Azure AD entitlement Aggregation

Hi Experts,

In Azure AD connector, Aggregation gets failed for entitlement type : applicationRole, I’m seeing the following error message in ccg logs.

Can someone help me on this?

Hello @chandramohans27
Can you let me know the tenant name and enable tenant access for me to check the configurations. Looks like some sort of configuration issue.
You can DM me the tenant name.

1 Like

This is a FedRamp tenant, so discard my above request.
graph.microsoft.usv1.0 we observe that there is a missing slash (/) after “us” in the URI.
Can you add a slash (/) at the end where you have configured the domain.

1 Like

@harshamin9 Thanks for your reply!

But the mentioned API is no where configured in the source config, I believe Sailpoint Azure AD connector sends this API information.

Can you do a SP-CONFIG export for that source via below endpoint and also GET source API call.
And in the response please search for “graph.microsoft.us” and let us know if you find a URI anywhere there for this search.
export-sp-config | SailPoint Developer Community
get-source | SailPoint Developer Community

@harshamin9

Yes, I’m able to find the Graph URI in the source export.

“msGraphResourceBase”: “https://graph.microsoft.us”.

But with the same base URL, I’m able to successfully aggregate groups from Azure Tenant, I face aggregation failure when we pull roles from Entra ID

Hello @chandramohans27
Feel free to raise this issue with support team, this needs to be looked into by FEDRAMP CONNECTOR TEAM.

1 Like

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.