ACAT report creation fails with "Permission check failed" despite the account holding all documented required roles on the target subscription.

Marney Edwards 20 Reputation points
2026-06-11T18:07:57.2666667+00:00

Here's the ticket body — paste-ready:


Summary: ACAT report creation fails with "Permission check failed" despite the account holding all documented required roles on the target subscription.

Details:

Creating a compliance report in the App Compliance Automation Tool for Microsoft 365 (Azure portal) fails repeatedly with:

Error: Permission check failed, due to you miss below required permission(s). Missed permission: [{"SubscriptionId":"0fa51402-217b-4a30-8942-752ac7172417","MissedPermissions":["Microsoft.Authorization/policyAssignments/delete", ...]}] (Code: Forbidden)

Failed attempts (correlation IDs):

  1. 211f7f77-4471-49c3-9161-57de88c49ffb
  2. 78df00e6-0c65-4fd8-boc1-19b3f20a8874
  3. 59f48d0a-0f07-4d5a-a248-df2f4005890e

Account: [******@pansophyai.com] (Global Administrator of the tenant)

Role assignments on subscription 0fa51402-217b-4a30-8942-752ac7172417, verified via az role assignment list immediately before the third attempt:

  • Owner
  • App Compliance Automation Administrator
  • Resource Policy Contributor

The latter two were assigned per the remediation in the ACAT troubleshooting documentation (aka.ms/acat-troubleshooting). The third failure occurred more than 10 minutes after assignment, after signing out of the portal and back in, so token/RBAC propagation should not be a factor. Owner already includes all Microsoft.Authorization/policyAssignments/* actions the error lists as missing.

Report being created: offer pansophy-mcp-server (Second Opinion for Sales), publisher pansophyaiinc1775341545935.

Request: Please advise what ACAT's permission check is evaluating that these roles do not satisfy, or whether this is a known issue with the preview evaluator.

Cost Management
Cost Management

A Microsoft offering that enables tracking of cloud usage and expenditures for Azure and other cloud providers.


Answer accepted by question author
Suchitra Suregaunkar 16,780 Reputation points Microsoft External Staff Moderator
2026-06-11T18:29:44.0233333+00:00

Hello Marney Edwards

Thank you for posting your query on Microsoft Q&A platform.

Based on the ACAT troubleshooting guidance you referenced, ACAT performs permission checks in the subscription scope(s) relevant to the report creation. The documented minimum roles for administrator operations like creating reports are:

  • App Compliance Automation Administrator
  • Resource Policy Contributor

And the troubleshooting guide also calls out this general verification approach:

  • In the target subscription, check Access control (IAM) > View my access and confirm your role assignments include the required ACAT permissions for that subscription.

Why you might still see missing permissions:

From your error, ACAT is specifically complaining about missing Azure Policy assignment delete capability, e.g.:

  • Microsoft.Authorization/policyAssignments/delete

Even if your role assignments look correct (and Owner normally includes broad permissions), an ACAT-style permission check can still fail if:

  • the effective permissions at the exact scope/time of the operation don’t include what the ACAT workflow expects (for example due to policy/RBAC evaluation nuances), or
  • the operation is being evaluated across additional subscription scopes/resources beyond the one you checked (ACAT reports can rely on cloud resources that may span multiple subscriptions).

The ACAT docs explicitly mention that compliance report resources can span multiple subscriptions, and you need the appropriate roles for the corresponding subscriptions.

What to try next (practical checks):

  1. Confirm access at the subscription scope(s) actually involved
    • In the Azure portal, open the Subscriptions blade and go to the relevant subscription(s).
    • For each subscription that could be involved in report creation, check IAM > View my access.
    • Ensure you have App Compliance Automation Administrator and Resource Policy Contributor on every corresponding subscription involved (not just the one where you checked with az role assignment list).
  2. Re-check the operation from the same account context
    • Since you already tried waiting for propagation and re-signing, the remaining likely causes are scope coverage (additional subscriptions) or effective RBAC evaluation differences.
  3. If you’re using preview tooling / evaluator
    • With the info provided, we can’t confirm a known preview-evaluator issue from the documents you supplied, so it’s safest to treat this as a permissions/scope coverage evaluation until proven otherwise

Thanks,
Suchitra.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.