Cannot add or remove Registered Device Owner despite global admin and Device.ReadWrite.All
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 30/100
- Tipo di issue
- Bug
- Chiarezza
- Da chiarire
- Stato di attività
- Ferma
- Stack tecnologico
- powershell
- Ambito
- api, authentication, authorization
Direzione di ricerca
Inizia riproducendo le chiamate New-MgDeviceRegisteredOwnerByRef e Remove-MgDeviceRegisteredOwnerDirectoryObjectByRef verso gli endpoint POST e DELETE registeredOwners/$ref mostrati nel report, usando gli scope delegati elencati. Confronta le autorizzazioni richieste con la risposta 403; l'attività è completata quando il proprietario può essere aggiunto e rimosso oppure l'errore identifica l'autorizzazione mancante.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Describe the bug
I am trying to add and remove device owners using New-MgDeviceRegisteredOwnerByRef and Remove-MgDeviceRegisteredOwnerDirectoryObjectByRef. But I am getting "Insufficient privileges to complete the operation."
This is despite confirming that I am Global Administrator and have the Device.ReadWrite.All and Directory.ReadWrite.All scopes.
(I can read the device owner fine.)
Expected behavior
I expect the owner of the device to actually change.
Secondly, I want the error message to point to what permission is needed so I can activate that.
How to reproduce
$ownermg = Get-MgUser -UserId "[email protected]"
$devicemg = Get-MgDevice -Filter "displayName eq 'win11'"
(Get-MgUser -UserId (Get-MgDeviceRegisteredOwner -DeviceId $devicemg.id).id) | Select-Object DisplayName, UserPrincipalName
New-MgDeviceRegisteredOwnerByRef -DeviceId $devicemg.id -BodyParameter @{ "@odata.id" = "https://graph.microsoft.com/v1.0/users/$($ownermg.id)" } -Debug
{error insufficient privileges}
Remove-MgDeviceRegisteredOwnerDirectoryObjectByRef -DeviceId $devicemg.id -DirectoryObjectId $ownermg.id -Debug
{error insufficient privileges}
SDK Version
2.25.0 and 2.28.0
Latest version known to work for scenario above?
n/a
Known Workarounds
none
Debug output
Click to expand log for "add/new"
DEBUG: [CmdletBeginProcessing]: - New-MgDeviceRegisteredOwnerByRef begin processing with parameterSet 'Create'.
DEBUG: [Authentication]: - AuthType: 'Delegated', TokenCredentialType: 'InteractiveBrowser', ContextScope: 'CurrentUser', AppName: 'Microsoft Graph Command Line Tools'.
DEBUG: [Authentication]: - Scopes: [AdministrativeUnit.Read.All, AdministrativeUnit.ReadWrite.All, Device.ReadWrite.All, Directory.Read.All, Directory.ReadWrite.All, Group.Read.All, Group.ReadWrite.All, IdentityRiskEvent.Read.All, IdentityRiskyUser.ReadWrite.All, openid, Policy.Read.All, PrivilegedAccess.ReadWrite.AzureADGroup, PrivilegedAssignmentSchedule.ReadWrite.AzureADGroup, profile, RoleAssignmentSchedule.ReadWrite.Directory, RoleEligibilitySchedule.ReadWrite.Directory, RoleManagement.ReadWrite.Directory, RoleManagementPolicy.Read.AzureADGroup, RoleManagementPolicy.ReadWrite.AzureADGroup, Team.ReadBasic.All, TeamMember.Read.All, User.Read, User.Read.All, User.ReadWrite.All, email].
Confirm
Are you sure you want to perform this action?
Performing the operation "New-MgDeviceRegisteredOwnerByRef_Create" on target "Call remote 'POST /devices/{device-id}/registeredOwners/$ref' operation".
