Prisma Cloud: How to resolve error "The Service Account Key uploaded is not valid. Please update to continue"

Prisma Cloud: How to resolve error "The Service Account Key uploaded is not valid. Please update to continue"

14758
Created On 01/17/22 22:05 PM - Last Modified 10/26/25 22:19 PM


Symptom


Customer onboard an Azure Active Directory Tenant With Management Groups gets an error "The Service Account Key uploaded is not valid. Please update to continue".

GUI Path: Settings > Providers > Edit Cloud account 
The Service account key uploaded is not valid. Please update to continue


Environment


  • Prisma Cloud
  • Azure 


Cause


The following can be the root cause of the issue:

  1. IAM role permissions are not assigned at root-level in Management Group in Azure portal.
  2. Prisma Cloud App Client secret is expired under "Certificates & secrets"


Resolution


IAM role permissions are not assigned at root-level in Management Group in Azure portal.

It's not possible by design to onboard Management Group without giving root-level permissions in Azure Portal.

Azure portal:

  1.  Login Azure portal
  2.  Go to Management Groups > Tenant Root Group
Tenant Root Group
* If you're unable to select Tenant Root group then refer to steps 1 to 5 in this article .
 
  1. Add Access control (IAM) permissions and retry onboarding steps in the following link

Prisma Cloud App Client secret is expired under "Certificates & secrets"

  1. Login Azure portal
  2. Go to App registrations > Click on "All applications"
  3. Type "Prisma Cloud" in Search boxScreenshot 2023-09-05 at 11.30.56 AM.png
  4. Select Prisma Cloud app. In my case, it's "Prisma Cloud App arhww"
  5. Click on Certificates & secrets Client secret
  6. Client's Secret is expired.Screenshot_2023-09-05_at_11_45_56_AM.png
  7. Click on "New client secret" to create a new one.
  8. Copy newly created Client Secret Value and replace it on Prisma Cloud console.
Prisma Cloud Console:
  1. Login to Prima Cloud > Settings > Providers > Edit Azure Cloud Account > Select "Configure Account"
  2. Replace newly created Client Secret with the old one. Client Secret on Prisma Cloud Console
  3. Click "Next" and then click on "Save and Close".


Additional Information


Reference doc: Add an Azure Active Directory Tenant With Management Groups .
 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004MrGCAU&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language