You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/develop/troubleshoot-publisher-verification.md
+39-42Lines changed: 39 additions & 42 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -147,14 +147,11 @@ The MPN ID you provided (`MPNID`) doesn't exist, or you don't have access to it.
147
147
Most commonly caused by the signed-in user not being a member of the proper role for the MPN account in Partner Center- see [requirements](publisher-verification-overview.md#requirements) for a list of eligible roles and see [common issues](#common-issues) for more information. Can also be caused by the tenant the app is registered in not being added to the MPN account, or an invalid MPN ID.
148
148
149
149
**Remediation Steps**
150
-
151
-
1. Go to your [partner profile](https://partner.microsoft.com/pcv/accountsettings/connectedpartnerprofile) and verify that:
152
-
- The MPN ID is correct.
153
-
- There are no errors or “pending actions” shown, and the verification status under Legal business profile and Partner info both say “authorized” or “success”.
154
-
155
-
2. Go to the [MPN tenant management page](https://partner.microsoft.com/dashboard/account/v3/tenantmanagement) and confirm that the tenant the app is registered in and that you're signing with a user account from is on the list of associated tenants. To add another tenant, follow the instructions [here](/partner-center/multi-tenant-account). Be aware that all Global Admins of any tenant you add will be granted Global Administrator privileges on your Partner Center account.
156
-
157
-
3. Go to the [MPN User Management page](https://partner.microsoft.com/pcv/users) and confirm the user you're signing in as is either a Global Administrator, MPN Admin, or Accounts Admin. To add a user to a role in Partner Center, follow the instructions [here](/partner-center/create-user-accounts-and-set-permissions).
150
+
1. Go to your [partner profile](https://partner.microsoft.com/pcv/accountsettings/connectedpartnerprofile) and verify that:
151
+
- The MPN ID is correct.
152
+
- There are no errors or “pending actions” shown, and the verification status under Legal business profile and Partner info both say “authorized” or “success”.
153
+
2. Go to the [MPN tenant management page](https://partner.microsoft.com/dashboard/account/v3/tenantmanagement) and confirm that the tenant the app is registered in and that you're signing with a user account from is on the list of associated tenants. To add another tenant, follow the instructions [here](/partner-center/multi-tenant-account). Be aware that all Global Admins of any tenant you add will be granted Global Administrator privileges on your Partner Center account.
154
+
3. Go to the [MPN User Management page](https://partner.microsoft.com/pcv/users) and confirm the user you're signing in as is either a Global Administrator, MPN Admin, or Accounts Admin. To add a user to a role in Partner Center, follow the instructions [here](/partner-center/create-user-accounts-and-set-permissions).
158
155
159
156
### MPNGlobalAccountNotFound
160
157
@@ -163,8 +160,8 @@ The MPN ID you provided (`MPNID`) isn't valid. Provide a valid MPN ID and try ag
163
160
Most commonly caused when an MPN ID is provided which corresponds to a Partner Location Account (PLA). Only Partner Global Accounts are supported. See [Partner Center account structure](/partner-center/account-structure) for more details.
164
161
165
162
**Remediation Steps**
166
-
1. Navigate to your [partner profile](https://partner.microsoft.com/pcv/accountsettings/connectedpartnerprofile) > Identifiers blade > Microsoft Cloud Partners Program Tab
167
-
2. Use the Partner ID with type PartnerGlobal
163
+
1. Navigate to your [partner profile](https://partner.microsoft.com/pcv/accountsettings/connectedpartnerprofile) > Identifiers blade > Microsoft Cloud Partners Program Tab
164
+
2. Use the Partner ID with type PartnerGlobal
168
165
169
166
### MPNAccountInvalid
170
167
@@ -173,8 +170,8 @@ The MPN ID you provided (`MPNID`) isn't valid. Provide a valid MPN ID and try ag
173
170
Most commonly caused by the wrong MPN ID being provided.
174
171
175
172
**Remediation Steps**
176
-
1. Navigate to your [partner profile](https://partner.microsoft.com/pcv/accountsettings/connectedpartnerprofile) > Identifiers blade > Microsoft Cloud Partners Program Tab
177
-
2. Use the Partner ID with type PartnerGlobal
173
+
1. Navigate to your [partner profile](https://partner.microsoft.com/pcv/accountsettings/connectedpartnerprofile) > Identifiers blade > Microsoft Cloud Partners Program Tab
174
+
2. Use the Partner ID with type PartnerGlobal
178
175
179
176
### MPNAccountNotVetted
180
177
@@ -183,8 +180,8 @@ The MPN ID (`MPNID`) you provided hasn't completed the vetting process. Complete
183
180
Most commonly caused by when the MPN account hasn't completed the [verification](/partner-center/verification-responses) process.
184
181
185
182
**Remediation Steps**
186
-
1. Navigate to your [partner profile](https://partner.microsoft.com/pcv/accountsettings/connectedpartnerprofile) and verify that There are no errors or “pending actions” shown, and that the verification status under Legal business profile and Partner info both say “authorized” or “success”.
