Cannot Query Management Service - WVD

%3CLINGO-SUB%20id%3D%22lingo-sub-1085633%22%20slang%3D%22en-US%22%3ECannot%20Query%20Management%20Service%20-%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1085633%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Everyone%2C%3CBR%20%2F%3E%3CBR%20%2F%3EHappy%20New%20Year!%3CBR%20%2F%3E%3CBR%20%2F%3ESince%20joining%20a%20new%20organization%2C%20me%20and%20one%20of%20my%20colleagues%20build%2Fmaintain%20the%20azure%20environment%20we%20have.%20When%20I%20first%20joined%20I%20was%20only%20given%20Global%20Reader%20Access.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20now%20have%20the%20same%20access%20control%20as%20him%20(Owner%2C%20Contributor%2C%20User%20Access%20Admin)%2C%20same%20AAD%20Roles%20such%20as%20Global%20Admin%20and%20others%20whilst%20he%20just%20has%20Global%20Admin.%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20problem%20I%20have%20is%20that%20I%20cannot%20manage%20our%20tenants%2Fhostpools%20via%20powershell%20like%20he%20can.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3ERunning%26nbsp%3BAdd-RdsAccount%20-DeploymentUrl%20%22%3CA%20href%3D%22https%3A%2F%2Frdbroker.wvd.microsoft.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Frdbroker.wvd.microsoft.com%3C%2FA%3E%22%3C%2FP%3E%3CP%3EI%20sometimes%20get%20errors%20or%20it%20will%20connect.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20just%20connected%20and%20attempted%20to%20run%26nbsp%3BGet-RdsTenant%20for%20one%20of%20our%20tenants%20and%20got%20the%20following%20%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGet-RdsTenant%20%3A%20User%20is%20not%20authorized%20to%20query%20the%20management%20service.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEven%20running%20the%20same%20command%20for%20a%20tenant%20I%20created%20I%20get%20the%20same%20error.%3CBR%20%2F%3E%3CBR%20%2F%3EWe%20have%20both%20have%20MFA%20enabled%20but%20he%20has%20no%20issues%20whatsoever.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3ECan%20anyone%20share%20any%20suggestions%2Ffixes%3F%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1085633%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Virtual%20Desktop%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1108880%22%20slang%3D%22en-US%22%3ERe%3A%20Cannot%20Query%20Management%20Service%20-%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1108880%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F503977%22%20target%3D%22_blank%22%3E%40AT1991%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYour%20doing%20it%20with%20the%20Azure%20CLI%20or%20Powershell%3F%3C%2FP%3E%3CP%3EMaybe%20this%20is%20a%20Problem%20with%20the%20Account%20Cache%20in%20the%20Powershell.%3C%2FP%3E%3CP%3EI%20saw%20this%20somewhen%20in%20the%20past.%3C%2FP%3E%3CP%3EMaybe%20reinstallation%20of%20the%20Modules%20or%20Azure%20CLI%20may%20help%2C%20and%20also%20a%20new%20AZ%20Login%20and%20Token%20Refresh.%20Maybe%20also%20try%20if%20the%20Issue%20is%20the%20same%20in%20your%20colleagues%20Cliwent%2C%20or%20if%20all%20works%20fine%20with%20that%20one.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESounds%20more%20like%20a%20Client%20Issue%20instead%20of%20a%20Azure%20Permission%20Issue.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKind%20Regards%2C%20Peter%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1109954%22%20slang%3D%22en-US%22%3ERe%3A%20Cannot%20Query%20Management%20Service%20-%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1109954%22%20slang%3D%22en-US%22%3EHi%20Peter%2C%3CBR%20%2F%3E%3CBR%20%2F%3EI%20should%20have%20closed%20this%2C%20it%20is%20resolved.%20It%20was%20to%20do%20with%20a%20RDS%20Role%20permission%20%3A)%3C%2Fimg%3E%3CBR%20%2F%3E%3CBR%20%2F%3EThanks%2C%3CBR%20%2F%3EAaron%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi Everyone,

Happy New Year!

Since joining a new organization, me and one of my colleagues build/maintain the azure environment we have. When I first joined I was only given Global Reader Access.

I now have the same access control as him (Owner, Contributor, User Access Admin), same AAD Roles such as Global Admin and others whilst he just has Global Admin. 

The problem I have is that I cannot manage our tenants/hostpools via powershell like he can.

Running Add-RdsAccount -DeploymentUrl "https://rdbroker.wvd.microsoft.com"

I sometimes get errors or it will connect.

I just connected and attempted to run Get-RdsTenant for one of our tenants and got the following :

 

Get-RdsTenant : User is not authorized to query the management service.

 

Even running the same command for a tenant I created I get the same error.

We have both have MFA enabled but he has no issues whatsoever.

Can anyone share any suggestions/fixes? 

2 Replies
Highlighted

Hi @AT1991,

 

Your doing it with the Azure CLI or Powershell?

Maybe this is a Problem with the Account Cache in the Powershell.

I saw this somewhen in the past.

Maybe reinstallation of the Modules or Azure CLI may help, and also a new AZ Login and Token Refresh. Maybe also try if the Issue is the same in your colleagues Cliwent, or if all works fine with that one.

 

Sounds more like a Client Issue instead of a Azure Permission Issue.

 

Kind Regards, Peter

Highlighted
Hi Peter,

I should have closed this, it is resolved. It was to do with a RDS Role permission :)

Thanks,
Aaron