SOLVED

Unable to add users to Application Groups using Modern WVD Admin console

%3CLINGO-SUB%20id%3D%22lingo-sub-1386207%22%20slang%3D%22en-US%22%3EUnable%20to%20add%20users%20to%20Application%20Groups%20using%20Modern%20WVD%20Admin%20console%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1386207%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20Guys%2C%3CBR%20%2F%3E%3CBR%20%2F%3EStarting%20to%20look%20into%20the%20new%20deployment%20%26amp%3B%20management%20portal%20introduced%20in%20end%20of%20April%202020%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fblog%2F2020%2F04%2F30%2Fenable-remote-work-faster-new-windows-virtual-desktop-capabilities%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fblog%2F2020%2F04%2F30%2Fenable-remote-work-faster-new-windows-virtual-desktop-capabilities%2F%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EStarted%20to%20play%20with%20and%20successfully%20created%20WVD%20pools%20and%20now%20facing%20issue%20when%20wanted%20to%20assign%20users%20to%20remote%20desktop%20the%20vm%20in%20that%20pool%20using%20Application%20Groups.%3CBR%20%2F%3E%3CBR%20%2F%3EIn%20fact%2C%20when%20trying%20to%20assign%20a%20user%20to%20an%20application%20group%2C%20the%20following%20error%20message%20is%20thrown%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%3E%7B%22details%22%3A%5B%7B%22code%22%3A%22InvalidTemplateDeployment%22%2C%22message%22%3A%22%7B%5C%22content%5C%22%3A%7B%5C%22error%5C%22%3A%7B%5C%22code%5C%22%3A%5C%22AuthorizationFailed%5C%22%2C%5C%22message%5C%22%3A%5C%22The%20client%20'%5Bredacted%5D'%20with%20object%20id%20'f1a4cbe1-3c75-4c9a-93ee-8e098841bcba'%20does%20not%20have%20authorization%20to%20perform%20action%20'Microsoft.Authorization%2FroleAssignments%2Fwrite'%20over%20scope%20'%2Fsubscriptions%2F%5Bredacted%5D%2FresourceGroups%2F%5Bredacted%5D%2Fproviders%2FMicrosoft.DesktopVirtualization%2Fapplicationgroups%2F%5Bredacted%5D%2Fproviders%2FMicrosoft.Authorization%2FroleAssignments%2F0aa9cdd7-0e9f-48d2-b711-e1d90aacb03c'%20or%20the%20scope%20is%20invalid.%20If%20access%20was%20recently%20granted%2C%20please%20refresh%20your%20credentials.%5C%22%7D%7D%2C%5C%22headers%5C%22%3A%7B%5C%22cache-control%5C%22%3A%5C%22no-cache%5C%22%2C%5C%22content-length%5C%22%3A%5C%22608%5C%22%2C%5C%22content-type%5C%22%3A%5C%22application%2Fjson%3B%20charset%3Dutf-8%5C%22%2C%5C%22expires%5C%22%3A%5C%22-1%5C%22%2C%5C%22pragma%5C%22%3A%5C%22no-cache%5C%22%2C%5C%22x-ms-correlation-request-id%5C%22%3A%5C%2231cd6312-fb7d-47eb-8e31-b211b3d3cc9a%5C%22%2C%5C%22x-ms-failure-cause%5C%22%3A%5C%22gateway%5C%22%2C%5C%22x-ms-request-id%5C%22%3A%5C%2231cd6312-fb7d-47eb-8e31-b211b3d3cc9a%5C%22%2C%5C%22x-ms-routing-request-id%5C%22%3A%5C%22FRANCECENTRAL%3A20200513T122722Z%3A31cd6312-fb7d-47eb-8e31-b211b3d3cc9a%5C%22%7D%2C%5C%22httpStatusCode%5C%22%3A403%7D%22%2C%22target%22%3A%220aa9cdd7-0e9f-48d2-b711-e1d90aacb03c%22%7D%5D%7D%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FSPAN%3EAny%20idea%20why%20this%20happens%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1387223%22%20slang%3D%22en-US%22%3ERe%3A%20Unable%20to%20add%20users%20to%20Application%20Groups%20using%20Modern%20WVD%20Admin%20console%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1387223%22%20slang%3D%22en-US%22%3ECan%20you%20please%20check%20if%20you%20are%20the%20owner%20of%20your%20resource%20group%3F%20go%20to%20the%20resource%20group%20that%20contains%20your%20WVD%20deployment%2C%20select%20Access%20Control%2C%20Role%20Assignment%20Tab%2C%20make%20sure%20you%20see%20your%20name%20and%20your%20role%20is%20Owner.%3CBR%20%2F%3Eif%20you're%20not%20the%20owner%2C%20then%20you'll%20need%20to%20ask%20your%20azure%20subscription%20administrator%20to%20add%20you%20as%20owner%20to%20your%20resource%20group.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1388383%22%20slang%3D%22en-US%22%3ERe%3A%20Unable%20to%20add%20users%20to%20Application%20Groups%20using%20Modern%20WVD%20Admin%20console%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1388383%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F181812%22%20target%3D%22_blank%22%3E%40Soo%20Kuan%20Teo%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EThank%20you%20for%20your%20response.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20see%20my%20account%20that%20i%20used%20to%20provision%20WVD%20and%20I%20inherit%20the%20permission%20through%20the%20Contributor%20role%20for%20the%20subscription%20%22Pay-As-You-Go%22.%3CBR%20%2F%3E%3CBR%20%2F%3EDoes%20this%20mean%20only%20users%20with%20Owner%20role%20can%20use%20the%20modern%20WVD%20admin%20console%3F%3CBR%20%2F%3E%3CBR%20%2F%3EAnother%20question%2C%20when%20i%20try%20to%20list%20pools%20using%20powershell%2C%20i%20do%20not%20see%20the%20pools%20created%20using%20the%20modern%20console%20either%20under%20the%20RDS%20tenant.%20Is%20there%20a%20specific%20way%20to%20look%20into%20please%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1390064%22%20slang%3D%22en-US%22%3ERe%3A%20Unable%20to%20add%20users%20to%20Application%20Groups%20using%20Modern%20WVD%20Admin%20console%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1390064%22%20slang%3D%22en-US%22%3Eyes%2C%20you%20need%20to%20have%20owner%20role%20for%20the%20resource%20group%20to%20be%20able%20to%20add%20user%20assignment.%3CBR%20%2F%3Ewhat%20powershell%20command%20you%20used%20to%20list%20pools%3F%20Make%20sure%20you%20use%20the%20latest%20powershell%20module%20for%20WVD%20deployment%20that%20is%20created%20with%20the%20modern%20console%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-desktop%2Fpowershell-module%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-desktop%2Fpowershell-module%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1391991%22%20slang%3D%22en-US%22%3ERe%3A%20Unable%20to%20add%20users%20to%20Application%20Groups%20using%20Modern%20WVD%20Admin%20console%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1391991%22%20slang%3D%22en-US%22%3EThanks%20a%20lot%20Soo%20Kuan%20Teo.%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hello Guys,

