A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.
Azure Automation: Managing Exchange Online Distribution Groups with Managed Identity — Connection Failure
Problem description
I am attempting to use an Azure Automation runbook with a system-assigned managed identity to add a member to an Exchange Online distribution group. The runbook connects successfully using 'Connect-ExchangeOnline -ManagedIdentity', retrieves group and user details, but fails when executing 'Add-DistributionGroupMember' with the error: "A server side error has occurred because of which the operation could not be completed. Please try again after some time." The failure occurs consistently during this command.
Environment
Azure Automation account with system-assigned managed identity, PowerShell 7.2 runtime, connecting to *** Online in a tenant where the distribution group resides.
What I've already tried
I verified that the managed identity has the '***.ManageAsApp' application permission and that the connection to *** Online via 'Connect-ExchangeOnline -ManagedIdentity' is successful. The script successfully retrieves group details and resolves members. The issue only occurs during 'Add-DistributionGroupMember'. I have also assigned temporary *** Recipient Administrator and *** Administrator roles to the managed identity at tenant scope, but the failure persists. Additionally, a manual PowerShell session using a user account can add members successfully, indicating the cmdlet and environment are correctly configured.
Current status
The process fails at 'Add-DistributionGroupMember' with a server-side error, despite the managed identity having appropriate permissions. I seek guidance on the required permissions, configuration steps, and whether this app-only approach is supported for distribution groups with a custom recipient write scope. Any insights into resolving the server error or alternative solutions would be appreciated.