@Olav Henrik Hoggen Thank you for reaching out to us.
This is a by design behavior as creating azure sandbox only provides user with contributor access so anything with AAD/RBAC will result in permission error.
Given that, we should be converting this module to use BYOS model – bring your own subscription in order for users to complete the provided steps.
We will be making the required changes within the module at earliest.
Let me know if you have any further questions.
Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.