Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
If Cloud Management Gateway (CMG) creation fails, first identify the exact stage: Azure sign-in, subscription selection, configuration, provisioning, or client connectivity. Each points to a different cause. Capture the error and timestamp before changing or deleting resources, then match the symptom to the relevant Configuration Manager log and Azure deployment evidence.
Start by locating the failure
“CMG creation fails” is not a single error. A console crash after sign-in is different from an Azure capacity failure, a policy denial, or a CMG that deploys but cannot serve clients. Record the Configuration Manager current-branch version and update level, the last wizard page that worked, the complete error text, the Azure cloud, subscription and region, chosen VM size and instance count, resource-group name and location, and the failure time in UTC. Note whether the console itself failed or Azure provisioning did.
Use this quick map to choose where to investigate first:
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →| What you see | Check first | First action |
|---|---|---|
| Console closes after clicking Sign in | SMSAdminUI.log and Configuration Manager version |
Check for the version-specific Microsoft sign-in issue and applicable hotfix. |
| Subscription list is empty or permission error appears | Tenant, subscription role, active elevation, and sign-in token | Verify the documented account roles, then sign in again. |
VM size is unavailable or Azure reports AllocationFailure |
Selected region, VM-family quota, and regional capacity | Determine whether the problem is quota or actual SKU availability. |
| Azure deployment fails after resources start provisioning | CloudMgr.log, CMGSetup.log, deployment operations, and Activity Log |
Follow the explicit Azure error; check policy, location, permissions, and certificate details. |
| CMG exists but stays unready or clients cannot connect | Connection-point and service-health logs, then client and site-role configuration | Separate deployment health from post-deployment connectivity. |
Microsoft’s CMG setup documentation identifies CloudMgr.log and CMGSetup.log for deployment troubleshooting, and CMGService.log and SMS_Cloud_ProxyConnector.log for service and connection-point issues.
#1 Best Overall
- Server 2022 Standard 16 Core
If the console crashes after Azure sign-in
Microsoft documents a specific Configuration Manager console crash after signing in during CMG creation. It affects versions 2111, 2203, and 2207 and can be associated with Microsoft.Identity.Client.MsalUiRequiredException in SMSAdminUI.log. This is a console authentication issue, not proof that Azure provisioning failed.
- Version 2207: Microsoft’s fix is hotfix rollup KB15152495.
- Version 2203: Microsoft lists limited-release hotfix KB14244456 as a prerequisite to the applicable fix.
- Version 2111: Microsoft lists limited-release hotfix KB12896009 as a prerequisite to the applicable fix.
- Version 2211 and later: Microsoft says this particular issue does not occur in version 2211.
For applicable updates, use the console’s Administration > Updates and Servicing node and select Check for updates where appropriate. Follow Microsoft’s instructions for your exact version at its CMG sign-in crash troubleshooting article. These fixes address that version-specific crash; they are not a general remedy for Azure deployment failures.
If sign-in, tenant, or subscription selection fails
First make sure the signed-in account belongs to the Microsoft Entra tenant associated with the intended Azure subscription. Then check the roles required for the initial creation workflow. Microsoft’s CMG planning requirements specify an Azure subscription Owner, a Microsoft Entra Global Administrator, and a Configuration Manager Full administrator or Infrastructure administrator for creation. The setup flow, beginning with Configuration Manager version 2309, uses a Microsoft Entra tenant and app flow and authenticates with an Azure Subscription Owner account.
Do not assume that Contributor alone is sufficient, or that Global Administrator alone provides Azure subscription ownership. If your organization uses Privileged Identity Management (PIM), confirm that elevation is active for the whole setup session. After a role change, sign out and authenticate again so the wizard is not using an earlier token. Check Azure Activity Log for denied operations, role-assignment failures, or policy denials. A successfully created web app or resource group does not establish that all CMG permissions and authentication steps succeeded.
Global Administrator is a highly privileged role. Treat it as an initial-setup requirement stated in Microsoft’s CMG planning documentation where applicable, not as a reason to leave broad access assigned permanently. Have your identity and Azure administrators apply your organization’s least-privilege process after setup.
