Forum Discussion

Peter_Kaagman's avatar
Peter_Kaagman
Brass Contributor
Sep 13, 2023

SDS reports insufficient privileges on import

Hi There,

We've been using classic SDS for a couple of years now to create edu teams for our classes. We have a profile set up for this using "CSV Files: SDS format". Never experienced much troubles with that. Errors could usually be fixed by reading the error report.

Up until this schoolyear. This year we are getting a lot of errors concerning "insufficient privileges". Entries like:

 

EntryStatus: Error

EntryType: SchoolStudents

ErrorCode: AzureActiveDirectoryInsufficientRights

ErrorMessage: Insufficient privileges to complete the operation.

JoiningValue: School_3

MitigationSteps: <empty>

Operation: Update

RecordedTime: <some date>

TenantActionable: true

ReportableIdentifier: 3

 

About a thousand of those error are shown.

EntryType has 4 distinct values: Schoolreference, Schoolstudents, Schoolteachters or SectionReference

JoiningValue varies from School_3 up to School_6 

ReportableIdentifier changes with the JoiningValue

 

I have no clue as to what SDS is trying to do. Don't know what the problem is other than insufficient privileges.

 

Is there a place (log or something) which will explain what is going on?

 

regards

 

Peter

 

5 Replies

  • Peter_Kaagman's avatar
    Peter_Kaagman
    Brass Contributor
    Like to awnser my own question. Got the solution from ms support.

    SDS adds members to AUs. Turned out a co-worker hyjacked the AUs and made them of type dynamic membership. After this SDS could no longer add members. Resulting in an insufficient rights error.
  • SPEYK_RBroer's avatar
    SPEYK_RBroer
    Brass Contributor
    Don't know if you already have a solution, but, have you tried to do a Reset Sync? Or even adding a new sync profile and removing or disabling the old profile? Is the account used to upload still a Global Admin or does it have separate Admin roles to narrow down it's rights?
    • Peter_Kaagman's avatar
      Peter_Kaagman
      Brass Contributor

      SPEYK_RBroer 

       

      Did try full reset. Did not make a new profile yet, that kinda frightens me. I don't want to loose data.

      The account running the workflow is a full global global admin. But I get the error even when I sync by hand using the global admin account.

       

      Thanks for your reply.

       

      Peter

      • SPEYK_RBroer's avatar
        SPEYK_RBroer
        Brass Contributor
        I think a new profile is still a possibility to resolve your issues, but true, if you have data in active teams I also wouldn't risk it.

        But also, if you don't mix the numbers for the teams with a new upload in a new profile, it would create new teams with the same sectionnumber and a add-on of 4 random numbers. So the teams would exist next to each other and you don't lose data. In that case, the question is, can you live with all teams doubled? Would the teachers and students recognize and use the correct team, etcetera. All in all, I think this would not be the preferable way to solve it and should be used very carefully.

        Do you have considered opening a ticket with Microsoft?

Resources