685 questions with Azure Role-based access control tags

Sort by: Answers
10 answers

Storage Gen2 API in Postman

Hi , I am new to Azure Portal and would like to use the Azure Gen2 API to create the files on storage. I have been able to generate the access token in Postman - [https://login.microsoftonline.com/]()<tenant id>/oauth2/v2.0/token I now have access…

Azure Storage Explorer
Azure Storage Explorer
An Azure tool that is used to manage cloud storage resources on Windows, macOS, and Linux.
233 questions
Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
2,744 questions
Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
asked 2020-12-23T23:58:09.51+00:00
Shiv Khullar 1 Reputation point
answered 2021-03-05T12:32:26.663+00:00
Sumarigo-MSFT 44,001 Reputation points Microsoft Employee
8 answers

az ad group member list not returning results

In the version "azure-cli 2.40.0", the command "az ad group member list" returns an empty array even though the group has members, this used to work in the previous versions. For the same combination of group and member id the…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
asked 2022-09-08T17:27:57.17+00:00
Anonymous
commented 2023-07-21T09:17:33.77+00:00
RichardReeves-8228 0 Reputation points
7 answers

"Insufficient privileges to complete the operation" while using Graph API

The access token I get from the following curl request curl "$IDENTITY_ENDPOINT?resource=https://graph.microsoft.com&api-version=2017-09-01" -H secret:$IDENTITY_HEADER does not have the permission to list or create user. Request: GET…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,808 questions
asked 2020-12-14T17:46:54.273+00:00
Anonymous
commented 2024-05-16T04:29:36.67+00:00
Rav Panchalingam 0 Reputation points
6 answers One of the answers was accepted by the question author.

Authorization failed when when writing a roleAssignment

I'm receiving the following error when trying to create a role assignment using terraform: Error: authorization.RoleAssignmentsClient#Create: Failure responding to request: StatusCode=403 -- Original Error: autorest/azure: Service returned an error.…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,808 questions
asked 2021-02-24T21:50:28.377+00:00
Andrew 26 Reputation points
answered 2024-02-28T05:08:45.4233333+00:00
Mahmoud A. ATALLAH 191 Reputation points MVP
6 answers

Error when exectuing a powershell script aganist Azure

Hi, I've following the script, which gives me the output App name, Expires date, etc of App registration secrets that are expiring in 1 year. It is working fine for Azure Playgrounds, this playground is provided by Kodekloud. But when i execute the…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
Windows Server PowerShell
Windows Server PowerShell
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.PowerShell: A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
5,403 questions
asked 2022-08-19T14:37:30.213+00:00
Sharath chandra Gajjela 1 Reputation point
commented 2022-09-12T23:25:55.503+00:00
Olga Os - MSFT 5,836 Reputation points Microsoft Employee
5 answers

The request did not have a subscription or a valid tenant level resource provider.

When i trying to run command az ad sp create-for-rbac --role="Contributor" --scopes="/subscription/<<Subscription ID>>" I am getting error as (MissingSubscription) The request did not have a subscription or a valid tenant…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
Azure Kubernetes Service (AKS)
Azure Kubernetes Service (AKS)
An Azure service that provides serverless Kubernetes, an integrated continuous integration and continuous delivery experience, and enterprise-grade security and governance.
1,886 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,808 questions
asked 2023-09-06T07:58:53.3566667+00:00
Arun Kumar 0 Reputation points
commented 2024-02-06T16:34:19.02+00:00
João Pedro Bervalt 5 Reputation points
5 answers

locked out of directory because i removed account from mfa on my phone

hi - i have 2 directories in my azure portal. i can log into one and i can see the other but cannot switch to it, because i removed that account from the authenticator app on my phone (i know, silly) and it is set up to require mfa. trouble is, there are…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,975 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,808 questions
asked 2023-07-07T16:02:53.2866667+00:00
Aylmer Carson 0 Reputation points
commented 2023-07-11T16:07:31.8266667+00:00
Aylmer Carson 0 Reputation points
5 answers

Assigned "User Administrator" role to user, but user cannot reset a user password.

Hello! I've assigned the "User Administrator" role for a particular user we'd like to test. Role has been set to "active" in Privileged Access Management. Test user even gets the email that their access has been elevated in…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,808 questions
asked 2023-02-10T18:27:18.0466667+00:00
Dale Kinnear 0 Reputation points
edited a comment 2023-03-08T19:25:48.75+00:00
JamesTran-MSFT 36,476 Reputation points Microsoft Employee
5 answers One of the answers was accepted by the question author.

Get-AzWvdSessionHost gives error: Cannot bind argument to parameter 'SubscriptionId' because it is null.

Hi! I am getting an error, if I am tring to run the Get-AzWvdSessionHost command from a Powershell script. The error is: Cannot bind argument to parameter 'SubscriptionId' because it is null. If i am connecting in interactive mode, using…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
Windows Server PowerShell
Windows Server PowerShell
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.PowerShell: A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
5,403 questions
asked 2022-10-17T10:41:47.85+00:00
petersonal 86 Reputation points
commented 2022-10-24T16:21:39.203+00:00
Olga Os - MSFT 5,836 Reputation points Microsoft Employee
5 answers One of the answers was accepted by the question author.

Issue Capturing VM fortigate as an image

Hello i am trying to Capture an vm of fortigate as an image and it doesnt work does azure support capturing nva machines as an image? if no is there another way to save nva as an image ?