187
-
2. If not, view pending action items in Partner Center and troubleshoot with [here](/partner-center/verification-responses)
183
+
1. Navigate to your [partner profile](https://partner.microsoft.com/pcv/accountsettings/connectedpartnerprofile) and verify that There are no errors or “pending actions” shown, and that the verification status under Legal business profile and Partner info both say “authorized” or “success”.
184
+
2. If not, view pending action items in Partner Center and troubleshoot with [here](/partner-center/verification-responses)
188
185
189
186
### NoPublisherIdOnAssociatedMPNAccount
190
187
@@ -193,8 +190,8 @@ The MPN ID you provided (`MPNID`) isn't valid. Provide a valid MPN ID and try ag
193
190
Most commonly caused by the wrong MPN ID being provided.
194
191
195
192
**Remediation Steps**
196
-
1. Navigate to your [partner profile](https://partner.microsoft.com/pcv/accountsettings/connectedpartnerprofile) > Identifiers blade > Microsoft Cloud Partners Program Tab
197
-
2. Use the Partner ID with type PartnerGlobal
193
+
1. Navigate to your [partner profile](https://partner.microsoft.com/pcv/accountsettings/connectedpartnerprofile) > Identifiers blade > Microsoft Cloud Partners Program Tab
194
+
2. Use the Partner ID with type PartnerGlobal
198
195
199
196
### MPNIdDoesNotMatchAssociatedMPNAccount
200
197
@@ -203,8 +200,8 @@ The MPN ID you provided (`MPNID`) isn't valid. Provide a valid MPN ID and try ag
203
200
Most commonly caused by the wrong MPN ID being provided.
204
201
205
202
**Remediation Steps**
206
-
1. Navigate to your [partner profile](https://partner.microsoft.com/pcv/accountsettings/connectedpartnerprofile) > Identifiers blade > Microsoft Cloud Partners Program Tab
207
-
2. Use the Partner ID with type PartnerGlobal
203
+
1. Navigate to your [partner profile](https://partner.microsoft.com/pcv/accountsettings/connectedpartnerprofile) > Identifiers blade > Microsoft Cloud Partners Program Tab
204
+
2. Use the Partner ID with type PartnerGlobal
208
205
209
206
### ApplicationNotFound
210
207
@@ -213,9 +210,9 @@ The target application (`AppId`) can’t be found. Provide a valid application I
213
210
Most commonly caused when verification is being performed via Graph API, and the ID of the application provided is incorrect.
214
211
215
212
**Remediation Steps**
216
-
1. The Object ID of the application must be provided, not the AppId/ClientId. See "id" on the list of application properties [here](/graph/api/resources/application)
217
-
2. Log in to [Azure Active Directory](https://aad.portal.azure.com/) with a user account in your organization's primary tenant > Azure Active Directory > App Registrations blade
218
-
3. Find your app's registration to view the Object ID
213
+
1. The Object ID of the application must be provided, not the AppId/ClientId. See "id" on the list of application properties [here](/graph/api/resources/application)
214
+
2. Log in to [Azure Active Directory](https://aad.portal.azure.com/) with a user account in your organization's primary tenant > Azure Active Directory > App Registrations blade
215
+
3. Find your app's registration to view the Object ID
219
216
220
217
221
218
### ApplicationObjectisInvalid
@@ -225,9 +222,9 @@ The target application's object ID is invalid. Please provide a valid ID and try
225
222
Most commonly caused when the verification is being performed via Graph API, and the ID of the application provided does not exist.
226
223
227
224
**Remediation Steps**
228
-
1. The Object ID of the application must be provided, not the AppId/ClientId. See "id" on the list of application properties [here](/graph/api/resources/application)
229
-
2. Log in to [Azure Active Directory](https://aad.portal.azure.com/) with a user account in your organization's primary tenant > Azure Active Directory > App Registrations blade
230
-
3. Find your app's registration to view the Object ID
225
+
1. The Object ID of the application must be provided, not the AppId/ClientId. See "id" on the list of application properties [here](/graph/api/resources/application)
226
+
2. Log in to [Azure Active Directory](https://aad.portal.azure.com/) with a user account in your organization's primary tenant > Azure Active Directory > App Registrations blade
227
+
3. Find your app's registration to view the Object ID
231
228
232
229
233
230
### B2CTenantNotAllowed
@@ -245,7 +242,7 @@ The target application (`AppId`) must have a Publisher Domain set. Set a Publish
245
242
Occurs when a [Publisher Domain](howto-configure-publisher-domain.md) isn't configured on the app.
246
243
247
244
**Remediation Steps**
248
-
1. Follow the directions [here](/azure/active-directory/develop/howto-configure-publisher-domain#set-a-publisher-domain-in-the-azure-portal) to set a Publisher Domain
245
+
1. Follow the directions [here](/azure/active-directory/develop/howto-configure-publisher-domain#set-a-publisher-domain-in-the-azure-portal) to set a Publisher Domain
249
246
250
247
### PublisherDomainMismatch
251
248
@@ -256,11 +253,11 @@ Occurs when neither the app's [Publisher Domain](howto-configure-publisher-domai
256
253
See [requirements](publisher-verification-overview.md) for a list of allowed domain or sub-domain matches.
