> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/content-collections/connect/connect-cloud-accounts/onboard-your-azure-account/troubleshoot-azure-account-onboarding.md).

# Troubleshoot Azure Account Onboarding

During the onboarding process and after you may encounter some issues that may lead to issues with retrieving logs, metadata, scanning network traffic or identifying vulnerabilities on your Azure resources.

Use this troubleshooting guide to find tips to identify, detect, and remediate any issues that may arise.

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Issue</strong></td><td><strong>Troubleshooting Tip</strong></td></tr><tr><td><strong>Azure Onboarding Terraform Issues</strong></td><td></td></tr><tr><td><p>Error below when running the Azure onboarding Terraform template on your local system or Azure Cloud shell.</p><pre><code>Could not retrieve the list of available versions for provider hashicorp/random: ... must use terraform init -upgrade to allow selection of new version
</code></pre></td><td>Your local system or Azure Cloud shell still has the old versions of Terraform libraries installed. To update to the new terraform library versions, execute <strong>terraform init -upgrade command</strong> in the directory where you want to execute terraform. Next, execute <strong>terraform apply</strong> to run Terraform.</td></tr><tr><td><p>Following error during <strong>terraform apply</strong> step, while running Azure onboarding Terraform template on your local system or Azure Cloud Shell.</p><pre><code>Access Denied error with 403 status code
</code></pre></td><td>Ensure that the you have been assigned the <a href="https://learn.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin#elevate-access-for-a-global-administrator">Global Administrator</a> role on Azure Active Directory (AD).</td></tr><tr><td><p>Following error during terraform apply step, while running Azure onboarding Terraform template on your local system or Azure Cloud Shell.</p><pre><code>data.azurerm_management_group.tenant_root_group: Reading...

Error: reading Management Group "\<Tenant ID>": managementgroups.Client#Get: Failure responding to request: StatusCode=404 -- Original Error: autorest/azure: Service returned an error. Status=404 Code="NotFound" Message="'/providers/Microsoft.Management/managementGroups/\<tenant-id>' not found"

with data.azurerm\_management\_group.tenant\_root\_group,
on prisma-cloud-azure-terraform.tf.json line 26, in data.azurerm\_management\_group.tenant\_root\_group: </code></pre></td><td>The Azure tenant does not have Management Group service enabled or the user running the terraform command does not have elevated accesss to Azure subscription. Ensure that the Global Administrator user has <a href="https://learn.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin#elevate-access-for-a-global-administrator">elevated access</a> to the Azure subscription.</td></tr><tr><td><p>Following error during <strong>terraform apply</strong> step, while running Azure onboarding Terraform template on your local system or Azure Cloud Shell</p><pre><code>Error: Could not create service principal

with azuread\_service\_principal.prisma\_cloud\_sp,
on terraform (1).tf line 124, in resource "azuread\_service\_principal" "prisma\_cloud\_sp":
124: resource "azuread\_service\_principal" "prisma\_cloud\_sp" {

ServicePrincipalsClient.BaseClient.Post(): unexpected status 403 with OData error: Authorization\_RequestDenied: When using this permission, the backing application of the service principal being created must
in the local tenant

