Regain access to Nerdio Manager when no administrator can sign in

Nerdio Manager is a platform-as-a-service application that runs entirely inside your own Azure subscription. Because of this, the Nerdio Support team does not have access to your installation and cannot grant, restore, or change user access on your behalf. Access is controlled by a Microsoft Entra ID enterprise application in your tenant, and only someone with sufficient permissions in your Azure environment can modify it.

This article explains how to manually assign a user to the Nerdio Manager Enterprise application from the Azure portal so they can sign in.

When to use this article

Use this process when no one is able to sign in to Nerdio Manager to manage access through the application itself. Common situations include:

  • The only administrator has left the organization or is otherwise unavailable

  • The administrator's account was disabled, deleted, or had its assignment removed.

Tip

If you can still sign in to Nerdio Manager as an administrator you don't need to use this procedure: use the built-in role management instead.

Before you begin

You will need an account with sufficient permissions in your Azure tenant and subscription. Typically this means:

  • Owner on the subscription or resource group where Nerdio Manager is deployed

  • Permission to manage enterprise applications in Microsoft Entra ID (for example, Global Administrator or Cloud Application Administrator).

If you do not have these permissions, you will need to work with whoever administers your Azure tenant. Nerdio Support cannot perform these steps for you.

Find the Nerdio Manager Application ID

Multiple enterprise applications named web-admin-portal may exist in your tenant, so you first need the Application ID of the one tied to your Nerdio Manager installation.

  1. In the Azure portal, navigate to App Services and open the Nerdio Manager web app. Its name begins with web-admin-portal- followed by a random string.

  2. Navigate to Settings > Environment variables.

  3. On the App settings tab, find SignIn:ClientId and select Show value. Copy the value. This is the Application ID.

Tip

If you are not sure which subscription or resource group Nerdio Manager is deployed in, search for web-admin-portal in the Azure portal's top search bar and look for an App Service result.

Open the Enterprise application

  1. In the Azure portal's top search bar, search for and open Enterprise applications.

  2. In the search box under All applications, type web-admin-portal.

  3. In the results, locate the row whose Application ID matches the value you copied in Find the Nerdio Manager Application ID, and select it.

Assign the user and role

  1. In the Azure portal, navigate to Manage > Users and groups.

  2. Select Add user/group.

  3. Under Users and groups, select None Selected, search for the user, select them, and select Select.

  4. Under Select a role, choose the role the user needs. To restore full administrative access, choose Super Admin.

  5. Select Assign.

Sign in to Nerdio Manager

Open the Nerdio Manager URL and sign in with the account you just assigned. The assignment should take effect immediately. 

Tip

If sign-in still fails, wait a few minutes and try again, since Entra ID changes can take a short time to propagate.

Once you are in, review the remaining users and roles under System > System Settings and remove or update any stale assignments.

Troubleshooting

I see more than one web-admin-portal application

Compare each one's Application ID to the SignIn:ClientId value from Find the Nerdio Manager Application ID. Only the matching application controls access to your Nerdio Manager installation.

I don't have permission to add assignments

Contact the Azure tenant administrator. Assigning users to enterprise applications requires elevated permissions, and Nerdio cannot grant these on your behalf.

The user still can't sign in after being assigned

Confirm the user is signing in with the exact account that was assigned, try a private browser window, and verify the assignment was saved on the correct application.

I can't find the Nerdio Manager URL

On the App Service from Find the Nerdio Manager Application ID, the Overview page shows the Default domain. That is the Nerdio Manager sign-in address.

Was this article helpful?

0 out of 0 found this helpful
Have more questions? Submit a request

Comments (0 comments)

Article is closed for comments.