ACS Call Automation PlayFailed error 8565 on TTS despite correct managed identity, role assignment, and multi-service Cognitive Services connection
Environment:
- Azure Communication Services:
amn-acs-prod (United States, global)
- Cognitive Services: multi-service
CognitiveServices kind, West US 2, S0 SKU
- SDK:
@azure/communication-call-automation v1.5.1
- Function App: Azure Functions (Node.js)
Problem:
Every playToAll TTS call fails immediately with:
json
{
"code": 400,
"subCode": 8565,
"message": "Action failed due to a bad request to Cognitive Services. Please check your input parameters."
}
The call connects successfully, CallConnected fires, playToAll returns HTTP 202, but PlayFailed with 8565 arrives ~1 second later every single time.
Everything configured correctly:
- ✅ Multi-service
CognitiveServices resource (not single Speech)
- ✅ System-assigned managed identity enabled on ACS
- ✅
Cognitive Services User role assigned to ACS managed identity at the Cognitive Services resource scope
- ✅ Resource connected via Portal under ACS → Cognitive Services
- ✅
cognitiveServicesEndpoint passed in answerCall options
- ✅ Voice
en-US-JennyNeural confirmed available in West US 2 via Voices List API
- ✅ No network/firewall restrictions on Cognitive Services resource
Code:
javascript
const answerOptions = {
callIntelligenceOptions: {
cognitiveServicesEndpoint: "https://westus2.api.cognitive.microsoft.com"
}
};
await client.answerCall(incomingCallContext, callbackUri, answerOptions);
// Later on CallConnected:
await callMedia.playToAll([{
kind: "textSource",
text: "Welcome to AMN Healthcare.",
voiceName: "en-US-JennyNeural",
sourceLocale: "en-US"
}], { operationContext: "greeting" });
Things already tried:
- Multiple Cognitive Services resources (eastus, westus2, single Speech, multi-service)
- Both regional endpoint format (
https://westus2.api.cognitive.microsoft.com) and resource-specific format (https://amn-ai-multisvc-prod.cognitiveservices.azure.com)
- With and without trailing slash on endpoint
- With and without
cognitiveServicesEndpoint in answerCall (Portal connection alone)
- Multiple voice names (NancyNeural, JennyNeural)
- Waited 10+ minutes for RBAC propagation between attempts
- Verified role assignment via
az role assignment list --scope <resource-id>
Correlation IDs:
-
0448001e-4c4b-4745-9faf-cabcf51af303
-
882d1b82-3188-4dbf-80e3-5ed9a1ea7d3b
-
6aef40b4-de1e-41e3-b528-08837dd1104a
Question:
Is there something beyond RBAC + Portal connection + correct endpoint that's required? Is there a known issue with new subscriptions or specific regions? The Portal connection UI also fails intermittently with a generic error when trying to connect the Cognitive Services resource, which makes me think there may be a backend provisioning issue.
Any help appreciated — this has been blocking for several hours.
That gives the community everything they need to help quickly.
Sonnet 4.6json
{
The call connects successfully, CallConnected fires, playToAll returns HTTP 202, but PlayFailed with 8565 arrives ~1 second later every single time.
Everything configured correctly:
- ✅ Multi-service
CognitiveServices resource (not single Speech)
- ✅ System-assigned managed identity enabled on ACS
- ✅
Cognitive Services User role assigned to ACS managed identity at the Cognitive Services resource scope
- ✅ Resource connected via Portal under ACS → Cognitive Services
- ✅
cognitiveServicesEndpoint passed in answerCall options
- ✅ Voice
en-US-JennyNeural confirmed available in West US 2 via Voices List API
- ✅ No network/firewall restrictions on Cognitive Services resource
Code:
javascript
const
Things already tried:
- Multiple Cognitive Services resources (eastus, westus2, single Speech, multi-service)
- Both regional endpoint format (
https://westus2.api.cognitive.microsoft.com) and resource-specific format (https://amn-ai-multisvc-prod.cognitiveservices.azure.com)
- With and without trailing slash on endpoint
- With and without
cognitiveServicesEndpoint in answerCall (Portal connection alone)
- Multiple voice names (NancyNeural, JennyNeural)
- Waited 10+ minutes for RBAC propagation between attempts
- Verified role assignment via
az role assignment list --scope <resource-id>
Correlation IDs:
-
0448001e-4c4b-4745-9faf-cabcf51af303
-
882d1b82-3188-4dbf-80e3-5ed9a1ea7d3b
-
6aef40b4-de1e-41e3-b528-08837dd1104a
Question:
Is there something beyond RBAC + Portal connection + correct endpoint that's required? Is there a known issue with new subscriptions or specific regions? The Portal connection UI also fails intermittently with a generic error when trying to connect the Cognitive Services resource, which makes me think there may be a backend provisioning issue.
Any help appreciated — this has been blocking for several hours.