<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Service Principal issues on Panorama Plugin for Azure in Integration Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/integration-discussions/service-principal-issues-on-panorama-plugin-for-azure/m-p/537133#M167</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Panorama&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;OS version 10.1.x&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Azure plugin 3.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can the below error, when trying to validate Service Principle&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Failed to validate credentials with error - Failed to validated Azure Monitoring permissions and Deployment permissions. Error: Failed to validate monitoring permissions. Error: Missing permission for &amp;amp;#39;Microsoft.Compute/virtualMachines/read&amp;amp;#39;, please update service principal.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Azure App is set with "reader"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can anyone explain more what to check or what the problem could be ?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Mar 2023 17:42:02 GMT</pubDate>
    <dc:creator>CStorrar</dc:creator>
    <dc:date>2023-03-30T17:42:02Z</dc:date>
    <item>
      <title>Service Principal issues on Panorama Plugin for Azure</title>
      <link>https://live.paloaltonetworks.com/t5/integration-discussions/service-principal-issues-on-panorama-plugin-for-azure/m-p/404273#M66</link>
      <description>&lt;P&gt;While setting up the Service Principal on Panorama Plugin for Azure, even though the IAM role of reader seems to be properly defined in Azure we get this error message during the validation phase:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;ERROR: Validation of #######-####-####-############ failed with msg Failed to validate credentials with error - Failed to validated Azure Monitoring permissions and Deployment permissions. Error: Failed to validate monitoring permissions. Error: Missing permission for 'Microsoft.Compute/virtualMachines/read', please update service principal.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Any ideea what else might cause this? Most probably is something very simple we are missing but we run out of troubleshooting leads now and any suggestion will be highly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 16:34:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/integration-discussions/service-principal-issues-on-panorama-plugin-for-azure/m-p/404273#M66</guid>
      <dc:creator>cezarb</dc:creator>
      <dc:date>2021-04-30T16:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: Service Principal issues on Panorama Plugin for Azure</title>
      <link>https://live.paloaltonetworks.com/t5/integration-discussions/service-principal-issues-on-panorama-plugin-for-azure/m-p/476254#M130</link>
      <description>&lt;P&gt;Having the same issue, did you ever resolve this?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 10:42:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/integration-discussions/service-principal-issues-on-panorama-plugin-for-azure/m-p/476254#M130</guid>
      <dc:creator>MichaelBredell</dc:creator>
      <dc:date>2022-03-28T10:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: Service Principal issues on Panorama Plugin for Azure</title>
      <link>https://live.paloaltonetworks.com/t5/integration-discussions/service-principal-issues-on-panorama-plugin-for-azure/m-p/476608#M131</link>
      <description>&lt;P&gt;Yes, I'm having this issue as well and have a TAC case open, but so far no luck - please post if you find a solution!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 14:19:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/integration-discussions/service-principal-issues-on-panorama-plugin-for-azure/m-p/476608#M131</guid>
      <dc:creator>Blake_Wofford</dc:creator>
      <dc:date>2022-03-29T14:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: Service Principal issues on Panorama Plugin for Azure</title>
      <link>https://live.paloaltonetworks.com/t5/integration-discussions/service-principal-issues-on-panorama-plugin-for-azure/m-p/480140#M135</link>
      <description>&lt;DIV&gt;PLUG-7780 -&amp;nbsp;&lt;SPAN&gt;When the monitoring definition service principle for VM monitoring in Azure is configured correctly on the Panorama plugin for Azure 3.0.x with PAN-OS 10.0.x, the service principal validation check displays as failed under&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV&gt;Panorama &amp;gt; Azure &amp;gt;&amp;nbsp;Setup &amp;gt; Service Principal&lt;/DIV&gt;&lt;/DIV&gt;.&lt;/DIV&gt;&lt;P&gt;Please find the list of actions/permissions required to support monitoring for the Azure 3.0.1 plugin below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The list of permissions required to enable monitoring are as below:&lt;/P&gt;&lt;P&gt;"actions": [&lt;BR /&gt;"Microsoft.Compute/virtualMachines/read",&lt;BR /&gt;"Microsoft.Network/networkInterfaces/read",&lt;BR /&gt;"Microsoft.Network/virtualNetworks/read",&lt;BR /&gt;"Microsoft.Network/locations/serviceTags/read",&lt;BR /&gt;"Microsoft.Network/loadBalancers/read",&lt;BR /&gt;"Microsoft.Resources/subscriptions/resourcegroups/read",&lt;BR /&gt;"Microsoft.Network/publicIPAddresses/read"&lt;BR /&gt;]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With these permissions assigned to a service principal, validation will fail but the monitoring functionality is not affected and the 3.0.1 plugin will continue to function as designed.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 10:21:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/integration-discussions/service-principal-issues-on-panorama-plugin-for-azure/m-p/480140#M135</guid>
      <dc:creator>dmaynard</dc:creator>
      <dc:date>2022-04-13T10:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: Service Principal issues on Panorama Plugin for Azure</title>
      <link>https://live.paloaltonetworks.com/t5/integration-discussions/service-principal-issues-on-panorama-plugin-for-azure/m-p/537133#M167</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Panorama&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;OS version 10.1.x&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Azure plugin 3.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can the below error, when trying to validate Service Principle&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Failed to validate credentials with error - Failed to validated Azure Monitoring permissions and Deployment permissions. Error: Failed to validate monitoring permissions. Error: Missing permission for &amp;amp;#39;Microsoft.Compute/virtualMachines/read&amp;amp;#39;, please update service principal.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Azure App is set with "reader"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can anyone explain more what to check or what the problem could be ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 17:42:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/integration-discussions/service-principal-issues-on-panorama-plugin-for-azure/m-p/537133#M167</guid>
      <dc:creator>CStorrar</dc:creator>
      <dc:date>2023-03-30T17:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: Service Principal issues on Panorama Plugin for Azure</title>
      <link>https://live.paloaltonetworks.com/t5/integration-discussions/service-principal-issues-on-panorama-plugin-for-azure/m-p/997842#M192</link>
      <description>&lt;P&gt;Good afternoon, I have the same issue and I read that the application should have the "Reader" role. Is this correct? Could you please guide me on how to grant those permissions from the Azure portal?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 19:32:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/integration-discussions/service-principal-issues-on-panorama-plugin-for-azure/m-p/997842#M192</guid>
      <dc:creator>agagliardi</dc:creator>
      <dc:date>2024-12-11T19:32:43Z</dc:date>
    </item>
  </channel>
</rss>

