AuthorizationPermissionMismatch 🔷 Azure

Azure Storage: AuthorizationPermissionMismatch (403) — This request is not authorized to perform this operation using this permission

You’re accessing blob/queue data with Microsoft Entra ID, but the identity has only management roles (Owner/Contributor) — not a *data* role.

Seen on: Azure

Meaning

Azure separates control plane (manage the storage account) from data plane (read/write blobs). Owner or Contributor does not grant data access when using Entra ID auth. You need a role like Storage Blob Data Reader/Contributor.

Common causes

  • Missing Storage Blob/Queue/Table Data role
  • Role assigned at a different scope (container vs account)
  • Role assignment still propagating
  • Firewall/network rules (that gives AuthorizationFailure instead)

⚡ Quick fix

  1. Assign “Storage Blob Data Contributor” (or Reader) to the identity on the account or container
  2. Wait a few minutes for propagation
  3. For quick tests, use a SAS token — but prefer Entra ID in production

Detailed fix by platform

Azure

  1. Assign a data role:
    bash
    az role assignment create --assignee <object-id> \
      --role "Storage Blob Data Contributor" \
      --scope $(az storage account show -n mystorage -g my-rg --query id -o tsv)

How to diagnose

  1. Auth type — Entra ID, account key or SAS?
  2. Roles — Any *Data* role on that scope?
  3. Network — Firewall/private endpoint blocking?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.