Body
Summary
This article is a guide to Microsoft Azure, and how to troubleshoot using your Azure admin account. These resources can be reached from the Azure Portal, Exchange Admin Center, or the M365 Admin Center
Admin (ADM) Account
Working in the Azure Portal requires that you have certain privileges to do things. Based on our job responsibilities, we have some roles that are permanently granted, and others that require PIM (Privileged Identity Management) activation before they can be utilized.
Learn more about Azure AD Built-in Roles here: https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference
Permanent Roles
|
Role
|
Permission
|
|
USNH-HD-SignInLogview
|
Custom Role
|
|
Helpdesk Administrator
|
Can reset passwords for non-administrators and Helpdesk Administrators.
|
|
Service Support Administrator
|
Can read service health information and manage support tickets.
|
|
Message Center Reader
|
Can read security messages and updates in Office 365 Message Center only.
|
PIM (Privileged Identity Management) Roles
|
Role
|
Permission
|
|
Authentication Administrator
|
Can access to view, set and reset authentication method information for any non-admin user.
|
|
Reports Reader
|
Can read sign-in and audit reports.
|
|
Cloud Device Administrator
|
Can enable, disable, and delete devices in Azure AD and read Windows 10 BitLocker keys (if present) in the Azure portal.
|
Task: To Access the Azure Portal and Activate PIM (Privileged Identity Management) Roles.
Note: You must be on the campus network or on the VPN to sign in with ADM_ credentials (as of Oct. 2, 2024).
Instructions
Step 1 - Navigate to the Azure Portal - https://portal.azure.com
Step 2 - Login using Admin Credentials (adm_username)
Step 3 - Search for "PIM" in the search bar at the top of the page.
Step 4 - Select Azure AD Privileged Identity Management from the Services Section
Step 5 - Select My Roles from the menu on the left-hand side of the screen.
Step 6 - Under Eligible Assignments, Click Activate on your desired roles.
Step 7 - Select the amount of time that you require the activation for, enter a reason for activation, and select Activate.
Outcome
Once PIM Roles have been activated, admin users will be able to manage authentication methods and view sign-in/audit reports.
Note: You will hear PIM used as a verb. For example, "I have to PIM before I can access the audit logs". There are multiple ways to get to the page where you can PIM and activate your permissions.
Back to top
Users
The Users module in Azure is where you will find a complete list of user accounts.
- The Users module can be found in the navigation menu on the left-hand side of the screen (alternatively by searching for Users from the search menu at the top of the screen).
- Clicking on an account brings you to an Overview page. This page contains high-level information about the users account, and the status of the account in the Azure system.
- A more detailed view is available in the Properties tab.
Along the left-hand side of the screen, you can access more specific information about the user's Audit Logs, Sign-In Logs, and Authentication Methods.
Task: To Locate a User Using Only Their Personal Email Address.
Note: If you are unable to locate a user, or if they are unable to provide other credentials, there are many filters that can be utilized to search based on personal information.
Instructions
Step 1 - Activate PIM Roles.
Step 2 - Select Users, then All users from the navigation menu on the left-hand side of the screen.
Step 3 - Click Add filter to the right of the search bar.
Step 4 - Select Other emails.
Step 5 - Enter the user’s personal email address in the Value field.
Step 6 - Click Apply.
Outcome
Users with a matching personal email address will return as results.
Note: This process can be repeated with many different filters, including: phone numbers, and street addresses
Back to top
Users: Audit Logs
The audit logs can be useful when trying to get information about what has recently changed with regards to the user account. Here, you can view Activities like, “User started security info registration”, “User registered all required security info”, “Disable Account”, “Add FIDO2 security key”, and many others across all M365 systems.
Example: If you can see that a user's account was disabled (and when), you may be able to determine whether or not the account will still have email access when re-activated.
Under the Status column, users should be able to view the point in which a process may have been halted. By further clicking on the transaction, there should also be a Status Reason.
Example: If a user calls with MFA trouble after recently registering, the status may show, "Interrupted". By looking into the status reason, users should be able to determine precisely where the user got stuck, “User failed to register Outlook mobile with Code”.
Learn more about Audit Logs here: https://learn.microsoft.com/en-us/azure/active-directory/reports-monitoring/concept-audit-logs
Users: Sign-In Logs
Sign-In logs are helpful when trying to troubleshoot a users inability to login. This page notably includes timestamps, login status (Success, Interrupted, or Failed), and most importantly notes the application the user was trying to login to.
Example: If a user is attempting to access canvas and there is no record of their login attempt, they may have entered the wrong username, or tried accessing the wrong website.
By clicking on a specific entry in the sign-in log you can view Additional Details. This allows users to view the potential cause of the issue, and can help guide the next steps in the conversation with the customer.
Example: If the status of a login shows "Interrupted", the user had made an attempt to login but was unable to complete the process. A frequent cause of an interruption will note, “User needs to perform multifactor authentication”.
Learn more about Sign-In Logs here: https://learn.microsoft.com/en-us/azure/active-directory/reports-monitoring/reference-basic-info-sign-in-logs
Users: Applications
This menu item will show you applications that have been assigned to the user. It will additionally show whether the application was “Directly Assigned” or “Assigned as a member of a group”. This might be a good place to confirm, for example, whether the person is assigned to Zoom or MyCourses.
