'Microsoft.Network/networkManagers/networkGroups/join/action' permission

Garsha Rostami 121 Reputation points
2024-12-09T15:24:45.8633333+00:00

When I try to create a policy on an Azure policy on a Network Manager managed group, I get the following error (both in bicep code and also when using the Azure UI). Anybody has run into this? Specifically is 'Microsoft.Network/networkManagers/networkGroups/join/action' some new permission? I am an admin at the subscription and I'm still getting this error. Any help is appreciated!

'The client with object id '*

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
939 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Pranay Reddy Madireddy 1,230 Reputation points Microsoft Vendor
    2024-12-10T12:57:35.15+00:00

    Hi Garsha Rostami

    Welcome to the Microsoft Q&A Platform! Thank you for asking your question here.

    To successfully create and assign policies that involve network groups in Azure, the following permissions are required:
    https://learn.microsoft.com/en-us/azure/templates/microsoft.authorization/policyassignments?pivots=deployment-language-bicep

    https://learn.microsoft.com/en-us/azure/templates/microsoft.authorization/policydefinitions?pivots=deployment-language-bicep

    You need the Microsoft.Network/networkManagers/networkGroups/join/action permission on the target network group in your policy. This permission allows you to add resources to that network group.

    Network Contributor: Grants permissions to manage network resources, including network groups.

    Resource Policy Contributor: Allows management of policy definitions and assignments.

    If you have any further queries, do let us know.


    If the answer is helpful, please click "Accept Answer" and "Upvote it".

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.