AuthorizationFailed 🔷 Azure

Azure: AuthorizationFailed — The client does not have authorization to perform action

The signed-in identity (user, service principal or managed identity) lacks an Azure RBAC role for that action on that scope.

Seen on: Azure

Meaning

Azure Resource Manager checks role assignments at management group → subscription → resource group → resource scope. The message names the identity (object ID), the action (e.g. Microsoft.Storage/storageAccounts/write) and the scope — everything you need to grant the right role.

Common causes

  • No role assignment at that scope (or only at a narrower scope)
  • Role lacks the specific action (Reader trying to write)
  • New role assignment not yet propagated (can take a few minutes)
  • Pipeline/service principal different from the one you granted
  • Deny assignments or Azure Policy blocking the action

⚡ Quick fix

  1. Read the object ID, action and scope from the message
  2. Assign the least-privileged built-in role that includes the action at the right scope
  3. Wait a few minutes and refresh credentials (az account clear && az login)

Detailed fix by platform

Azure

  1. Grant a role to a service principal at resource-group scope:
    bash
    az role assignment create \
      --assignee <object-or-app-id> \
      --role "Contributor" \
      --scope /subscriptions/<sub-id>/resourceGroups/<rg-name>
    az role assignment list --assignee <object-or-app-id> --all -o table

How to diagnose

  1. Identity — Which object ID is denied?
  2. Action — Which action is required?
  3. Scope — Where is the role assigned vs where you act?
  4. Policy — Any deny assignment or policy?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.