Azure Active Directory (AAD) User is unable to start process although rights were already given
kbt135715
PRODUCTIssue
The user is unable to start a process even though they were already given the "Start Process" rights through K2 Management.Symptoms
This usually occurs when a K2 environment is using both Windows Active Directory (AD) and Azure Active Directory (AAD), and the users has accounts in both security providers.
When the user tries to start the process, they are presented with an error that looks like: "24408 AAD:username@domain.com from <IP ADDRESS> does not have rights to Start Process <PROCESS NAME>"
Troubleshooting Steps
Check the account that was given the "Start Process" rights. Chances are, the rights were given to the user's AD account (i.e. "K2:DOMAINUsername") instead of the AAD account that was shown in the error message (i.e. "AAD:username@domain.com").
The accounts has to be matched 1 to 1 under the process rights as K2 does not form any symbolic link between a user's AD and AAD account, thus the account rights are not interchangeable and has to be assigned individually to each of the user's accounts.