appium training institute in chennnai
This is a really very nice and good informative blog.
ReplyDeletewhat is ios development
what is hadoop in big data
characteristics and benefits of cloud computing
categories of cloud computing
hardware and networking question and answer
node js interview questions and answers pdf
Aivivu - đại lý chuyên vé máy bay trong nước và quốc tế
ReplyDeletevé máy bay đi Mỹ bao nhiêu
gia ve may bay ve vn
vé máy bay hà nội sài gòn giá rẻ
vé máy bay từ phú quốc đi hà nội
vé máy bay hà nội nha trang
dịch vụ xe đưa đón sân bay
combo hà nội đà lạt 4 ngày 3 đêm