Azure KeyVault Data Access Administrator Role can't assign KeyVault Certificate User role
The KeyVault Data Access Administrator role is meant to be used to assign permissions for other KeyVault related roles, however it appears the KeyVault Certificate User was missed and cannot be assigned by the KV Data Access Administrator role. So, at…
![](https://techprofile.blob.core.windows.net/images/m5buVEA_QUeJ9P_0vgAtbg.png?8DACCA)
Cannot obtain permission to edit container App
My administrator has given me all the roles that seem remotely relevant to editing Container Apps, such as Container Apps ConnectedEnvironments Contributor Container Apps Contributor Container Apps ManagedEnvironments Contributor Container Apps…
Can't access Account Admin that created Pay-as-you-go subscription so cant update billing info
Hi everyone! I am running into an irritating issue with billing update. We cant gain access to the user account that created a pay as you go subscription and due to this we cant update the payment method to pay a due invoice. I have access to a…
how to get the list of SPN role assignment access
We assigned built-in roles and custom roles to the service principle, but where we are check all SPN access list? when we go to subscription and can verify the roles.
Unable to get email alert for PIM role activation
Hello, we used to receive emails from Microsoft Azure for the PIM roles activation but It just stopped. Nothing changed just we are no longer receiving emails for role activation. Can you please help me with this? Thanks!
![](https://techprofile.blob.core.windows.net/images/e7s9gP8_AwAAAAAAAAAAAA.png?8DB21C)
How to configure "Europe Access Only" for resources in Azure Subscription instead of Tenant
Our objective is to restrict access to resources within our Azure subscription to ensure that personal data remains inaccessible to operators and end-users located outside the EEA (European Economic Area) or Switzerland. Could you please share any clear…
![](https://techprofile.blob.core.windows.net/images/e7s9gP8_AwAAAAAAAAAAAA.png?8DB21C)
Need MFA reset for Tenant Admin
Hi Team, Need your help in resetting the MFA for one of the Tenant admins in Azure portal. Kindly let me know the steps to do the same.
![](https://techprofile.blob.core.windows.net/images/e7s9gP8_AwAAAAAAAAAAAA.png?8DB21C)
No rights to delete a subscription
I have an old tenant from a company I shutdown a few years ago. I want to delete the tenant but there is still a subscription in the tenant and that is blocking the deletion. So, I try to cancel the subscription. I don't have rights. I am the 'Global…
How can I assign granular RBAC rights to Defender EASM Azure Resource
When creating a Defender EASM Resource in Azure, there is no possibility to granularly assign RBAC Roles to this resource. In the Defender EASM Portal the "IAM" Section is missing for role assignment. However in order to create the resource you…
![](https://techprofile.blob.core.windows.net/images/A_IwTKcWAQAAAAAAAAAAAA.png?8D8142)
After creating Azure compute gallery and making it public unable to find images in it via it's Community gallery name
Hi, I have created Azure compute gallery with Community sharing type, via both Azure portal and Azure cli, by following official documentation, but was unable to list VM images that I have created in it from VM in azure community images both via image…
How to control access to a folder in ADLS gen2 container while Storage account IAMs are in action
Hi, I have a synapse pipeline that saves an output file in a folder (ex: salary) in an ADLS container (ex: employee). Now Mr. X wants the data saved in the folder to be accessible only to him but storage account level IAMs have already given access to…
Azure Function App Read-only on functions
How can I create a custom role in Azure that allows users to view Function App code in read-only mode? Currently, users with the built-in Reader role can see the Function App but get an error requiring write permissions when trying to view the actual…
A resource owner is on leave, and you urgently need to assign roles to manage Azure resources.
i need to assign the role for the particular user to access the azure active directory
Access control (IAM) Issue - Creating is greyed out
I am owner of a MS Action Pack Subscription. I cannot find out why i am not able to create role assignents in Access control (IAM) anymore. I stuck in the last menu. The create button is greyed out.
[UnusualActivity] Full Deny assignment
I can't perform any action on my account using my student credit . I can't create nor manage any resource even though I still have unused credits and valid azure account. The client with object id '.............' has permission to perform action…
How to use Azure C# SDK to retriever filtered role assignments
I'm starting to feel like Azure C# SDK does not provide a way for me to list all role assignments a user has been assigned directly or indirectly assigned at a given scope (e.g. subscription). I know this is supported via the underlying REST API and…
Issue with roles and admin assignments
There was an issue with the roles and admins assignments. The assigned users were 14 members and Im able to see the assigned users as 15. What was the issue. Is the group name also added into the assigned users count.
azure owner roles issue
Hi Team, accidentally i was deleted my owner role attached to the my subscription . and now i am unable to perform operations in my account. could you please help me on this issue
Azure Service Health for Subscription ID
Hello, We got a following mail from [azure-noreply@microsoft.com] to ******@some.hidden.company.com. But we dont have this Subscription ID someidid-****-****-81ef-hiddenhidden in our Azure account. Can you please help us how can we find the this …
How to apply roleAssignment write permissions to an application registration
Hey, i have an application registration to grant a terraform pipeline access to azure. The application registration has the contributor role on subscription scope. But Terraform now needs to be able to asign roles inside a resource group that was created…