Urgent Issue with Role Assignment in Azure – "MissingSubscription" Error
Issue: Unable to Assign Role to ACR - MissingSubscription Error Problem Description: I encountered an issue while trying to assign the AcrPull role to a service principal for my Azure Container Registry (ACR). Every time I run the following command: az…
Azure resource sharing among multiple users
I have created few resources under Startup Subscription, however even after trying many times and many options, I am unable to add another user to see these resources and use them (e.g. DB Creation, App deployment etc.). Can you please suggest the steps…
Unusual Activity Detected: Full Deny Assignment for User
A full deny assignment was detected on ********* for user ******** at the root level. The deny assignment was added at the scope / for user ***********. What could be the implications of this unusual activity? Though i have marked my account ( service…
Unable to Update Azure Role for a Subscription although i have Owner and User Access Admin rights at that Subscription
Unable to Update Azure Role for a Subscription although i have Owner and User Access Admin rights at that Subscription, It gives error The requestor XXX does not have permissions for this request. Please use $filter=asTarget() to filter on the…
Difference between Global Admin and Owner in Microsoft Azure
Hi guys, So far, I know that Global Administrator is an Azure AD built-in role that manage access to all the administrative features in Azure AD and Owner is an RBAC role that has full access to all Azure resources. But what are the other differences…
How to list eligible roles in PIM assigned with a group in PIM?
How to list eligible roles in PIM assigned with a group in PIM even if the role hasn't been enabled yet. We assign privileged roles with role-assigned groups with PIM but eligible roles. if the user has enabled his roles on the "My Roles"…

I cannot remove Resource Group and its resources due to system defined RBAC deny assignments
I have created an Automatic Azure Kubernetes Cluster with managed Prometheus monitoring and Managed Grafana instance for visualization. When I remove Resource Group in which cluster resource resides, the automatically created Resource Group with Azure…
Is it possible to create a Redirect URI via an API call instead of using the Azure portal? Trying to automate.
I am trying to figure out if it is possible to create a Redirect URI in Azure WITHOUT going through the Azure portal? I understand how to add a Redirect URI for doing AD authentication for my application, but I would like to automate the creation of this…
How to configure "Europe Access Only" for resources in Azure Subscription instead of Tenant
Our objective is to restrict access to resources within our Azure subscription to ensure that personal data remains inaccessible to operators and end-users located outside the EEA (European Economic Area) or Switzerland. Could you please share any clear…
Azure KeyVault Data Access Administrator Role can't assign KeyVault Certificate User role
The KeyVault Data Access Administrator role is meant to be used to assign permissions for other KeyVault related roles, however it appears the KeyVault Certificate User was missed and cannot be assigned by the KV Data Access Administrator role. So, at…
[UnusualActivity] Full Deny assignment
I can't perform any action on my account using my student credit . I can't create nor manage any resource even though I still have unused credits and valid azure account. The client with object id '.............' has permission to perform action…
A resource owner is on leave, and you urgently need to assign roles to manage Azure resources.
i need to assign the role for the particular user to access the azure active directory
how to get the list of SPN role assignment access
We assigned built-in roles and custom roles to the service principle, but where we are check all SPN access list? when we go to subscription and can verify the roles.
Unable to get email alert for PIM role activation
Hello, we used to receive emails from Microsoft Azure for the PIM roles activation but It just stopped. Nothing changed just we are no longer receiving emails for role activation. Can you please help me with this? Thanks!

Need MFA reset for Tenant Admin
Hi Team, Need your help in resetting the MFA for one of the Tenant admins in Azure portal. Kindly let me know the steps to do the same.

No rights to delete a subscription
I have an old tenant from a company I shutdown a few years ago. I want to delete the tenant but there is still a subscription in the tenant and that is blocking the deletion. So, I try to cancel the subscription. I don't have rights. I am the 'Global…
How can I assign granular RBAC rights to Defender EASM Azure Resource
When creating a Defender EASM Resource in Azure, there is no possibility to granularly assign RBAC Roles to this resource. In the Defender EASM Portal the "IAM" Section is missing for role assignment. However in order to create the resource you…

After creating Azure compute gallery and making it public unable to find images in it via it's Community gallery name
Hi, I have created Azure compute gallery with Community sharing type, via both Azure portal and Azure cli, by following official documentation, but was unable to list VM images that I have created in it from VM in azure community images both via image…
Azure Function App Read-only on functions
How can I create a custom role in Azure that allows users to view Function App code in read-only mode? Currently, users with the built-in Reader role can see the Function App but get an error requiring write permissions when trying to view the actual…
Access control (IAM) Issue - Creating is greyed out
I am owner of a MS Action Pack Subscription. I cannot find out why i am not able to create role assignents in Access control (IAM) anymore. I stuck in the last menu. The create button is greyed out.