# Azure AD - Aggregation error

**URL:** <https://developer.sailpoint.com/discuss/t/azure-ad-aggregation-error/56702>\
**Category:** IIQ Discussion and Questions\
**Tags:** identityiq, applications\
**Created:** [May 16, 2024, 6:18am UTC](https://developer.sailpoint.com/discuss/t/azure-ad-aggregation-error/56702 "2024-05-16T06:18:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![BertJohnson](https://avatars.discourse-cdn.com/v4/letter/b/47e85d/32.png) [@BertJohnson](https://developer.sailpoint.com/discuss/u/BertJohnson)\
**Post date:** [May 16, 2024, 6:18am UTC](https://developer.sailpoint.com/discuss/t/azure-ad-aggregation-error/56702/1 "2024-05-16T06:18:01Z")

</div>

### Which IIQ version are you inquiring about?

Version 8.4

### Share all details related to your problem, including any error messages you may have received.

Hello,

I have onboarded Azure AD application without IQService. SailPoint Test connection is successful to Azure AD. But when performing the aggregation, I face an error

“Exception during aggregation of Object Type Account on Application Test-Azure AD. Reason: Unable to create iterator sailpoint.connector.ConnectorException: Exception occurred in Iterate Objects - populateRiskyUsersDetails. Error message - Exception occurred in processReadRequest. Error - Exception occurred while trying to receive data from Server. Number of retries exceeded.Your tenant is not licensed for this feature. Please upgrade your subscription to access it.”

Do I need to upgrade my subscription ?

---

<div class="post-metadata">

**Author:** ![kjakubiak](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/kjakubiak/32/7052_2.png) [@kjakubiak](https://developer.sailpoint.com/discuss/u/kjakubiak)\
**Post date:** [May 16, 2024, 6:19am UTC](https://developer.sailpoint.com/discuss/t/azure-ad-aggregation-error/56702/2 "2024-05-16T06:19:11Z")

</div>

Hi Bert,  
It depends which features you use - easiest way would be to paste here the app xml so we could take a look on them.

Here you can also find some more details about features

> **[Supported Features](https://documentation.sailpoint.com/connectors/microsoft/entra_id/help/integrating_entra_id/supported_features.html)**
>
> SailPoint Connectors Documentation

and here about required permissions

> **[Required Permissions](https://documentation.sailpoint.com/connectors/microsoft/entra_id/help/integrating_entra_id/administrator_permission.html)**
>
> SailPoint Connectors Documentation

---

<div class="post-metadata">

**Author:** ![BalajiChandrasekaran](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/balajichandrasekaran/32/8386_2.png) [@BalajiChandrasekaran](https://developer.sailpoint.com/discuss/u/BalajiChandrasekaran)\
**Post date:** [May 16, 2024, 6:23am UTC](https://developer.sailpoint.com/discuss/t/azure-ad-aggregation-error/56702/3 "2024-05-16T06:23:39Z")

</div>

Hello @BertJohnson,

In the application go to schema and in Accountschema and delete the attribute called risky user attributes in the schema and it will work

Please also see config guide for Azure [https://community.sailpoint.com/t5/IdentityNow-Connectors/Azure-Active-Directory-Source-Configuration-Reference-Guide/ta-p/75323](https://community.sailpoint.com/t5/IdentityNow-Connectors/Azure-Active-Directory-Source-Configuration-Reference-Guide/ta-p/75323)

- **Risky User Alert Feature**

With the security reports in the Azure Active Directory system, you can gauge the probability of the compromised user accounts in your environment. A user flagged for risk is an indicator that the account might have been compromised. The user risk represents the probability that a given identity or account is compromised. These risks are calculated offline using Microsoft’s internal and external threat intelligence sources including security researchers, law enforcement professionals, security teams at Microsoft, and other trusted sources.

The Azure Active Directory source supports the risky user alert feature. **Requirement** : An Azure AD Premium P2 license is required to avail this feature. The supported operations for the risky user alert feature are Full Account Aggregation and Get Object.

Test this and if it doesnt work, paste here the app xml object

---

<div class="post-metadata">

**Author:** ![akash\_gupta](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/akash_gupta/32/2869_2.png) [@akash\_gupta](https://developer.sailpoint.com/discuss/u/akash_gupta)\
**Post date:** [May 23, 2024, 5:24pm UTC](https://developer.sailpoint.com/discuss/t/azure-ad-aggregation-error/56702/4 "2024-05-23T17:24:39Z")

</div>

Thanks, this is very helpful.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [July 22, 2024, 5:25pm UTC](https://developer.sailpoint.com/discuss/t/azure-ad-aggregation-error/56702/5 "2024-07-22T17:25:30Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
