Tech Community Live: Endpoint Manager edition
Jul 21 2022, 08:00 AM - 12:00 PM (PDT)

Cloud Only account accessing Configmgr information for devices

%3CLINGO-SUB%20id%3D%22lingo-sub-2607226%22%20slang%3D%22en-US%22%3ECloud%20Only%20account%20accessing%20Configmgr%20information%20for%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2607226%22%20slang%3D%22en-US%22%3E%3CP%3EIn%20our%20current%20configuration%2C%20we%20separate%20our%20on-prem%20management%20and%20our%20cloud%20management%20accounts.%26nbsp%3B%20We%20have%20come%20across%20an%20issue%20with%20Endpoint%20Manager%20when%20we%20access%20any%20info%20that%20comes%20from%20ConfigMgr%20(Timeline%2C%20Collections%2C%20CMPivot%2C%20ect%20ect)%20due%20to%20a%20401%20error.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%20data-unlink%3D%22true%22%3EThe%20reason%20why%20this%20happens%20is%20that%20our%20username%40company.onmicrosoft.com%26nbsp%3Bdoes%20not%20have%20access%20to%20this%20data%20on-premise.%26nbsp%3B%20You%20need%20to%20grant%20a%20local%20account%2C%20%3CA%20href%3D%22mailto%3Ausername%40company.com%2C%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Eusername%40company.com%2C%3C%2FA%3E%26nbsp%3Baccess%20to%20pull%20this%20info.%3C%2FP%3E%3CP%20data-unlink%3D%22true%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20data-unlink%3D%22true%22%3EI%20have%20tested%20that%20if%20our%20onprem%20account%20is%20granted%20access%20to%20endpoint%20manager%2C%20they%20can%20pull%20the%20information%20but%20I%20really%20do%20not%20want%20to%20have%20to%20train%20my%20team%20that%20you%20use%20your%20onmicrosoft.com%20for%20everything%20cloud%2C%20and%20then%20use%20your%20local%20account%20for%20Endpoint%20Manager.%3C%2FP%3E%3CP%20data-unlink%3D%22true%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20data-unlink%3D%22true%22%3EIs%20there%20any%20way%20around%20this%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2607226%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECloud-attached%20management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ECM%20current%20branch%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2789233%22%20slang%3D%22en-US%22%3ERe%3A%20Cloud%20Only%20account%20accessing%20Configmgr%20information%20for%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2789233%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3E%3CBR%20%2F%3EYou%20can%E2%80%99t%20use%20separate%20account%20for%20these%20functionnalities.%20It%E2%80%99s%20a%20prereq%20to%20use%20the%20same%20account%20for%20Configuration%20Manager%20and%20Admin%20Center.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fconfigmgr%2Ftenant-attach%2Ftroubleshoot-cmpivot%23bkmk_noinfo%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fconfigmgr%2Ftenant-attach%2Ftroubleshoot-cmpivot%23bkmk_noinfo%3C%2FA%3E%3C%2FLINGO-BODY%3E
Contributor

In our current configuration, we separate our on-prem management and our cloud management accounts.  We have come across an issue with Endpoint Manager when we access any info that comes from ConfigMgr (Timeline, Collections, CMPivot, ect ect) due to a 401 error.

 

The reason why this happens is that our username@company.onmicrosoft.com does not have access to this data on-premise.  You need to grant a local account, username@company.com, access to pull this info.

 

I have tested that if our onprem account is granted access to endpoint manager, they can pull the information but I really do not want to have to train my team that you use your onmicrosoft.com for everything cloud, and then use your local account for Endpoint Manager.

 

Is there any way around this?

2 Replies
Hi,

You can’t use separate account for these functionnalities. It’s a prereq to use the same account for Configuration Manager and Admin Center.

https://docs.microsoft.com/en-us/mem/configmgr/tenant-attach/troubleshoot-cmpivot#bkmk_noinfo
Which is a poor design IMO, if you separate your accounts for security purposes. I was aware of the limitation, was wondering if anyone was able to overcome it.