question

MaartendeVreeze-8260 avatar image
0 Votes"
MaartendeVreeze-8260 asked MarileeTurscak-MSFT answered

PTA Staged rollout Manage groups not available.

When we try to enable Azure Pass through Authenication - Staged rollout option. "Manage Groups" option is not getting enabled. Its greyed out.

Trying to setup Stage Rollout for PTA, using this manual: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-staged-rollout

Works fine until step: Enable Staged Rollout, step 2. You can enable the feature, but the manage groups won't become clickable. For PasswordHash and Seamless-SSO this works.
I have seen this behaviour in multiple tenants.

azure-ad-pass-through-authentication
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

MarileeTurscak-MSFT avatar image
0 Votes"
MarileeTurscak-MSFT answered

It won't work if you don't have on-premises pass-through agents registered to the tenant. Can you make sure that these are registed? https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-security-deep-dive

Do you see an error when you enable it? Or does it turn on successfully with no error, but the manage groups is still unclickable?

Make sure you try with a global admin account.

If you can reproduce this issue please send me a screenshot or video to AzCommunity@microsoft.com and I will get someone from the product group involved.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

MaartendeVreeze-8260 avatar image
0 Votes"
MaartendeVreeze-8260 answered MaartendeVreeze-8260 edited

I have two servers which have the PTA-agent successfully installed. These servers also show up in the portal (Home -> Azure Active Directory -> Azure AD Connect -> Pass-Through Authentication.).

I can enable / disable it without problems, it reports as successful, but Manage Groups is unclickable.
My account is global admin account.

I have sent additional information to the email address you mentioned.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

MaartendeVreeze-8260 avatar image
0 Votes"
MaartendeVreeze-8260 answered MaartendeVreeze-8260 edited

And there are more reports about this issue:

And I have another AzureAD tenant, we have enabled PTA staged roll out about two months ago. At that moment I was able to select the groups for staged roll out. I have checked it again. Also in this tenant Manage Groups not available.



5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

RuudS-4804 avatar image
0 Votes"
RuudS-4804 answered

I also have the same problem.
Agent registerd ok.
PTA enabled OK
Manage groups greyed out

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

MaartendeVreeze-8260 avatar image
0 Votes"
MaartendeVreeze-8260 answered

@MarileeTurscak Did you receive the information I have sent to azcommunity@microsoft.com?
Do you need additional information? Do you have an update?

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

MarileeTurscak-MSFT avatar image
0 Votes"
MarileeTurscak-MSFT answered

I'm sorry for the delay! I was out of office and just saw your response.

I just heard from engineering that this fix was put in to production yesterday. I would suggest trying again to see if this works.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.