[Y] Yes [A] Yes to All [N] No [L] No to All [S] Suspend [?] Help (default is "Y"): y
DEBUG: ============================ HTTP REQUEST ============================
HTTP Method:
POST
Absolute Uri:
https://graph.microsoft.com/v1.0/devices/{guid}/registeredOwners/$ref
Headers:
FeatureFlag : 00000003
Cache-Control : no-store, no-cache
User-Agent : Mozilla/5.0,(Windows NT 10.0; Microsoft Windows 10.0.22631; en-US),PowerShell/2025.0.0
SdkVersion : graph-powershell/2.28.0
client-request-id : {guid}
Accept-Encoding : gzip,deflate,br
Body:
{
"@odata.id": "https://graph.microsoft.com/v1.0/users/{guid}"
}
DEBUG: ============================ HTTP RESPONSE ============================
Status Code:
Forbidden
Headers:
Cache-Control : no-cache
Vary : Accept-Encoding
Strict-Transport-Security : max-age=31536000
request-id : {guid}
client-request-id : {guid}
x-ms-ags-diagnostic : {"ServerInfo":{"DataCenter":"US","Slice":"E","Ring":"4","ScaleUnit":"002","RoleInstance":"CH01"}}
x-ms-resource-unit : 1
Date : Wed, 21 May 2025 16:58:02 GMT
Body:
{
"error": {
"code": "Authorization_RequestDenied",
"message": "Insufficient privileges to complete the operation.",
"innerError": {
"date": "2025-05-21T16:58:02",
"request-id": "{guid}",
"client-request-id": "{guid}"
}
}
}
New-MgDeviceRegisteredOwnerByRef_Create: Insufficient privileges to complete the operation.
Status: 403 (Forbidden)
ErrorCode: Authorization_RequestDenied
Date: 2025-05-21T16:58:02
Headers:
Cache-Control : no-cache
Vary : Accept-Encoding
Strict-Transport-Security : max-age=31536000
request-id : {guid}
client-request-id : {guid}
x-ms-ags-diagnostic : {"ServerInfo":{"DataCenter":"US","Slice":"E","Ring":"4","ScaleUnit":"002","RoleInstance":"CH01"}}
x-ms-resource-unit : 1
Date : Wed, 21 May 2025 16:58:02 GMT
Recommendation: See service error codes: https://learn.microsoft.com/graph/errors
DEBUG: [CmdletEndProcessing]: - New-MgDeviceRegisteredOwnerByRef end processing.
Click to expand log for "remove"
DEBUG: [CmdletBeginProcessing]: - Remove-MgDeviceRegisteredOwnerDirectoryObjectByRef begin processing with parameterSet 'Delete'.
DEBUG: [Authentication]: - AuthType: 'Delegated', TokenCredentialType: 'InteractiveBrowser', ContextScope: 'CurrentUser', AppName: 'Microsoft Graph Command Line Tools'.
DEBUG: [Authentication]: - Scopes: [AdministrativeUnit.Read.All, AdministrativeUnit.ReadWrite.All, Device.ReadWrite.All, Directory.Read.All, Directory.ReadWrite.All, Group.Read.All, Group.ReadWrite.All, IdentityRiskEvent.Read.All, IdentityRiskyUser.ReadWrite.All, openid, Policy.Read.All, PrivilegedAccess.ReadWrite.AzureADGroup, PrivilegedAssignmentSchedule.ReadWrite.AzureADGroup, profile, RoleAssignmentSchedule.ReadWrite.Directory, RoleEligibilitySchedule.ReadWrite.Directory, RoleManagement.ReadWrite.Directory, RoleManagementPolicy.Read.AzureADGroup, RoleManagementPolicy.ReadWrite.AzureADGroup, Team.ReadBasic.All, TeamMember.Read.All, User.Read, User.Read.All, User.ReadWrite.All, email].
Confirm
Are you sure you want to perform this action?
Performing the operation "Remove-MgDeviceRegisteredOwnerDirectoryObjectByRef_Delete" on target "Call remote 'DELETE /devices/{device-id}/registeredOwners/{directoryObject-id}/$ref' operation".