257
254
258
255
**Remediation Steps**
259
-
1. Navigate to your [partner profile](https://partner.microsoft.com/pcv/accountsettings/connectedpartnerprofile), and view the email listed as Primary Contact
260
-
2. The domain used to perform email verification in Partner Center is the portion after the “@” in the Primary Contact’s email
261
-
3. Log in to [Azure Active Directory](https://aad.portal.azure.com/) > Azure Active Directory > App Registrations blade > (`Your App`) > Branding and Properties
262
-
4. Click “Update Publisher Domain” and follow the instructions to “Verify a New Domain”
263
-
5. Add the domain used to perform email verification in Partner Center as a New Domain
256
+
1. Navigate to your [partner profile](https://partner.microsoft.com/pcv/accountsettings/connectedpartnerprofile), and view the email listed as Primary Contact
257
+
2. The domain used to perform email verification in Partner Center is the portion after the “@” in the Primary Contact’s email
258
+
3. Log in to [Azure Active Directory](https://aad.portal.azure.com/) > Azure Active Directory > App Registrations blade > (`Your App`) > Branding and Properties
259
+
4. Click “Update Publisher Domain” and follow the instructions to “Verify a New Domain”
260
+
5. Add the domain used to perform email verification in Partner Center as a New Domain
264
261
265
262
266
263
### NotAuthorizedToVerifyPublisher
@@ -270,10 +267,10 @@ You aren't authorized to set the verified publisher property on application (<`A
270
267
Most commonly caused by the signed-in user not being a member of the proper role for the MPN account in Azure AD- see [requirements](publisher-verification-overview.md#requirements) for a list of eligible roles and see [common issues](#common-issues) for more information.
271
268
272
269
**Remediation Steps**
273
-
1. Sign in to the [Azure AD Portal](https://aad.portal.azure.com) using a user account in your organization's primary tenant.
274
-
2. Navigate to [Role Management](https://aad.portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/RolesAndAdministrators).
275
-
3. Select the desired admin role and click “Add Assignment” if you have sufficient permissions.
276
-
4. If you do not have sufficient permissions, contact an admin role for assistance
270
+
1. Sign in to the [Azure AD Portal](https://aad.portal.azure.com) using a user account in your organization's primary tenant.
271
+
2. Navigate to [Role Management](https://aad.portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/RolesAndAdministrators).
272
+
3. Select the desired admin role and click “Add Assignment” if you have sufficient permissions.
273
+
4. If you do not have sufficient permissions, contact an admin role for assistance
277
274
278
275
279
276
### MPNIdWasNotProvided
@@ -283,8 +280,8 @@ The MPN ID wasn't provided in the request body or the request content type wasn'
283
280
Most commonly caused when the verification is being performed via Graph API, and the MPN ID wasn’t provided in the request.
284
281
285
282
**Remediation Steps**
286
-
1. Navigate to your [partner profile](https://partner.microsoft.com/pcv/accountsettings/connectedpartnerprofile) > Identifiers blade > Microsoft Cloud Partners Program Tab
287
-
2. Use the Partner ID with type PartnerGlobal in the request
283
+
1. Navigate to your [partner profile](https://partner.microsoft.com/pcv/accountsettings/connectedpartnerprofile) > Identifiers blade > Microsoft Cloud Partners Program Tab
284
+
2. Use the Partner ID with type PartnerGlobal in the request
288
285
289
286
### MSANotSupported
290
287
@@ -299,22 +296,22 @@ Occurs when multi-factor authentication (MFA) hasn't been enabled and performed
299
296
The error message displayed will be: "Due to a configuration change made by your administrator, or because you moved to a new location, you must use multi-factor authentication to proceed."
300
297
301
298
**Remediation Steps**
302
-
1. Ensure [multi-factor authentication](../fundamentals/concept-fundamentals-mfa-get-started.md) is enabled and **required** for the user you're signing in with and for this scenario
303
-
2. Retry Publisher Verification
299
+
1. Ensure [multi-factor authentication](../fundamentals/concept-fundamentals-mfa-get-started.md) is enabled and **required** for the user you're signing in with and for this scenario
300
+
2. Retry Publisher Verification
304
301
305
302
### UserUnableToAddPublisher
306
303
307
304
When a request to add a verified publisher is made, many signals are used to make a security risk assessment. If the user risk state is determined to be ‘AtRisk’, an error, “You're unable to add a verified publisher to this application. Contact your administrator for assistance” will be returned. Please investigate the user risk and take the appropriate steps to remediate the risk (guidance below):
> Self-serve password reset (SSPR): If the organization allows SSPR, use aka.ms/sspr to reset the password for remediation. Please choose a strong password; Choosing a weak password may not reset the risk state.
317
-
314
+
>
318
315
> [!NOTE]
319
316
> Please give some time after remediation for the risk state to update, and then try again.
0 commit comments