204004 - Failed to Look Up the Azure Subscription
Uploading...Agent error code #204004 indicates that the knoc has no subscription ID set, and the call the agent makes to discover one did not come back.
The subscription ID is optional. When it is blank, the agent asks Azure which subscriptions the integration's service principal can see and uses that one, so a knoc configured without the field still works. This error means the question went unanswered. When the answer comes back and the agent cannot act on it, the code is #204005.
Common causes:
management.azure.com that is down, slow or intermittent
An outbound proxy or firewall blocking or delaying the connection
Credentials that cannot authenticate at all, so no token was issued for the lookup
A reply that did not finish inside the page limit the agent walks. A partial list is reported rather than acted on, because the unread pages could hold another enabled subscription
A continuation link in the reply naming a host other than management.azure.com. The agent refuses to follow it, since the request that follows it carries the access token
Steps to Resolve
Set the Subscription ID
This removes the lookup entirely. Open the knoc, enter the subscription ID the network security group lives in, and save. The agent then addresses that subscription directly and never makes the discovery call.
The agent logs Azure's own error code and message alongside this one, in the agent_error_vendor_msg field. That is what separates the causes above: AuthorizationFailed points at the role assignment, an invalid token points at the credentials. It is kept out of the portal message, so read it from the agent log.
A message mentioning the page limit or a link that is not the management endpoint usually means an interfering proxy. Confirm the agent reaches management.azure.com without a device rewriting the response.
Check Connectivity to Azure
From the agent host, confirm the Azure management endpoint answers. A request to https://management.azure.com/ should return promptly, even if the response is an authentication error: a fast 401 means the endpoint is reachable. If the agent reaches Azure through a proxy, confirm the proxy is healthy. The agent uses the standard HTTPS_PROXY environment variable if one is set.
Check the Credentials
If the client ID, client secret or tenant ID are wrong, the lookup cannot get a token. Those failures usually report as #204001 instead, so check them here only once connectivity is ruled out.
Retry
A network failure is often transient, and the agent retries on the next reconcile. The failure is held for a few seconds first, so an endpoint that accepts the connection and then hangs cannot charge its full timeout to every operation in turn. A one-off #204004 that clears on its own needs no action; repeated ones point at the network path or the proxy.