Usually as per the error it looks like an issue with RBAC roles not assigned properly. You will have to assign a specific role to service principle on the subscription level. Role that should be assigned to service principal should have 'Microsoft.Network/networkSecurityGroups/read' permission in it.
Can we work on this issue offline.
Please send us an email on azcommunity [at] microsoft [dot] com with Sub - Attn: Sandeg and following details in the email body:
Link to this thread/post
We can connect offline and discuss further on this.