Home Support Documentation Privacy Terms Licenses

Overview

Introduction How it works

Get started

Prerequisites Marketplace install Entra prerequisites Admin authorization Setup wizard Hostname & TLS

Operate

Daily operations Updates & plans Restricted networks

Troubleshoot

Recover admin access

Legal

Open source notices

Support

Get help

Recover admin access

Last updated: 20 September 2026

Goal: Restore Sandman admin access without SSH when Entra assignments are wrong.

  1. Entra — Create or fix the admin app role and assign yourself under Enterprise applications → Users and groups.
  2. Azure Portal → VM → Networking — Add a temporary inbound rule: port 8091, source your admin IP (x.x.x.x/32).
  3. Azure Portal → VM → Run command — Run: sudo sandman config enable. Copy the maintenance token and URL from the output.
  4. Browser — Open the URL, paste the token if prompted, update admin authorization in Settings, click Apply changes.
  5. Run command — Run: sudo sandman config disable
  6. Networking — Remove the temporary port 8091 rule.
Azure Portal VM Run command output showing maintenance mode token.
Figure 7. Azure Portal Run command — enable maintenance mode and obtain the maintenance token.

Verify: Sign in at https://<your-host>/ with admin navigation visible. SSH (sudo sandman config enable) remains available as break-glass.

© 2026 Sandman