-
Write down exactly what failed
Note the page, the action, the exact message and the approximate time. Confirm which account, tenant and object you were working with. If you use delegated administration, check the customer banner and tenant picker before doing anything else.
-
Read the relevant documentation
Start with the documentation overview, then read the page for the feature that failed. Use Sign-in & permissions for consent or access errors and Who can do what to find the Microsoft role required for the exact operation. Partner administrators should also read Delegated administration.
-
Refresh the data and allow Microsoft changes to propagate
Choose Refresh on the affected list and try a safe read again. Microsoft Entra, Exchange and SharePoint changes are not always visible immediately. If a role, consent, mailbox permission, licence or object was just changed, wait for Microsoft to finish propagating it before testing again. Do not repeatedly run a destructive action.
-
Check the CloudSergeant version and restart it
Open Settings to note the installed version. Install an offered update, or use the Download page if you need the current installer. Finish any running jobs, close every CloudSergeant window, reopen the app and retry once.
-
Understand the two permission checks
CloudSergeant uses delegated access: it borrows the rights of the signed-in person and never has independent administrator rights. Every operation therefore needs both:
- Consent for CloudSergeant to request the required Microsoft API permission.
- A Microsoft role allowing your signed-in account to perform that operation on that target.
A CloudSergeant licence does not grant Microsoft roles. Consent in your own tenant does not grant consent in a customer tenant, and your home-tenant role does not carry into a customer tenant; GDAP must provide the required role there. Managing an account that is itself an administrator can also require a more privileged role.
-
Renew the sign-in and consent
From the account menu, use Grant permissions again when consent may be missing. If a changed role or Conditional Access decision still looks stale, use Clear cached tokens; this signs you out, so sign in again to obtain fresh tokens. For a customer tenant, a Global Administrator of that customer must approve its separate consent request.
-
Test the same workload in Microsoft
Use the same account and target tenant wherever possible:
- Microsoft Entra admin center: test directory tasks involving users, groups, devices, roles or authentication methods. Confirm the required role is active, including any PIM activation, and applies to the target.
- Exchange admin center: test mailbox, mail contact, distribution group or Exchange permission work. These tasks need an Exchange role such as Exchange Administrator or Recipient Management; an Entra directory role alone is not enough.
- SharePoint admin center: test OneDrive sharing, lock, quota or site administrator settings. These settings require SharePoint Administrator. CloudSergeant can also manage tenant-level settings through GDAP when that role is in the customer relationship. In a customer tenant, use the SharePoint admin center to inspect the existing site-administrator list or work directly with files.
- Azure portal or Microsoft Entra admin center: check the CloudSergeant enterprise application, verify that tenant-wide admin consent is granted and review the sign-in logs for a Conditional Access, consent or authentication failure.
If the same action is refused in Microsoft's portal, the cause is the Microsoft account, role, policy or tenant configuration. Ask the administrator who controls that tenant to correct it. If it succeeds there but still fails in CloudSergeant, continue below.
-
Check special Microsoft limitations
- Mailbox content requires mailbox ownership or Full Access; no administrator role replaces it.
- Mailbox content tools cannot access a customer mailbox through GDAP.
- Through GDAP, OneDrive tenant settings work but Graph drive details, file sharing and the existing site-administrator list do not.
- The last Global Administrator cannot be removed.
- PIM-eligible or group-based role assignments cannot be removed as direct assignments.
- A failure affecting only an administrator account may require Privileged Authentication Administrator.
-
Check connectivity, service health and licence state
Confirm that Microsoft sign-in and the relevant admin portal open in your browser. Check Microsoft 365 service health if your organisation has access, and make sure a proxy, VPN or firewall is not blocking Microsoft or CloudSergeant. If the app shows a licence notice, use Check licence status or Manage subscription before troubleshooting a feature.
-
Collect the safe diagnostic information
Open Settings ▸ Activity log and find the lines from the time of the failure. Include the installed version, page, action, exact error, time, whether the same task worked in Microsoft's portal and the relevant log lines when emailing support@cloudsergeant.com.
Never send passwords, access tokens, BitLocker recovery keys, mailbox content or other customer data. Redact anything you do not want included in the support request.
We can investigate technical problems in CloudSergeant. We cannot grant Microsoft roles, approve tenant consent, change Conditional Access, configure GDAP or override Microsoft Entra, Exchange or SharePoint restrictions.
Contact support
Email is the only support channel. The same address is also open for comments, feature requests, constructive criticism or simply a pat on the shoulder.