Rank #2
- LAPTOP TO SERVER: USB crash cart adapter connects your laptop to a headless system, turning your laptop into a portable console for rack servers in your server room, PCs, ATMs, kiosks, etc
- EFFICIENT TROUBLESHOOTING: Easily log server activity using the crash cart adapter software; For optimal performance, be sure to install the latest drivers; Note: Please make sure to download the drivers specifically for the NOTECONS01
- BIOS-LEVEL CONTROL: Connect the laptop crash cart adapter to your computer using the included USB cable, then connect the integrated USB and VGA cables to your server for instant BIOS-level control
- SELF-POWERED: The KVM adapter is powered by the server-side USB connection, reducing strain on the laptop's battery and eliminating the need for an AC outlet, allowing you to connect to any PC or device with a VGA output port and USB connection
- COMPACT DESIGN: This TAA Compliant pocket-sized data center crash cart adapter requires no additional accessories, eliminating the need to carry around a traditional crash cart/trolley when troubleshooting and servicing your systems
If the VM size is unavailable or Azure reports allocation failure
The VM choices documented for CMG include Standard (A2_V2) as the default, Large (A4_v2) for more capacity per VM, and Lab (B2s) for lab or small proof-of-concept use. Microsoft explicitly says B2s is not intended for production. The documented maximum is 16 VM instances per CMG. See Microsoft’s VM-size and instance guidance before changing the design.
Availability is specific to the subscription and region. Check both total regional vCPU quota and the quota for the VM family used by the selected SKU. Also check subscription restrictions, Azure Policy allowed locations or SKUs, and whether the region supports the selected size for your subscription.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteDistinguish two kinds of failure:
- Quota exhaustion: Your subscription is not allowed to allocate the requested vCPU capacity. A quota request may resolve this if the quota is the cause. Microsoft explains Azure VM quotas in its quota documentation.
- Regional capacity shortage: Azure cannot currently allocate that SKU in the selected region for your subscription. Increasing quota does not guarantee that capacity will become available. An approved alternate region or an Azure support case may be necessary.
If you consider another region, check data-residency and compliance requirements, client latency, allowed-location policies, certificate and DNS design, and any cross-region transfer implications before changing it. If the region is mandatory, contact Azure support with the subscription ID, region, VM SKU, exact allocation error, quota evidence, and deployment correlation ID. A region change is a possible workaround, not a guaranteed fix.
If the deployment fails during Azure provisioning
Open the selected resource group in the Azure portal and inspect its deployment history and individual deployment operations. Also check the subscription Activity Log, policy evaluation details, quota and usage, selected SKU availability, and any resources left by the failed deployment. Correlate Azure timestamps with entries in CloudMgr.log and CMGSetup.log; a final red status in the Configuration Manager console is not enough to identify the cause.
Search the relevant log window around the recorded failure time for terms such as Error, Failed, Exception, RequestDisallowedByPolicy, AuthorizationFailed, AllocationFailure, certificate, resource group, region, and quota. An error string is a lead to investigate, not proof of a root cause unless it states the failure explicitly.
Rank #3
- 14” Diagonal HD BrightView WLED-Backlit (1366 x 768), Intel Graphics
- Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD
- 1x USB Type C, 2x USB Type A, 1x SD Card Reader, 1x Headphone/Microphone
- 802.11a/b/g/n/ac (2x2) Wi-Fi and Bluetooth, HP Webcam with Integrated Digital Microphone
- Windows 11 OS
Check the resource-group location
Microsoft requires an existing resource group to be in the same region selected for the CMG. If the locations do not match, create a resource group in the intended CMG region or select an existing one there. Do not assume that moving a group after creation is equivalent to using a correctly located group: the CMG wizard validates the relationship between the selected region and resource group.
Free tools Windows power users keep installed
One-click scans. No signup required.
Check Azure Policy and resource restrictions
A policy can deny a deployment even when the account has sufficient permissions and quota. In the Activity Log and deployment operation details, look for policy evaluation results and restrictions on locations, VM SKUs, resource types, tags, or network settings. Resolve the specific policy or use an approved configuration; repeatedly retrying the same blocked deployment will not help.
Validate the CMG name and certificate
Microsoft’s documented CMG name rules are 3–24 alphanumeric characters, starting with a letter, ending with a letter or digit, and containing no consecutive hyphens. The CMG setup wizard requires a server authentication certificate. Its common name populates service and deployment-name fields; with a wildcard certificate, replace the wildcard with a globally unique deployment-name prefix. See Microsoft’s planning requirements and setup instructions.
Before retrying, check that the PFX includes its private key, the certificate is not expired, its subject or wildcard matches the intended CMG name, and its chain is trusted. Confirm that the certificate is usable by the relevant Configuration Manager site systems and CMG connection point. If certificate-revocation verification is enabled, Microsoft requires a publicly published certificate revocation list (CRL); check that it is reachable from where validation occurs.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Check the deployment method and prerequisites
For current Configuration Manager deployments, use the supported VM scale-set path. VM scale sets were introduced as a pre-release feature in version 2010 and became generally available in version 2107. Starting with version 2203, the classic cloud-service deployment option was removed and VM scale sets became the required method. Confirm the optional VM scale-set feature is enabled where your site version requires it, and do not rely on older instructions that tell current-branch administrators to create a new classic Azure Cloud Service.
