Access Request - Azure Policy/Management Group RBAC

Cedric Garner 0 Reputation points Microsoft Employee
2026-04-15T20:24:10.9733333+00:00

I am attempting to deploy an Azure AI Foundry resource and am being blocked by policy evaluation due to missing permission to read a management group–level policy assignment.

Error: The client '******@xxxxxxxxxx.com' does not have authorization to perform action 'Microsoft.Authorization/policyAssignments/read' over scope '/providers/Microsoft.Management/managementGroups/4ab550xxxxxxxxxxxxxxxxx/providers/Microsoft.Authorization/policyAssignments/CloudGov_AISer_DLPEnable'

Requesting RBAC assignment that grants: Microsoft.Authorization/policyAssignments/read

At scope: /providers/Microsoft.Management/managementGroups/4ab550xxxxxxxxxxxxxxxxxxxxx

Required to deploy Azure AI Foundry resources in compliance with CloudGov AI Service DLP policy.

Azure Role-based access control
Azure Role-based access control

An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.