Monitoring Benefit
The Configuration PowerShell status test confirms that ENow can open a remote PowerShell session to Exchange Online using the configured monitoring account, and that the session accepts commands. It is the foundation check for the Microsoft 365 workloads: several other tests use this same connection, so when PowerShell fails they fail with it.
ENow establishes the connection, issues a lightweight command, and passes the test if the command returns without throwing an exception. The result is recorded in the ENow database.
This test runs before the Admin Portal test
The Configuration - Admin Portal Status test does not connect to Microsoft 365 itself. It reports on the result this test records. That means:
- If PowerShell and Admin Portal are both showing warning or error, you have one problem, not two.
- Fix PowerShell first. Admin Portal will normally clear on the next cycle without any further action.
How do we verify the monitoring test results?
From the ENow web server, sign in as the ENow monitoring service account — not your own admin account — and connect to Exchange Online by hand.
Modern authentication is required. Install the Exchange Online Management module if it is not already present:
Install-Module -Name ExchangeOnlineManagement -Scope CurrentUser
Then connect and run a lightweight command:
Connect-ExchangeOnline -UserPrincipalName <monitoring account UPN> Get-OrganizationConfig | Select-Object Name, IsDehydrated Disconnect-ExchangeOnline -Confirm:$false
If Get-OrganizationConfig returns without error, the connection ENow depends on is working, and a failing check points at the monitoring account's permissions or at Conditional Access rather than at the service.
Common warning or error results, and potential solutions
- The account is blocked by Conditional Access. Non-interactive service accounts cannot answer an MFA prompt. See Service Accounts: What Each ENow Component Needs, and Rotating Credentials and Conditional Access and ENow: Why Device-Based Policies Block Monitoring.
-
Basic authentication errors. Microsoft removed basic authentication for Exchange Online remote PowerShell. Older connection methods that pass a credential object to
New-PSSessionagainst the/powershell-liveid/endpoint no longer work; the Exchange Online Management module is required. - The account lacks the required role. Confirm the monitoring account still holds the roles listed in the prerequisites for your ENow version. Role assignments are sometimes removed during access reviews.
- The command works by hand but ENow still reports a failure. That usually means you ran it as a different account. Repeat the test as the monitoring service account itself.
Reference: Connect to Exchange Online PowerShell | Microsoft Learn
Comments
0 comments
Article is closed for comments.