Error: Adding password for application with object ID "89d14baf-ab16-4a66-a2c8-1719b6085d28" </code></pre></td><td>Ensure that the you have been assigned the <a href="https://learn.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin#elevate-access-for-a-global-administrator">Global Administrator</a> role on Azure Active Directory (AD).</td></tr><tr><td><strong>Azure Cloud Account Status related issues</strong></td><td></td></tr><tr><td><p>Cloud account status shows the following error / warning for under Config on the Cloud Account Status page.</p><pre><code>Prisma Cloud application is not assigned following role(s): User.Read.All, Application.Read.All, Reports.Read.All, Directory.Read.All, Domain.Read.All, Group.Read.All, GroupMember.Read.All, Policy.Read.All </code></pre></td><td><p>Ensure that you have granted <strong>Admin Consent</strong> to all the <strong>Microsoft Graph API Permissions</strong> on the Azure Portal and confirm that the Status column for all the API Permissions has a green checkmark.</p><p>Steps: Go to Azure tenant > App registrations > Select the Prisma Cloud app > API permissions > Grant Admin conceent for Tenant (check mark)</p><p><img src="/files/Fk4zwkiKvIY68Zac8Eqb" alt="" data-size="original"></p></td></tr><tr><td>Cloud account status shows error for multiple components.</td><td><p>Verify that you have created the required roles, added the role assignments and selected <strong>Grant Admin Consent</strong> for API permissions If the issue still persists after you have eliminated the items above as an issue, confirm that you have given Prisma Cloud the appropriate <strong>Enterprise Application Object ID</strong>:</p><ol><li>Navigate to Enterprise <strong>Applications > All Applications</strong>.</li><li>Search for your application in the Search box and copy the <strong>Object ID</strong>.</li><li>Copy and paste it in <strong>Enterprise Application Object ID</strong> in the Prisma Cloud Azure Onboarding workflow and ensure that all the statuses are green in the <strong>Review Status</strong> dialog.</li></ol><p><img src="/files/8P63mKRaRsnpsv5WKlIi" alt="" data-size="original"></p></td></tr><tr><td><p>Following permissions are shown as missing under Agent Based Workload Protection component under the account onboarding status tab:</p><pre><code>Prisma Cloud is not assigned the following data actions:
"Microsoft.KeyVault/vaults/keys/unwrapaction"
"Microsoft.KeyVault/vaults/keys/wrapaction" </code></pre></td><td><p>Verify that <strong>Key Vault Crypto Service Encryption User</strong> built in role is assigned at <strong>Tenant/Subscription</strong> scope to the Prisma Cloud app registration.</p><p><img src="/files/JwrK8gQEDWynuUigQrax" alt="" data-size="original"></p></td></tr><tr><td><p>Cloud account status displays red and includes the following error message:</p><pre><code>Authentication failed. Azure Subscription not found. </code></pre></td><td>Login to the Azure Portal and check whether the Azure subscription is deleted or disabled. Prisma Cloud cannot monitor the subscription if it is deleted or disabled.</td></tr><tr><td>A child account of an already added Tenant on Prisma Cloud is modified on the Azure Portal, but the change is not reflected in Prisma Cloud under <strong>Management Groups and Subscriptions</strong> of the already added Tenant.</td><td>It can take up to six hours for new child account information to be added, updated, or deleted in Prisma Cloud.</td></tr><tr><td><strong>Azure Flow Logs configuration related issues</strong></td><td></td></tr><tr><td><strong>Ingest and Monitor Network Security Group Flow Logs</strong> checkbox is checked during onboarding and you are still facing issues with Flow Logs Ingestion.</td><td><p><strong>Check whether Azure flow logs are being generated</strong> and written to the storage account:</p><ol><li>Log in to the Azure portal.</li><li>Select Storage Accounts and select the storage account that you want to check.</li><li>Select Blobs > Blob Service and navigate through the folders to find the .json files. These are the flow logs that Prisma Cloud ingests.</li></ol><p><strong>Check that you have created storage accounts in the same regions as the Network Security Groups</strong>.</p><p>Network Security Group (NSG) flow logs are a feature of Network Watcher that allows you to view information about ingress and egress IP traffic through an NSG. Azure flow logs must be stored within a storage account in the same region as the NSG.</p><ol><li>Log in to Prisma Cloud.</li><li><p>Select <strong>Investigate</strong> and enter the following RQL query:</p><pre><code>network from vpc.flow\_record where source.publicnetwork IN ( 'Internet IPs', 'Suspicious IPs') AND bytes > 0 </code></pre><p>This query allows you to list all network traffic from the Internet or from Suspicious IP addresses with over 0 bytes of data transferred to a network interface on any resource on any cloud environment.</p></li></ol><p><strong>Verify that you have enabled Network Watcher instance</strong>.</p><p>The Network Watcher is required to generate flow logs on Azure.</p><ol><li>Log in to the Azure portal and select <strong>Network Watcher > Overview</strong> and verify that the status is <strong>Enabled</strong>.</li><li>Log in to Prisma Cloud.</li><li><p>Select <strong>Investigate</strong> and enter the following RQL query:</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-network-nsg-list' addcolumn pr provisioningState </code></pre></li></ol><p><strong>Check that you have enabled flow logs on the NSGs</strong>.</p><ol><li>Log in to the Azure portal, and select <strong>Network Watcher > NSG Flow Logs</strong> and verify that the status is <strong>Enabled</strong>.</li><li>Log in to Prisma Cloud.</li><li><p>Select <strong>Investigate</strong> and enter the following RQL query:</p><pre><code>network from vpc.flow\_record where source.publicnetwork IN ('Internet IPs', 'Suspicious IPs') AND bytes > 0 </code></pre><p>This query allows you to list all network traffic from the Internet or from Suspicious IP addresses with over 0 bytes of data transferred to a network interface on any resource on any cloud environment.</p></li></ol></td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/content-collections/connect/connect-cloud-accounts/onboard-your-azure-account/troubleshoot-azure-account-onboarding.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
