Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
Though I am sure, you have validated the IAM role can you try below link as a solution which confirms the correct role "Storage Blob Data Contributor" to be assigned to the account used for AZcopy along with Owner permissions to the account (service principal) used having the Owner Role on the blob storage.
Ref : https://nishantrana.me/2020/11/23/fixed-authorizationpermissionmismatch-azure-blob-storage/