Rank #4
- COMPACT DESIGN - The compact-designed portable BENFEI USB A/C to Ethernet adapter connects your computer or tablet to a router,modem or network switch for network connection. It adds a standard RJ45 port to your Ultrabook, notebook or Macbook Air for file transferring, video conferencing, gaming, and HD video streaming.
- SUPERIOR STABILITY - Built-in advanced IC chip works as the bridge between RJ45 Ethernet cable and your USB A/C devices. The driver-free installation with native driver support in Chrome, Mac, and Windows OS; The USB A/C Ethernet adapter dongle supports important performance features including Wake-on-Lan (WoL), Full-Duplex (FDX) and Half-Duplex (HDX) Ethernet, Crossover Detection, Backpressure Routing, Auto-Correction (Auto MDIX).
- INCREDIBLE PERFORMANCE - Supports full 10/100/1000Mbps gigabit ethernet performance over USB A/C's 5Gbps bus, faster and more reliable than most wireless connections. Link and Activity LEDs. USB powered, no external power required. Backward compatible with USB 2.0/1.1.✅ To reach 1Gbps, make sure to use CAT6 & up Ethernet cables.
- BROAD COMPATIBILITY - The USB A/C-Ethernet adapter is compatible with Windows 11/10/8.1/8/7/Vista/XP, Mac OSX 10.6/10.7/10.8/10.9/10.10/10.11/10.12, Linux kernel 3.x/2.6, Android and Chrome OS.Compatible with IEEE 802.3, IEEE 802.3u and IEEE 802.3ab. Supports IEEE 802.3az (Energy Efficient Ethernet).❌Do Not Support Windows RT. (NOT compatible with Nintendo Switch.)
- 18 MONTH WARRANTY - Exclusive BENFEI Unconditional 18-month Warranty ensures long-time satisfaction of your purchase; Friendly and easy-to-reach customer service to solve your problems timely.
Before another attempt, review Microsoft’s CMG prerequisites. They include an available Azure subscription in the correct tenant, Microsoft Entra integration for the Configuration Manager site, required administrator roles, an online service connection point, a Windows Server host for the CMG connection point, a management point configured for HTTPS or Enhanced HTTP, a valid CMG server authentication certificate, and supported naming and deployment settings. Check as well that the intended region and VM size are available and that Azure policy or resource restrictions do not block them.
After the Azure resource exists: verify CMG readiness and client access
An Azure resource appearing in the portal is not the same as a usable CMG. Complete the Configuration Manager side of the setup:
- In the console, go to Administration > Cloud Services > Cloud Management Gateway and create or review the gateway using the supported Azure environment, deployment method, certificate, region, resource group, VM size, and instance count.
- Monitor CMG status and investigate provisioning errors in
CloudMgr.logandCMGSetup.log. - Add the Cloud management gateway connection point site-system role. It relays requests between the Azure-hosted gateway and on-premises Configuration Manager roles.
- Configure the management point and software update point to accept CMG traffic, and configure the relevant client authentication method.
- Set up boundary groups and client settings to enable clients to use the CMG.
- If the CMG will distribute content, configure that option and its associated storage. Verify that the chosen client authentication and certificate-revocation settings are compatible with your deployment.
Use CMGService.log and SMS_Cloud_ProxyConnector.log when the gateway is deployed but service-health or connection-point behavior is the issue. A deployed gateway with client failures calls for checking the connection point, management point and software update point settings, authentication, boundary groups, and client settings—not automatically rebuilding Azure resources.
When to clean up or escalate
Do not delete and recreate the CMG as the first diagnostic step. Preserve the failure timestamp, Configuration Manager logs, Azure deployment operations, and Activity Log evidence. Review whether failed Azure resources are safe to remove and whether they contain anything the organization needs before cleanup. Once you have isolated and corrected the cause, remove failed resources according to your organization’s process and retry with the verified region, subscription, permissions, certificate, and deployment method.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsFor Microsoft support, provide the Configuration Manager version and update level, subscription ID, region and VM SKU, exact error, CMG name and resource group, UTC timestamp, Azure deployment or correlation ID, relevant log excerpts, and evidence of quota and policy checks. Use Azure support options for a demonstrated Azure capacity, quota, allocation, or subscription-platform issue; route Configuration Manager-specific console or site deployment faults through the appropriate Microsoft support channel.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

