Troubleshooting
This guide lists common symptoms, likely causes, and actions you can take before escalating to Cloudaware Support.
Directory or Subscription Status Is Red
Symptoms
- Azure Active Directory or a subscription shows a red status in Cloudaware Admin.
- Error messages mention authentication failures or insufficient permissions.
Checks
- In Azure portal, verify that:
- The app registration still exists and is not disabled.
- Certificates or client secrets used by Cloudaware are valid and not expired.
- In the app registration:
- Confirm that Azure Service Management and Microsoft Graph permissions are still present.
- Confirm that admin consent is granted.
- In Access control (IAM) (Management group or Subscription level):
- Confirm that the Cloudaware service principal still has
Reader(or higher) at the intended scopes.
- Confirm that the Cloudaware service principal still has
If secrets or certificates have changed, update credentials in Cloudaware and re‑test.
Subscriptions Appear as “Untracked”
Symptoms
- Subscriptions show under Untracked Subscriptions in Cloudaware Admin.
- No resources from these subscriptions appear in CMDB.
Cause
Automatically Discover Subscriptionswas not enabled for the Azure Active Directory during tenant setup.
Resolution
- In Cloudaware, review the tab Untracked Subscriptions → select the subscription(s) → click + Track selected.
Subscription Exists in Azure but Is Missing in Cloudaware
Symptoms
- Subscription exists in Azure but is not listed in Cloudaware Admin
- No resources from this subscription appear in CMDB.
Cause
- Cloudaware can see the subscription in the tenant but does not have
Reader(or equivalent) RBAC on that subscription.
Resolution
- In Azure portal → Subscriptions → subscription → Access control (IAM):
- Assign the
Readerrole to the Cloudaware app for that subscription.
- Assign the
- Wait for the next discovery cycle and confirm that the subscription moves to healthy status.
Key Vault, AKS, Reservations, or Intune Data Is Missing
Symptoms
- Base resources (VMs, storage, networks) appear, but specialized services are empty.
Checks
- Review Least Privilege and confirm that:
- Key Vault access policies with
Listare configured for keys/secrets/certificates. - The
Reservations Readerrole is assigned where reservations are in scope. Azure Kubernetes Service Cluster User Role(or equivalent) is set for AKS subscriptions.- Intune Graph permissions (
DeviceManagementManagedDevices.Read.All, etc.) are present and have admin consent.
- Key Vault access policies with
Changes to Graph or RBAC can take time to propagate; allow at least 15–30 minutes and re‑check.
Authentication Errors After Credential Rotation
Symptoms
- Integration worked previously but started failing after a change.
- Cloudaware Admin errors mention invalid client secret, certificate, or login failures.
Resolution
- If you rotated a client secret:
- Update the secret value in Cloudaware Admin and save.
- If you replaced a certificate:
- Upload the new certificate in Azure and ensure the same certificate is uploaded/configured in Cloudaware.
- Retain at least one valid credential during transitions to avoid downtime.
Still Stuck?
If issues persist after these checks, collect the following details:
- Screenshots of the app registration permissions and role assignments.
- Example subscription IDs and resource IDs that are missing.
- The error text from Cloudaware.
Contact Cloudaware Support at support@cloudaware.com and include these details to help shorten time to resolution.