Azure device role sync fails with “Insufficient privileges”
Symptoms
When synchronizing an Activate system role whose Members parameter selects devices from an Azure Active Directory organizational unit:
- Activate identifies the expected devices during synchronisation.
- The devices may appear in the Active Directory cache.
- The synchronisation finishes without adding the devices to the system role.
- The same configuration may work in another environment, even when both environments use the same Azure app registration.
- Increasing the Azure connector trace level may not initially reveal the problem.
A full synchronisation may show the following error:
Cause
The Microsoft Entra ID application registration used by the Activate Azure AD connector does not have sufficient Microsoft Graph permissions to read all directory information required during the role synchronisation.
The devices can still appear in parts of the synchronisation or cache because some directory queries succeed. A later Microsoft Graph request fails when Activate attempts to resolve the complete membership information.
Resolution
Grant the application registration the following Microsoft Graph application permission:
An Entra ID administrator must then grant tenant-wide admin consent for the permission.
To configure the permission:
- Open the Microsoft Entra admin center.
- Go to App registrations.
- Select the application registration used by the Activate Azure AD connector.
- Open API permissions.
- Select Add a permission.
- Select Microsoft Graph.
- Select Application permissions.
- Add Directory.Read.All.
- Select Grant admin consent for the tenant.
- Confirm that the permission status shows that consent has been granted.
- Run the Activate role membership synchronisation again.
After the permission and admin consent are granted, the Azure devices should be added to the system role successfully.
Additional checks
If the problem continues:
- Confirm that Activate is using the expected tenant and application registration.
- Verify that Directory.Read.All was added as an application permission, not only as a delegated permission.
- Confirm that admin consent was granted in the tenant used by the affected environment.
- Check whether the production and UAT environments use different credentials, service principals, tenants, or connector settings despite referencing the same application registration.
Note about Device.Read.All
Device.Read.All provides access to device information, but this issue was resolved by granting Directory.Read.All because the role synchronisation also required broader directory data. Only grant permissions that have been reviewed and approved according to your organization’s security policies.