Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Issue with sharing a MDA #9248

Closed
1 task done
myatix opened this issue Nov 12, 2024 · 16 comments
Closed
1 task done

Issue with sharing a MDA #9248

myatix opened this issue Nov 12, 2024 · 16 comments
Assignees
Labels
bug Something isn't working coe-starter-kit CoE Starter Kit issues product-change

Comments

@myatix
Copy link

myatix commented Nov 12, 2024

Does this bug already exist in our backlog?

  • I have checked and confirm this is a new bug.

Describe the issue

We recently installed a completely fresh install of the CoE Starter Kit with a new environment and have been having a number of issues.

One issue is with access to the Maker Command Center. Users are getting the following access error:

Image

I have checked that the maker dashboard has been shared and as far as I can see it seems to have been.

Image

Image

I have also confirmed the users are a member of the M365 Group.

I am however able to access the maker dashboard with the Installation Administrator account???

Expected Behavior

I would expect users to be able to access the Maker Command Center if they are a member of the makers group in Entra ID.

What solution are you experiencing the issue with?

Core

What solution version are you using?

4.45

What app or flow are you having the issue with?

Make Command Center

What method are you using to get inventory and telemetry?

Cloud flows

Steps To Reproduce

No response

Anything else?

No response

@myatix myatix added bug Something isn't working coe-starter-kit CoE Starter Kit issues labels Nov 12, 2024
@Jenefer-Monroe
Copy link
Collaborator

Have you given that team access to the SR?

@myatix
Copy link
Author

myatix commented Nov 13, 2024

Hi Jenefer,

I presume you mean the below:
Image

As you can see the Makers Team has the the Power Platform Maker SR

Image
Image

Should the "Power Platform CoE - Maker Team" not have both the "Power Platform Maker SR" and the "Basic user" role?

We have installed the CoE using the wizard so I presume that the necessary permissions have been granted during the install?

Where else do I need to check!

@myatix
Copy link
Author

myatix commented Nov 14, 2024

@Jenefer-Monroe I think I have discovered the "Power Platform CoE" - Maker Team. (It would appear that the group in the error message is not the same group as the M365 Group specified in the Power Platform Team) Which seems quite strange...

Image

Image

however the group that is assigned to the Power Platform Team is as follows.
Image

Image

I am not sure how this has occurred but this definitely appears to be the problem.

Image

Is there an easy way to fix this without resetting the whole environment??? Your assistance would be appreciated!

@Jenefer-Monroe
Copy link
Collaborator

It sounds like the Maker group is just misconfigured, is that what you are saying?
If so, easy to fix.

  1. Update value in the kit
    You can use our CoE Admin Command Center app to update environment variables.
    I suggest you restart the Admin | Add Maker to Group flow after you do this to be sure the value is not cached in that flow.
    Then going forward new makers will be added to this correct group.
    Image

  2. Manually migrate existing makers
    We do not have a flow to migrate users from the incorrect group to this corrected group, so you will want to go make sure all your makers are in it. You can either refer to the incorrect group or you can refer to the Maker table.
    Image

@myatix
Copy link
Author

myatix commented Nov 15, 2024

Hi @Jenefer-Monroe,

There is something VERY strange going on here... Our Power Platform Team ("Power Platform CoE - Maker Team") and all the Environment variables point at the correct Entra ID Group ID, as you can see from all the screenshots above.

HOWEVER...

The Maker Apps are all trying to authenticate with a completely different Microsoft 365 Group than the one specified in the Power Platform Team.

Group Shown in Power Platform Team = "Power Platform - Makers"
Image

Group being authenticated with "Power Platform - Admin - Test" (This is the group it is using despite having specified and showing the group above the solution simply uses the incorrect M365 Group?????)
Image

@Jenefer-Monroe
Copy link
Collaborator

Sorry it sounds like you are having issues with the product's SRs and Sharing, which is something outside of my ability to help debug. I think you'll need to have someone local assist who can explore and debug with you, and maybe contact product support if needed.

@myatix
Copy link
Author

myatix commented Nov 19, 2024

Hi @Jenefer-Monroe,

This is Microsoft's Unified Support Response...

Image

It feels a little like no one is taking ownership of this issue. I would agree with you that this appears to be a core Power Platform issue but they seem to think it is a CoE issue as can be seen above.

@Jenefer-Monroe
Copy link
Collaborator

Sorry I'm a little lost. Let's forget the kit for a minute and see if you can explain the situation without the context of the kit.

