Troubleshooting Error Codes
CO-NoEnoughPermissionInCustomApp
Details:
Insufficient permissions of the app profile. Please verify the permissions of the app in the custom app profile that you created for IBM® Storage Protect for Cloud Azure VMs, Storage, and Entra ID.
Solutions:
Check the API permissions that the custom Azure app has been consented with in the Microsoft Entra admin center. For the list of the required API permissions for the data that you want to protect, refer to the table in the Default Permissions Granted to the Service App section.
AS-NoPermission
Details:
IBM has no permission to access your storage account. Please check your firewall for whether the IBM reserved IP addresses or ARM virtual networks have been added as the trusted.
Solutions:
Verify whether the Delegated app that you use to protect this Azure storage has the required API permissions. For details, refer to Enable the Backup for Azure Virtual Machines, Azure Storage, and Azure SQL.
Check your firewall for whether the IBM reserved IP addresses or ARM virtual networks have been added as the trusted. For details, refer to Allow IBM Storage Protect for Cloud Agent Servers to Access Your Storage Account.
APS-NoServiceAccount
Details:
Some properties are not backed up or restored as there are no valid service accounts configured in IBM Storage Protect for Cloud.
Solutions:
To protect the Group General Settings using the Admin Portal Settings service, a service account with the Cloud Application Administrator role is required. For detailed instructions, refer to Create a Service Account Profile.
APS-NoIntuneLicense
Details:
The Microsoft Intune license is invalid or expired. Please check your license in Microsoft 365 or exclude the related settings from backup.
Solutions:
To protect the Intune components using the Admin Portal Settings service, you must have active Microsoft Intune license. If you believe that you’re getting this message in error, contact IBM Software Support for assistance.
APS-NoDefenderForOffice365
Details:
No Microsoft Defender for Office 365 subscription is active in your tenant. Please verify your subscription and try again.
Solutions:
To protect the Microsoft Defender components using the Admin Portal Settings service, you must have an active Microsoft Defender for Office 365 subscription. If there are no components in your Microsoft Defender, you can edit your backup scope to exclude the Defender objects.
APS-NoADMXFile
Details:
The object is not restored because the ADMX file on which it was based has been deleted.
Solutions:
Import the ADMX file to your Microsoft Intune and try to perform the restore job again.
AAD-NoEnoughPermissions
Details:
Insufficient permissions of the app profile. Please re-authorize the service app or verify the permissions of the app in the custom Azure app profile that you created for IBM Storage Protect for Cloud Azure VMs, Storage, and Entra ID.
Solutions:
The required app permissions have been updated. Please re-authorize the service app profile or manually update the app permissions of the custom Azure app that you are using. For details on re-authorizing an app, refer to Re-authorize an App Profile.
AAD-RestrictedAdminUnit
Details:
Insufficient permissions. This object is a member of a restricted management administrative unit and can only be managed by administrators scoped for that administrative unit. Please remove the object from the administrative unit and try again.
Solutions:
To protect the objects using the Microsoft Entra ID service, ensure they are removed from restricted management administrative units before restoring.
VM-ExtensionScriptExist
Details:
The custom script extension of type “CustomScriptExtension” or “CustomScript” already exists.
Solutions:
Remove the existing custom script extension of type “CustomScriptExtension” or “CustomScript” from Azure VMs before restoring.