Something went wrong MDI instance cannot be created

EnterpriseArchitect 5,136 Reputation points
2024-07-02T15:45:31.0433333+00:00

How can I fix the below issue?

User's image

The MDI instance on my existing tenant was not completed before by my predecessor, hence I deleted the three builtin groups, however, I am still stuck at the above issue, despite the gMSA has been created and the agent installed on my OnPremise AD DS.

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
11,384 questions
PowerShell
PowerShell
A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
2,309 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
180 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,532 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Givary-MSFT 30,756 Reputation points Microsoft Employee
    2024-07-08T08:48:28.55+00:00

    @EnterpriseArchitect Apologies for the delayed response, just wanted to check does the issue still persists?

    Were you able to delete the MDI groups and re-create the instance?

    Check the required permissions/pre-reqs required to create MDI instance

    https://learn.microsoft.com/en-us/defender-for-identity/role-groups#required-permissions-defender-for-identity-in-microsoft-defender-xdr

    https://learn.microsoft.com/en-us/defender-for-identity/deploy/deploy-defender-identity

    Let me know if you have any questions, feel free to post back.

    1 person found this answer helpful.