You have a team in the envt : Power Platform CoE - Maker Team
You have associated this team with an entra group: Power Platform CoE - Makers
You have given this team access to the SR: Power Platform Maker SR
You've shared the MDA with the Team

Then people from the team do not have access?
Is that the issue?

@Jenefer-Monroe
Copy link
Collaborator

I think your issue is here
Image

Apps need to be shared with the entra group not the envt team.
Can you try that?

@myatix
Copy link
Author

myatix commented Nov 22, 2024

Hi @Jenefer-Monroe,

Yes that is completely correct... So you are saying we should share it with the M365 Group not the "Power Platform - Maker Team"?

We didn't create the "Power Platform - Maker Team"??? It was done as part of the install wizard. We have done the full install with the Installation wizard. So I presumed that the Team was part of the automated setup that occurs via the installation wizard???
Where does that Power Platform Team ("Power Platform CoE - Maker Team") get created?

@myatix
Copy link
Author

myatix commented Nov 22, 2024

Sorry I'm a little lost. Let's forget the kit for a minute and see if you can explain the situation without the context of the kit.

You have a team in the envt : Power Platform CoE - Maker Team You have associated this team with an entra group: Power Platform CoE - Makers You have given this team access to the SR: Power Platform Maker SR You've shared the MDA with the Team

Then people from the team do not have access? Is that the issue?

Yes that is correct but we didn't create the "Power Platform CoE - Maker Team" this was created as part of the installation wizard process I presume.

@Jenefer-Monroe
Copy link
Collaborator

It looks like the product behavior changed here and this action
Image

Which used to grant the group permission (as seen here for a case when run in the past)
Image

Now does not and only shares with the team.
You will need to manually share the app with your group today instead and I will add to hte backlog investigating this.

@Jenefer-Monroe Jenefer-Monroe changed the title [CoE Starter Kit - BUG] Share Maker Dashboard Relating PP Team with SR no longer shares app - need to update our tooling Nov 25, 2024
@Jenefer-Monroe Jenefer-Monroe removed their assignment Nov 25, 2024
@myatix
Copy link
Author

myatix commented Nov 26, 2024

Hi @Jenefer-Monroe,

I have tried manually removing the Power Platform Team and adding the group directly to the Makers Dashboard but the M365 Group gets automatically replaced by the Power Platform Team. What is really worrying however is how the Power Platform Team shows that it is mapped to the correct M365 Group but actually Mapped to a completely different M365 Entra ID group. That is a bit worrying if you ask me from a security prespective.

@Jenefer-Monroe
Copy link
Collaborator

Ok thanks for pointing out the name changes when added the permissions via the UX as well. I do repro this too.
I just made new Entra groups and ran the SetupWizard>ShareApps flow (which is called from the setup wizard) and it worked.
Then when I went to do it again with a case to match yours it failed, I think due to the sync between Entra and DV.

Let's level set to be sure we can find where the issue is. I do still suspect the issue is with the product but we shall see

All this works for me, please check that this part is all correct for you too

Entra groups

Which one: ADMIN
Name: Power Platform - Admin - Test
GUID: XXX-5d6aa101
Mail: PowerPlatformAdminTest@xxxxx
Members - 3
Owners - you are an owner

Which one: MAKER
Name: Power Platfform CoE - Makers
GUID: XXX-84ee5fc7
Mail: PowerPlatfformMakers@xxxxx
Members - 408 (including a specific test user we will use)
Owners - you are an owner

CoE Env Vars

Validate you have the correct values for these assigned
Image
Image

Teams

Name: Power Platform - Admin - Test Team
Name: Power Platfform CoE - Makers Team

Hit Edit for each and validate and validate its correctly configured to the group above
Image
Image

Click on the name to open in a form, GUID should be the correct Entra group
Image

App

App itself Shared with both SRs
Image

Each team shared with its SR
Image

What is broken for me

The team member lists are empty. Will test back in several hours to see if the sync is still broken
Image

@Jenefer-Monroe Jenefer-Monroe self-assigned this Nov 27, 2024
@Jenefer-Monroe Jenefer-Monroe changed the title Relating PP Team with SR no longer shares app - need to update our tooling Issue with sharing a MDA Nov 27, 2024
@Jenefer-Monroe
Copy link
Collaborator

For me, I had to wait ~12-18 hours but then the team finally sunk up with entra and now its working.

Image

Please let me know where in the above you differ.

@Jenefer-Monroe
Copy link
Collaborator

closing out as no further action for starter kit team

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working coe-starter-kit CoE Starter Kit issues product-change
Projects
Status: Done
Development

No branches or pull requests

2 participants