question

BrandonM-0342 avatar image
0 Votes"
BrandonM-0342 asked BrandonM-0342 answered

Properties unavailable on Azure Services

I just upgraded SCCM to 2006 and trying to setup Tenant attach. I already had Co-management configured prior to the upgrade, so I simply used the "Configure upload" section to setup Endpoint Manager admin center data upload. Everything seem to go through fine. I verified that I have a ConfigMgrSvc_xxxxxxxxxxxxxx app registered in my Azure AD with the necessary Microsoft Graph Directory Read permissions. In the SCCM console, I have verified that this application is registered under Azure Active Directory Tenants. Under Azure Services, I see there is a service added called "Cloud Attach" that I assume was added automatically by the Tenant attach process. However, when I select it, I do not have a Properties option to view/modify the configuration. I need to enable AAD User sync so that I can start leveraging the additional device management features in the Endpoint Manager admin center. I checked my user account in SCCM Assets and Compliance and see that the Azure AD tenant ID and User Id are not populated. My user accounts are synced from on-premise AD with Azure AD Connect. What am I missing? I just performed this configuration a few hours ago. Do I need to give it more time? Also, I looked over SMS_AZUREAD_DISCOVERY_AGENT.log and CMGatewaySyncUploadWorker.log, but nothing really sticking out there as a possible issue, though I am not sure what exactly to look for.
38846-azuresvcs.jpg

mem-cm-co-management
azuresvcs.jpg (41.9 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Jason-MSFT avatar image
0 Votes"
Jason-MSFT answered

The above (no properties on Cloud Attach) is normal and expected.

To enable AAD User Discovery, you need to review the Discovery page on the properties of the Cloud Management item listed in Azure Services. You won't have this service unless you enable co-management itself though. If you are not seeing this item in the list of Azure service, you may not have sufficient permissions within ConfigMgr.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

BrandonM-0342 avatar image
0 Votes"
BrandonM-0342 answered BrandonM-0342 edited

Thanks Jason. I am not sure I follow. You are saying that I should see a Cloud Management item, besides Cloud Attach, under Azure Services? I have Full Administrator in ConfigMgr. I setup Co-management months ago and just enabled the Configure upload > "Upload to Microsoft Endpoint Manager admin center" option today.

· 4
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Correct. Full admin is not sufficient, you must also have access to All Scopes as well.

If you still do not see this, you should open a support case.

0 Votes 0 ·

Yes, I also have access to "All" security scopes. Do you know which database table I can lookup where this object would be located so that I can see if it created something that I am just not seeing? Thanks.

0 Votes 0 ·

Off-hand no, I don't know where these objects are stored in the DB. Thus a support case as noted is in order.

0 Votes 0 ·
Show more comments
BrandonM-0342 avatar image
0 Votes"
BrandonM-0342 answered

I was about to open a support case, but I decided not to. Instead, I created another Cloud Management Azure Service just to see if it would sync AAD Users and that worked fine. Seems to me that there may be a bug with enabling Tenant Attach after Co-management has already been setup and I cannot justify using a support call for that. Support may just have me do what I already did on my own. In addition, our MS support contract is under another division at my company and I would have jump through all kinds of hoops just to get that opened.

On a side note, I really like these new integrated features you get under the Endpoint Manager admin center. Totally worth setting up if you have a hybrid environment.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.