ScopeLocked 🔷 Azure

ScopeLocked: The scope cannot perform write/delete operation because following scope(s) are locked

A resource lock (CanNotDelete or ReadOnly) on the resource, group or subscription blocks the change.

Seen on: Azure

Meaning

ReadOnly locks also block operations that seem harmless (listing storage keys, scaling). Only users allowed to manage locks (Owner/User Access Administrator) can remove them.

Common causes

  • CanNotDelete lock on resource/group
  • ReadOnly lock blocking writes and some POST operations
  • Lock inherited from a parent scope

⚡ Quick fix

  1. List locks on the scope and parents
  2. Remove or change the lock temporarily (with approval)
  3. Re-apply the lock afterwards

Detailed fix by platform

Azure CLI

  1. bash
    az lock list -g rg-app -o table
    az lock delete --name protect -g rg-app

How to diagnose

  1. Locks — Resource, group, subscription
  2. Type — ReadOnly vs CanNotDelete

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.