ScopeLocked: The scope cannot perform write/delete operation because following scope(s) are locked
A resource lock (CanNotDelete or ReadOnly) on the resource, group or subscription blocks the change.
Seen on:
Azure
Meaning
ReadOnly locks also block operations that seem harmless (listing storage keys, scaling). Only users allowed to manage locks (Owner/User Access Administrator) can remove them.
Common causes
- CanNotDelete lock on resource/group
- ReadOnly lock blocking writes and some POST operations
- Lock inherited from a parent scope
⚡ Quick fix
- List locks on the scope and parents
- Remove or change the lock temporarily (with approval)
- Re-apply the lock afterwards
Detailed fix by platform
Azure CLI
- bash
az lock list -g rg-app -o table az lock delete --name protect -g rg-app
How to diagnose
- Locks — Resource, group, subscription
- Type — ReadOnly vs CanNotDelete
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- AnotherOperationInProgress Conflict: AnotherOperationInProgress — Another operation is in progress on the resource
- AuthorizationFailed Azure: AuthorizationFailed — The client does not have authorization to perform action
- InvalidTemplateDeployment ARM/Bicep: DeploymentFailed / InvalidTemplateDeployment / InvalidTemplate
Most viewed in Azure
- AADSTS50076 Azure AD (Entra ID): AADSTS50076 / AADSTS50079 — multi-factor authentication required
- AuthorizationPermissionMismatch Azure Storage: AuthorizationPermissionMismatch (403) — This request is not authorized to perform this operation using this permission
- AADSTS700016 Azure AD (Entra ID): AADSTS700016 Application not found in the directory
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026