RBAC & PermissionsAzure Resource ManagerKnown error
LinkedAuthorizationFailed
You can create it, but not link it
RBAC โ linked resource permission
What the error looks like
- Error code
- WHO โ identity
- WHAT โ action
- WHERE โ scope
- Policy
- Correlation / trace
{
"error": {
"code": "LinkedAuthorizationFailedCODE",
"message": "The client 'b2c3d4e5-0000-4000-8000-000000000002WHO' with object id 'b2c3d4e5-0000-4000-8000-000000000002WHO' has permission to perform action 'Microsoft.Network/networkInterfaces/writeWHAT' on scope '/subscriptions/00000000-1111-4222-8333-444444444444/resourceGroups/rg-app/providers/Microsoft.Network/networkInterfaces/nic-app01WHERE'; however, it does not have permission to perform action 'Microsoft.Network/virtualNetworks/subnets/join/actionWHAT' on the linked scope(s) '/subscriptions/00000000-1111-4222-8333-444444444444/resourceGroups/rg-network/providers/Microsoft.Network/virtualNetworks/vnet-hub/subnets/snet-appWHERE' or the linked scope(s) are invalid."
}
}What you told me
โBut I'm Contributor!โ
you ยท just now
Let's read it.
RTFE ยท seen
What it actually says
You're Contributor on the resource group you're deploying into. The resource references something in another scope (often a subnet in a network resource group), and you need a permission there too โ typically subnets/join/action.
Azure outage? No. Two scopes, one permission missing. The error names the linked scope.
The fix
- 01Find the second action in the error โ the one after 'however'.
- 02Find the linked scope. It is usually a different resource group or subscription.
- 03Grant a role containing that action on the linked scope (e.g. Network Contributor on the subnet, or a narrow custom role with subnets/join/action).
az role assignment create \
--assignee-object-id <object-id> \
--assignee-principal-type ServicePrincipal \
--role "Network Contributor" \
--scope <linked-subnet-scope>Read it faster next time
Contributor is scoped. 'I'm Contributor' always needs the follow-up question: on what?