Skip to main content

Troubleshooting

This guide lists common symptoms, likely causes, and actions you can take before escalating to Cloudaware Support.

Directory or Subscription Status Is Red

Symptoms

  • Azure Active Directory or a subscription shows a red status in Cloudaware Admin.
  • Error messages mention authentication failures or insufficient permissions.

Checks

  • In Azure portal, verify that:
    • The app registration still exists and is not disabled.
    • Certificates or client secrets used by Cloudaware are valid and not expired.
  • In the app registration:
    • Confirm that Azure Service Management and Microsoft Graph permissions are still present.
    • Confirm that admin consent is granted.
  • In Access control (IAM) (Management group or Subscription level):
    • Confirm that the Cloudaware service principal still has Reader (or higher) at the intended scopes.

If secrets or certificates have changed, update credentials in Cloudaware and re‑test.

Subscriptions Appear as “Untracked”

Symptoms

  • Subscriptions show under Untracked Subscriptions in Cloudaware Admin.
  • No resources from these subscriptions appear in CMDB.

Cause

  • Automatically Discover Subscriptions was not enabled for the Azure Active Directory during tenant setup.

Resolution

  • In Cloudaware, review the tab Untracked Subscriptions → select the subscription(s) → click + Track selected.

Subscription Exists in Azure but Is Missing in Cloudaware

Symptoms

  • Subscription exists in Azure but is not listed in Cloudaware Admin
  • No resources from this subscription appear in CMDB.

Cause

  • Cloudaware can see the subscription in the tenant but does not have Reader (or equivalent) RBAC on that subscription.

Resolution

  • In Azure portal → Subscriptions → subscription → Access control (IAM):
    • Assign the Reader role to the Cloudaware app for that subscription.
  • Wait for the next discovery cycle and confirm that the subscription moves to healthy status.

Key Vault, AKS, Reservations, or Intune Data Is Missing

Symptoms

  • Base resources (VMs, storage, networks) appear, but specialized services are empty.

Checks

  • Review Least Privilege and confirm that:
    • Key Vault access policies with List are configured for keys/secrets/certificates.
    • The Reservations Reader role is assigned where reservations are in scope.
    • Azure Kubernetes Service Cluster User Role (or equivalent) is set for AKS subscriptions.
    • Intune Graph permissions (DeviceManagementManagedDevices.Read.All, etc.) are present and have admin consent.

Changes to Graph or RBAC can take time to propagate; allow at least 15–30 minutes and re‑check.

Authentication Errors After Credential Rotation

Symptoms

  • Integration worked previously but started failing after a change.
  • Cloudaware Admin errors mention invalid client secret, certificate, or login failures.

Resolution

  • If you rotated a client secret:
    • Update the secret value in Cloudaware Admin and save.
  • If you replaced a certificate:
    • Upload the new certificate in Azure and ensure the same certificate is uploaded/configured in Cloudaware.
  • Retain at least one valid credential during transitions to avoid downtime.

Still Stuck?

If issues persist after these checks, collect the following details:

  • Screenshots of the app registration permissions and role assignments.
  • Example subscription IDs and resource IDs that are missing.
  • The error text from Cloudaware.

Contact Cloudaware Support at support@cloudaware.com and include these details to help shorten time to resolution.