Starting to look into the new deployment & management portal introduced in end of April 2020:

https://www.microsoft.com/en-us/microsoft-365/blog/2020/04/30/enable-remote-work-faster-new-windows-...

Started to play with and successfully created WVD pools and now facing issue when wanted to assign users to remote desktop the vm in that pool using Application Groups.

In fact, when trying to assign a user to an application group, the following error message is thrown:

{"details":[{"code":"InvalidTemplateDeployment","message":"{\"content\":{\"error\":{\"code\":\"AuthorizationFailed\",\"message\":\"The client '[redacted]' with object id 'f1a4cbe1-3c75-4c9a-93ee-8e098841bcba' does not have authorization to perform action 'Microsoft.Authorization/roleAssignments/write' over scope '/subscriptions/[redacted]/resourceGroups/[redacted]/providers/Microsoft.DesktopVirtualization/applicationgroups/[redacted]/providers/Microsoft.Authorization/roleAssignments/0aa9cdd7-0e9f-48d2-b711-e1d90aacb03c' or the scope is invalid. If access was recently granted, please refresh your credentials.\"}},\"headers\":{\"cache-control\":\"no-cache\",\"content-length\":\"608\",\"content-type\":\"application/json; charset=utf-8\",\"expires\":\"-1\",\"pragma\":\"no-cache\",\"x-ms-correlation-request-id\":\"31cd6312-fb7d-47eb-8e31-b211b3d3cc9a\",\"x-ms-failure-cause\":\"gateway\",\"x-ms-request-id\":\"31cd6312-fb7d-47eb-8e31-b211b3d3cc9a\",\"x-ms-routing-request-id\":\"FRANCECENTRAL:20200513T122722Z:31cd6312-fb7d-47eb-8e31-b211b3d3cc9a\"},\"httpStatusCode\":403}","target":"0aa9cdd7-0e9f-48d2-b711-e1d90aacb03c"}]}

Any idea why this happens?

4 Replies
Highlighted
Can you please check if you are the owner of your resource group? go to the resource group that contains your WVD deployment, select Access Control, Role Assignment Tab, make sure you see your name and your role is Owner.
if you're not the owner, then you'll need to ask your azure subscription administrator to add you as owner to your resource group.

@Soo Kuan Teo 

Thank you for your response.

I see my account that i used to provision WVD and I inherit the permission through the Contributor role for the subscription "Pay-As-You-Go".

Does this mean only users with Owner role can use the modern WVD admin console?

Another question, when i try to list pools using powershell, i do not see the pools created using the modern console either under the RDS tenant. Is there a specific way to look into please?

Highlighted
Best Response confirmed by Sutha670 (New Contributor)
Solution
yes, you need to have owner role for the resource group to be able to add user assignment.
what powershell command you used to list pools? Make sure you use the latest powershell module for WVD deployment that is created with the modern console:
https://docs.microsoft.com/en-us/azure/virtual-desktop/powershell-module

Highlighted