# Identity Manager gets 403 when trying to query the API

**URL:** <https://discuss.pomerium.com/t/identity-manager-gets-403-when-trying-to-query-the-api/452>\
**Category:** Support\
**Created:** [February 24, 2025, 11:21am UTC](https://discuss.pomerium.com/t/identity-manager-gets-403-when-trying-to-query-the-api/452 "2025-02-24T11:21:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![DevOps\_saran](https://avatars.discourse-cdn.com/v4/letter/d/c6cbf5/32.png) [@DevOps\_saran](https://discuss.pomerium.com/u/DevOps_saran)\
**Post date:** [February 24, 2025, 11:21am UTC](https://discuss.pomerium.com/t/identity-manager-gets-403-when-trying-to-query-the-api/452/1 "2025-02-24T11:21:16Z")

</div>

We have deployed pomerium in K8s pod with azure IDP integration . Users are able to login and did not find any issues there however in pod logs I can see graph api error

## What did you expect to happen? No error message from azure end

## How’d it happen?

Running in K8s pod I can see

```auto
"level":"warn","service":"identity_manager","error":"no directory provider configured","time":"2025-02-24T10:55:23Z","message":"failed to refresh directory users and groups"}
{"level":"warn","service":"identity_manager","error":"no directory provider configured","time":"2025-02-24T10:55:23Z","message":"failed to refresh directory users and groups"}
{"level":"warn","service":"identity_manager","error":"no directory provider configured","time":"2025-02-24T10:55:25Z","message":"failed to refresh directory users and groups"}
{"level":"warn","service":"identity_manager","error":"no directory provider configured","time":"2025-02-24T10:55:25Z","message":"failed to refresh directory users and groups"}
{"level":"warn","service":"identity_manager","error":"no directory provider configured","time":"2025-02-24T10:55:28Z","message":"failed to refresh directory users and groups"}
{"level":"warn","service":"identity_manager","error":"no directory provider configured","time":"2025-02-24T10:55:31Z","message":"failed to refresh directory users and groups"}
{"level":"warn","service":"identity_manager","error":"azure: error making HTTP request: Get \"https://graph.microsoft.com/v1.0/groups/delta?$skiptoken=xxxxxx\": context deadline exceeded","time":"2025-02-24T10:56:34Z","message":"failed to refresh directory users and groups. You may need to increase the identity provider directory timeout setting(https://www.pomerium.com/docs/reference/identity-provider-refresh-directory-settings)"}
{"level":"warn","service":"identity_manager","error":"azure: error making HTTP request: Get \"https://graph.microsoft.com/v1.0/groups/delta?$skiptoken=xxxxx": context deadline exceeded","time":"2025-02-24T10:57:34Z","message":"failed to refresh directory users and groups. You may need to increase the identity provider directory timeout setting(https://www.pomerium.com/docs/reference/identity-provider-refresh-directory-settings)"}

```

## What’s your environment like?

- Pomerium version (retrieve with `pomerium --version`): pomerium/ingress-controller:sha-c0deea9
- Server Operating System/Architecture/Cloud: k8s

## What’s your config.yaml?

```auto
kind: Pomerium
metadata:
  annotations:
    meta.helm.sh/release-name: pomerium-oauth-azure
    meta.helm.sh/release-namespace: oauth
  generation: 1
  labels:
    app.kubernetes.io/managed-by: Helm
  name: pomerium-oauth-azure-azure
spec:
  authenticate:
    url: https://pomeriumnew.xxxx.com/oauth2/callback
  certificates:
  - oauth/wildcard.xxxx.com
  identityProvider:
    provider: azure
    secret: oauth/pomerium-oauth-azure-idpazure
    url: https://login.microsoftonline.com/xxxxxx/v2.0
  secrets: oauth/pomerium-oauth-azure-secretsazure

```

## What did you see in the logs?

```auto
"level":"warn","service":"identity_manager","error":"no directory provider configured","time":"2025-02-24T10:55:23Z","message":"failed to refresh directory users and groups"}
{"level":"warn","service":"identity_manager","error":"no directory provider configured","time":"2025-02-24T10:55:23Z","message":"failed to refresh directory users and groups"}
{"level":"warn","service":"identity_manager","error":"no directory provider configured","time":"2025-02-24T10:55:25Z","message":"failed to refresh directory users and groups"}
{"level":"warn","service":"identity_manager","error":"no directory provider configured","time":"2025-02-24T10:55:25Z","message":"failed to refresh directory users and groups"}
{"level":"warn","service":"identity_manager","error":"no directory provider configured","time":"2025-02-24T10:55:28Z","message":"failed to refresh directory users and groups"}
{"level":"warn","service":"identity_manager","error":"no directory provider configured","time":"2025-02-24T10:55:31Z","message":"failed to refresh directory users and groups"}
{"level":"warn","service":"identity_manager","error":"azure: error making HTTP request: Get \"https://graph.microsoft.com/v1.0/groups/delta?$skiptoken=xxxxxx\": context deadline exceeded","time":"2025-02-24T10:56:34Z","message":"failed to refresh directory users and groups. You may need to increase the identity provider directory timeout setting(https://www.pomerium.com/docs/reference/identity-provider-refresh-directory-settings)"}
{"level":"warn","service":"identity_manager","error":"azure: error making HTTP request: Get \"https://graph.microsoft.com/v1.0/groups/delta?$skiptoken=xxxxx": context deadline exceeded","time":"2025-02-24T10:57:34Z","message":"failed to refresh directory users and groups. You may need to increase the identity provider directory timeout setting(https://www.pomerium.com/docs/reference/identity-provider-refresh-directory-settings)"}