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
asked 2022-09-15T08:15:26.69+00:00
Slava Shishkin 21 Reputation points
answered 2022-09-15T13:28:37.42+00:00
Martin Dimovski 1,591 Reputation points MVP
4 answers

Missing Cosmos DB Built-in Data Reader and Cosmos DB Built-in Data Contributor roles in Access Control (IAM)

I'm trying to assign roles to managed identity in Cosmos DB, through browser using Access Control (IAM). Unfortunately two build in roles Cosmos DB Built-in Data Reader and Cosmos DB Built-in Data Contributor are not there. How can I add managed…

Microsoft Identity Manager
Microsoft Identity Manager
A family of Microsoft products that manage a user's digital identity using identity synchronization, certificate management, and user provisioning.
625 questions
Azure Cosmos DB
Azure Cosmos DB
An Azure NoSQL database service for app development.
1,469 questions
Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
asked 2023-02-01T15:31:32.8+00:00
Jacek Przezdziecki (ext) 15 Reputation points
commented 2024-05-17T11:55:19.7933333+00:00
AGA 0 Reputation points
4 answers One of the answers was accepted by the question author.

Azure Service Principal owner cannot reset credentials with az cli

Hello, as an Azure subscription admin I created a service principal and granted another user as Owner of the SP itself. This user is trying to reset SP credentials with command az ad sp credential reset --id <application id> but he gets the…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
asked 2023-07-05T16:43:30.74+00:00
Repetti Pierangelo 20 Reputation points
accepted 2023-09-29T09:45:04.19+00:00
Repetti Pierangelo 20 Reputation points
4 answers One of the answers was accepted by the question author.

Azure Management Group - Cannot add subscription if Owner via Security Group

I'm building an Azure Management Group structure where I'm having issues with the add subscription option to a sub-management group where the option is grayed out when Owner role is assigned via and AAD Security group. So in short, does Azure Management…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
asked 2023-08-30T12:40:03.0966667+00:00
EPNAdam 35 Reputation points
accepted 2023-09-07T07:39:33.9533333+00:00
EPNAdam 35 Reputation points
4 answers

correct way to give read permission to view multiple app services

Hi What would the correct way be to assign read permissions to all app services? I'm currently giving read access to the sub but that is more than is needed I also don't want to have to assign the permissions to each individual app service …

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
7,005 questions
asked 2022-12-15T16:24:10.727+00:00
doug 1 Reputation point
answered 2022-12-20T19:09:31.88+00:00
TP 78,826 Reputation points
4 answers One of the answers was accepted by the question author.

Azure RBAC and AKS not working as expected

Hello, I have create an AKS Cluster with AKS-managed Azure Active Directory and Role-based access control (RBAC) Enabled. If I try to connect with the Cluster by using one of the accounts which are included in the Admin Azure AD groups…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
Azure Kubernetes Service (AKS)
Azure Kubernetes Service (AKS)
An Azure service that provides serverless Kubernetes, an integrated continuous integration and continuous delivery experience, and enterprise-grade security and governance.
1,886 questions
asked 2021-10-19T07:00:23.883+00:00
Mile Mitsev 21 Reputation points
answered 2021-10-22T12:41:31.113+00:00
Mile Mitsev 21 Reputation points
4 answers One of the answers was accepted by the question author.

Azure PIM for global reader role - No resources to discover

Hi everyone, I'm currently testing Azure PIM to delegate read permissions to our Azure tenant. I've assigned with PIM the "Global reader" role for a test account, which has validated the access. The scope defined is…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
Microsoft Entra
asked 2021-08-18T15:08:00.467+00:00
Arnaud Rigole 126 Reputation points
accepted 2021-08-30T15:22:45.977+00:00
Arnaud Rigole 126 Reputation points
4 answers One of the answers was accepted by the question author.

Azure - Failed to delete public IP address The client 'XXX@XXXX.com' with object id XYZ does not have authorization to perform action 'Microsoft.Network/publicIPAddresses/delete' over scope 'XYZ'

User is global administrator. Cannot delete resources in the tenancy. Any idea why? Failed to delete public IP address 'XYZ'. Error: The client 'Tech.XYZ@Anonymous .com' with object id 'XYZ' does not have authorization to perform action…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
Azure Stack Hub
Azure Stack Hub
An extension of Azure for running apps in an on-premises environment and delivering Azure services in a datacenter.
180 questions
asked 2020-06-09T17:59:58.413+00:00
Tech Support 96 Reputation points
answered 2020-06-09T18:54:21.817+00:00
Manu Philip 16,991 Reputation points MVP
3 answers

Error during POD deployment for configuring Workload identity

I follow this document, https://learn.microsoft.com/en-us/azure/aks/learn/tutorial-kubernetes-workload-identity#create-an-aks-cluster And seeing this error on running logs command for the pod kubectl logs pods/mypod I am learning this topic, not sure…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
asked 2024-03-26T12:18:57.9+00:00
Sriramulu, Latha 0 Reputation points
commented 2024-04-09T11:27:25.8166667+00:00
Akshay-MSFT 16,436 Reputation points Microsoft Employee
3 answers

Difficulty creating a custom role with specific permissions

Hello, I am trying to create a custom role on the Azure portal that includes a number of permissions from the existing Auth Admin role. However, I cannot find certain permissions such as microsoft.directory/users/authenticationMethods/create,…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
asked 2023-09-04T22:21:58.8266667+00:00
Hari Sheth 0 Reputation points
commented 2024-04-05T11:49:05.87+00:00
Saurabh Shivalkar 0 Reputation points
3 answers

User don’t have authorization to perform action 'Microsoft.Resources/deployments/validate/action

Whenever a new user added to the directory tries to deploy custom azure templates, they get the following validation error - User don't have authorization to perform action 'Microsoft.Resources/deployments/validate/action Following roles are already…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
685 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,808 questions
asked 2021-06-13T06:29:32.047+00:00
Rabia Mehta 11 Reputation points
commented 2024-03-31T00:07:54.87+00:00
Intikhab Alam 0 Reputation points