[Y] Yes [A] Yes to All [N] No [L] No to All [S] Suspend [?] Help (default is "Y"): y
DEBUG: ============================ HTTP REQUEST ============================
HTTP Method:
DELETE
Absolute Uri:
https://graph.microsoft.com/v1.0/devices/{guid}/registeredOwners/{guid}/$ref
Headers:
FeatureFlag : 00000003
Cache-Control : no-store, no-cache
User-Agent : Mozilla/5.0,(Windows NT 10.0; Microsoft Windows 10.0.22631; en-US),PowerShell/2025.0.0
SdkVersion : graph-powershell/2.28.0
client-request-id : {guid}
Accept-Encoding : gzip,deflate,br
Body:
DEBUG: ============================ HTTP RESPONSE ============================
Status Code:
Forbidden
Headers:
Cache-Control : no-cache
Vary : Accept-Encoding
Strict-Transport-Security : max-age=31536000
request-id : {guid}
client-request-id : {guid}
x-ms-ags-diagnostic : {"ServerInfo":{"DataCenter":"US","Slice":"E","Ring":"4","ScaleUnit":"002","RoleInstance":"CH01"}}
x-ms-resource-unit : 1
Date : Wed, 21 May 2025 16:58:09 GMT
Body:
{
"error": {
"code": "Authorization_RequestDenied",
"message": "Insufficient privileges to complete the operation.",
"innerError": {
"date": "2025-05-21T16:58:10",
"request-id": "{guid}",
"client-request-id": "{guid}"
}
}
}
Remove-MgDeviceRegisteredOwnerDirectoryObjectByRef_Delete: Insufficient privileges to complete the operation.
Status: 403 (Forbidden)
ErrorCode: Authorization_RequestDenied
Date: 2025-05-21T16:58:10
Headers:
Cache-Control : no-cache
Vary : Accept-Encoding
Strict-Transport-Security : max-age=31536000
request-id : {guid}
client-request-id : {guid}
x-ms-ags-diagnostic : {"ServerInfo":{"DataCenter":"US","Slice":"E","Ring":"4","ScaleUnit":"002","RoleInstance":"CH01"}}
x-ms-resource-unit : 1
Date : Wed, 21 May 2025 16:58:09 GMT
Recommendation: See service error codes: https://learn.microsoft.com/graph/errors
DEBUG: [CmdletEndProcessing]: - Remove-MgDeviceRegisteredOwnerDirectoryObjectByRef end processing.
Configuration
- OS: Windows 11 x64
- no docker
- PSVersion 7.5.1
- PSEdition Core
- GitCommitId 7.5.1
- OS Microsoft Windows 10.0.22631
- Platform Win32NT
- PSCompatibleVersions {1.0, 2.0, 3.0, 4.0…}
- PSRemotingProtocolVersion 2.3
- SerializationVersion 1.1.0.1
- WSManStackVersion 3.0
Other information
No response
- Lingua principale
- C#
- Stelle
- 902
- Fork
- 233
- Merge medio
- 1g 3h
- PR unite (30g)
- 24
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di microsoftgraph/msgraph-sdk-powershell
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
microsoftgraph/msgraph-sdk-powershell#3752 ·
I maintainer di solito rispondono entro 1 giorno
-
status:waiting-for-triage type:bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
microsoftgraph/msgraph-sdk-powershell#3751 ·
I maintainer di solito rispondono entro 1 giorno
-
Graph PowerShell 2.41.0: Connect-MgGraph fails loading System.Text.Json 10; downgrading to 2.40.0 resolvesForse già presa @svrooij l’ha presa oggi. ApertaNeeds: Attention :wave: status:waiting-for-triage type:bug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
microsoftgraph/msgraph-sdk-powershell#3810 · 3 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
status:waiting-for-triage type:feature
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
microsoftgraph/msgraph-sdk-powershell#3806 · 2 commenti · 1 reazione ·
I maintainer di solito rispondono entro 1 giorno
-
Microsoft.Graph.Authentication fails after removal and re-import in the same PowerShell sessionApertastatus:waiting-for-triage type:bug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 25/100
microsoftgraph/msgraph-sdk-powershell#3805 · 3 commenti ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di microsoftgraph/msgraph-sdk-powershell
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 66/100
shimat/opencvsharp#2154 ·
I maintainer di solito rispondono entro 1 giorno
-
subsystem: UI
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
Open-Systems-Pharmacology/PK-Sim#3812 ·
I maintainer di solito rispondono entro 1 giorno
-
[C#]:主页联网更新的提示投稿横幅指向错误Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
PCL-Community/PCL-CE#3652 ·
I maintainer di solito rispondono entro 1 giorno
-
bug effort:S P3
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
nightscout/nocturne#2012 ·
I maintainer di solito rispondono entro 1 giorno