```

## Additional context

We use it custom chart means we pull it from public and in our organization we use it with custom changes like changing ports/scanning the image and resolving vulnerability stuff like that . I know it is an old image but still let us know if image change will help in this case and which image it will be?

---

<div class="post-metadata">

**Author:** ![calebdoxsey](https://avatars.discourse-cdn.com/v4/letter/c/7bcc69/32.png) [@calebdoxsey](https://discuss.pomerium.com/u/calebdoxsey)\
**Post date:** [February 24, 2025, 3:23pm UTC](https://discuss.pomerium.com/t/identity-manager-gets-403-when-trying-to-query-the-api/452/2 "2025-02-24T15:23:01Z")

</div>

This is an old version of the ingress controller. Directory support is now only available in the enterprise console.

Does the pod you’re running have internet egress access? Have you tried increasing the timeout as the error message suggests?

---

<div class="post-metadata">

**Author:** ![DevOps\_saran](https://avatars.discourse-cdn.com/v4/letter/d/c6cbf5/32.png) [@DevOps\_saran](https://discuss.pomerium.com/u/DevOps_saran)\
**Post date:** [February 25, 2025, 7:36am UTC](https://discuss.pomerium.com/t/identity-manager-gets-403-when-trying-to-query-the-api/452/3 "2025-02-25T07:36:34Z")

</div>

No did not increase it yet. Will increase and check . Also yes this have access to internet .

> [@calebdoxsey](#):
>
> This is an old version of the ingress controller. Directory support is now only available in the enterprise console.

does this mean in community it does not support anymore ??

---

<div class="post-metadata">

**Author:** ![calebdoxsey](https://avatars.discourse-cdn.com/v4/letter/c/7bcc69/32.png) [@calebdoxsey](https://discuss.pomerium.com/u/calebdoxsey)\
**Post date:** [February 25, 2025, 4:24pm UTC](https://discuss.pomerium.com/t/identity-manager-gets-403-when-trying-to-query-the-api/452/4 "2025-02-25T16:24:21Z")

</div>

> [@DevOps\_saran](#):
>
> does this mean in community it does not support anymore ??

Directory support (groups, additional user info claims) is now only available in the enterprise console. Some IdPs support populating claims with groups data and that can be used as a workaround: [Microsoft Entra ID (formerly Azure Active Directory) | Pomerium](https://www.pomerium.com/docs/integrations/user-identity/azure#getting-groups)

---

<div class="post-metadata">

**Author:** ![DevOps\_saran](https://avatars.discourse-cdn.com/v4/letter/d/c6cbf5/32.png) [@DevOps\_saran](https://discuss.pomerium.com/u/DevOps_saran)\
**Post date:** [February 26, 2025, 9:19am UTC](https://discuss.pomerium.com/t/identity-manager-gets-403-when-trying-to-query-the-api/452/5 "2025-02-26T09:19:40Z")

</div>

> [@DevOps\_saran](#):
>
> `https://www.pomerium.com/docs/reference/identity-provider-refresh-directory-settings`

This URL does not work for checking details about the timeout …

> [@calebdoxsey](#):
>
> Some IdPs support populating claims with groups data and that can be used as a workaround: [Microsoft Entra ID (formerly Azure Active Directory) | Pomerium](https://www.pomerium.com/docs/integrations/user-identity/azure#getting-groups)

Yes we have done the config as same as in the documentation.

---

<div class="post-metadata">

**Author:** ![calebdoxsey](https://avatars.discourse-cdn.com/v4/letter/c/7bcc69/32.png) [@calebdoxsey](https://discuss.pomerium.com/u/calebdoxsey)\
**Post date:** [February 27, 2025, 4:03pm UTC](https://discuss.pomerium.com/t/identity-manager-gets-403-when-trying-to-query-the-api/452/6 "2025-02-27T16:03:48Z")

</div>

Yes sorry the URL no longer works because the option no longer exists in current versions of Pomerium. Here is a link to the old docs:

[https://0-21-0.docs.pomerium.com/docs/reference/identity-provider-refresh-directory-settings](https://0-21-0.docs.pomerium.com/docs/reference/identity-provider-refresh-directory-settings)
