Skip to content
RTFE_
Error library
RBAC & PermissionsAzure Resource ManagerKnown error

AuthorizationFailed

The identity is missing a permission

RBAC โ€” missing permission

What the error looks like

  • Error code
  • WHO โ€” identity
  • WHAT โ€” action
  • WHERE โ€” scope
  • Policy
  • Correlation / trace
{
  "error": {
    "code": "AuthorizationFailedCODE",
    "message": "The client 'a1b2c3d4-0000-4000-8000-000000000001WHO' with object id 'a1b2c3d4-0000-4000-8000-000000000001WHO' does not have authorization to perform action 'Microsoft.Storage/storageAccounts/writeWHAT' over scope '/subscriptions/00000000-1111-4222-8333-444444444444/resourceGroups/rg-prod/providers/Microsoft.Storage/storageAccounts/stprodlogs001WHERE' or the scope is invalid. If access was recently granted, please refresh your credentials."
  }
}

What you told me

โ€œAzure is broken.โ€

you ยท just now

Let's read it.

RTFE ยท seen

What it actually says

The named identity lacks permission for the exact action on the exact scope. The error tells you all three: who (the client / object ID), what (the action), and where (the scope).

Azure outage? No. This is an RBAC denial. Azure did exactly what the role assignments told it to.

The fix

  1. 01Copy the object ID from the error. That is WHO โ€” not you, if a pipeline is running it.
  2. 02Copy the action. That is WHAT โ€” find a built-in role that contains it (or a custom role).
  3. 03Copy the scope. That is WHERE โ€” assign the role at that scope or a parent of it.
  4. 04Wait a few minutes. Role assignments can take time to propagate; refresh credentials / re-run the pipeline.
Azure CLI โ€” check existing assignments
az role assignment list \
  --assignee <object-id> \
  --all -o table
Azure CLI โ€” assign a role
az role assignment create \
  --assignee-object-id <object-id> \
  --assignee-principal-type ServicePrincipal \
  --role "<role-name>" \
  --scope <scope>
PowerShell
New-AzRoleAssignment `
  -ObjectId <object-id> `
  -RoleDefinitionName "<role-name>" `
  -Scope <scope>

Read it faster next time

When you see AuthorizationFailed, stop reading the deployment summary and find the action + scope.

Further reading

Open Microsoft Learn

Related errors