Users: Licenses
There is a license menu under each users account. This will tell you what Microsoft licenses have been granted to them. Clicking on the product gives you a view of what is included with each license. Most licenses are inherited based on what groups the user is a member of. Licenses can also be manually assigned.
Note: You likely will not have to use this, however it is a good page to be aware of.
Users: Devices
This section lists the users registered devices. This page is mostly used to view a devices BitLocker key. After selecting a device, under BitLocker keys, a device will sometimes have the key listed.
Note: Often times, BitLocker keys are not stored in Azure and will need to be accessed from https://myaccount.microsoft.com/device-list.
Users: Authentication Methods
This page is important for viewing what authentication methods a user currently has configured. From this page users can also, “Require re-register multifactor authentication”, or "Revoke multifactor authentication sessions".
Learn more about Authentication Methods here: https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-methods
Task: To Clear a User's Authentication Methods and Require Re-Register Multifactor Authentication.
Note: If the user is having trouble with Microsoft Authenticator and has Mobile Phone set up (and has cell reception where they are), have them login to their account, delete the Microsoft Authenticator method, and then walk the user through adding it back in. Re-registration is not always necessary when users are having trouble with MFA.
Instructions
Step 1 - Activate PIM Roles.
Step 2 - Navigate to the Authentication Methods tab under the desired users account.
Step 3 - Select Require Re-Register Multifactor Authentication.
Outcome
The users authentication methods should be cleared, and they will need to re-register a new method the next time they login.
Note: Whenever possible, it is good to encourage users to have more than one authentication method. If the user is stuck in a situation where they are unable to access one of their methods, the alternate will still allow them to access their account.
Example: If a user gets a new phone and Microsoft Authenticator is no longer working, they will still be able to receive a text so long as they have a Mobile Phone registered. Another common example is the result of students studying abroad. If the student is unable to receive text messages, they will still be able to authenticate their login through the Microsoft Authenticator (no internet connection required).
Back to top
Exchange Admin Center
The Exchange Admin Center is used for resolving issues with mail flow or checking on owners for distribution lists. To access these pages, navigate to the Exchange Admin Center.
Learn more about the Exchange Admin Center here: https://learn.microsoft.com/en-us/exchange/features-in-new-eac
Exchange: Recipients
The Recipients section allows users to view information on individual user Mailboxes, Groups (Microsoft 365, Distribution List, Mail-enabled security), and Resources.
The Mailbox section allows users to view general information about the mailbox, user delegation, and other information like the groups a user is a member of. From the General tab, it is possible to view the Mailbox Usage (percentage used of the total allocated storage). From the Delegation tab, you can see if there are any other users configured to send or receive mail on their behalf. Users are also able to view the groups an individual is a member of by navigating to the Others tab.
The Groups section makes it easy to search for, and view the members of any group or distribution list. This is also the best place to search for the owners of a group or distribution list. Similarly, the Resources tab allows access to the members and owners of different resources across USNH including a wide range of different services from bookable conference rooms, equipment, to parking services.
Exchange: Mail Flow
The Mail Flow section is used to gain an understanding of where mail is coming or going. This page allows admins to trace the status of a message to determine why a user might not have received it.
Task: To Trace a Message using Mail Flow
Note: You must be on the campus network or on the VPN to sign in with ADM_ credentials (as of Oct. 2, 2024).
Instructions
Step 1 - Navigate to the Exchange Admin Center and sign-in using your admin credentials.
Step 2 - Select Mail flow, then Message trace.
Step 3 - Select +Start a trace.
Step 4 - Fill out the form with the information that will narrow the search (sender, receiver, time-frame, etc...).
Step 5 - Select Search at the bottom of the window.
Outcome
Your results will vary, however this is a good way to check if an email has successfully been sent, or delivered to the recipient. By clicking on the message in question, users can view extra information about the message, including the folder/inbox it was delivered to.
Back to top
Microsoft 365 Admin Center
The Microsoft 365 Admin Center is used to view outages for Microsoft services, search for support articles, and to navigate to other M365 admin tools.
Learn more about the Microsoft 365 Admin Center here: https://learn.microsoft.com/en-us/microsoft-365/admin/admin-overview/admin-center-overview?view=o365-worldwide
M365 Admin: Health
The Health module can be used to view information about current Microsoft advisories and outages. By selecting the Health module, and clicking on Service Health users will see a list of current advisories. Selecting one of these, users will be able to view the Issue type, Status, and Updates including timestamps, scope of impact, root cause, current status, etc…
M365 Admin: Support
In the Support module you can enter a problem and Microsoft will provide some recommended self-support articles. If the articles are not helpful, you can open a ticket. This is something that we can potentially do at the help desk but not typically the most practical solution. Working with Microsoft can be time consuming and often requires administrative access to the device that is having the issue.
M365 Admin: Admin Centers
The Microsoft 365 Admin Center is also a hub to get to other admin centers. Some examples include Endpoint Manager, Azure Active Directory, Exchange, SharePoint and Teams.
Back to top
Further Readings
MFA: Setting up Multi-Factor Authentication (MFA) for M365
View Windows BitLocker Recovery Key
Microsoft Learn More Pages
Learn more about: Azure Audit Logs
Learn more about: Azure Sign-In Logs
Learn more about: Azure Authentication Methods
Learn more about: Exchange Admin Center
Learn more about: M365 Admin Center
Need additional help?
If you have questions or need additional help with these topics, please reach out to your Help Desk Team Lead or supervisor for assistance.