Troubleshooting missing Entra ID permissions after product update
Symptoms
After upgrading Cayosoft Guardian a health check reports issues related to Entra ID permissions.
Cause
Cayosoft Guardian cannot automatically re-grant permissions when the Entra ID service account is operating in Read-Only (RO) mode.
When a new Entra ID permission is introduced in a product update (for example, ProfilePhoto.Read.All in the current version), Guardian does not promote or re-consent permissions automatically for existing service accounts.
As a result:
- The permission is missing
- Guardian continues operating with the previously granted permission set
- Manual re-grant is required
Resolution
You must manually re-grant Entra ID permissions for the affected service account.
How to re-grant Entra ID permissions
- Open the Cayosoft Guardian web portal.
- Navigate to Configuration > Credentials.
- Locate the Entra ID service account used by Guardian.
- Open the credential Properties.
- Click Grant access.
- Complete the consent wizard.
- Verify that the wizard completes successfully.
NOTE: This action does not remove previously granted permissions.
After re-granting permissions:
Run Health check on Managed tenant after consent is regranted.
- Confirm that no Entra ID permission warnings are present.
- Verify that the required permission (for example,
ProfilePhoto.Read.All) appears in the Entra app registration. - Verify that affected functionality works as expected.
Comments
0 comments
Please sign in to leave a comment.