Azure: AuthorizationFailed — The client does not have authorization to perform action
The signed-in identity (user, service principal or managed identity) lacks an Azure RBAC role for that action on that scope.
Seen on:
Azure
Meaning
Azure Resource Manager checks role assignments at management group → subscription → resource group → resource scope. The message names the identity (object ID), the action (e.g. Microsoft.Storage/storageAccounts/write) and the scope — everything you need to grant the right role.
Common causes
- No role assignment at that scope (or only at a narrower scope)
- Role lacks the specific action (Reader trying to write)
- New role assignment not yet propagated (can take a few minutes)
- Pipeline/service principal different from the one you granted
- Deny assignments or Azure Policy blocking the action
⚡ Quick fix
- Read the object ID, action and scope from the message
- Assign the least-privileged built-in role that includes the action at the right scope
- Wait a few minutes and refresh credentials (
az account clear && az login)
Detailed fix by platform
Azure
- Grant a role to a service principal at resource-group scope:bash
az role assignment create \ --assignee <object-or-app-id> \ --role "Contributor" \ --scope /subscriptions/<sub-id>/resourceGroups/<rg-name> az role assignment list --assignee <object-or-app-id> --all -o table
How to diagnose
- Identity — Which object ID is denied?
- Action — Which action is required?
- Scope — Where is the role assigned vs where you act?
- Policy — Any deny assignment or policy?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026