Symantec Privileged Access Management

 View Only

Azure as IDP - SAML user sync issue

  • 1.  Azure as IDP - SAML user sync issue

    Posted Mar 25, 2021 11:01 AM
    Hi Team,

    I have configured Azure AD as IDP for my CA PAM azure cluster . However I am unable to sync users to PAM . Session logs reports this error .

    PAM-CMN-5361: Failed to access Azure API: Authorization_RequestDenied - Insufficient privileges to complete the operation..

    CAPAM has below API permission in Microsoft Graph 

    • Directory.AccessAsUser.All
    • Directory.Read.All
    • User.Read

      Kindly assist