A Microsoft offering that enables tracking of cloud usage and expenditures for Azure and other cloud providers.
Hello Marney Edwards
Thank you for posting your query on Microsoft Q&A platform.
Based on the ACAT troubleshooting guidance you referenced, ACAT performs permission checks in the subscription scope(s) relevant to the report creation. The documented minimum roles for administrator operations like creating reports are:
- App Compliance Automation Administrator
- Resource Policy Contributor
And the troubleshooting guide also calls out this general verification approach:
- In the target subscription, check Access control (IAM) > View my access and confirm your role assignments include the required ACAT permissions for that subscription.
Why you might still see missing permissions:
From your error, ACAT is specifically complaining about missing Azure Policy assignment delete capability, e.g.:
-
Microsoft.Authorization/policyAssignments/delete
Even if your role assignments look correct (and Owner normally includes broad permissions), an ACAT-style permission check can still fail if:
- the effective permissions at the exact scope/time of the operation don’t include what the ACAT workflow expects (for example due to policy/RBAC evaluation nuances), or
- the operation is being evaluated across additional subscription scopes/resources beyond the one you checked (ACAT reports can rely on cloud resources that may span multiple subscriptions).
The ACAT docs explicitly mention that compliance report resources can span multiple subscriptions, and you need the appropriate roles for the corresponding subscriptions.
What to try next (practical checks):
- Confirm access at the subscription scope(s) actually involved
- In the Azure portal, open the Subscriptions blade and go to the relevant subscription(s).
- For each subscription that could be involved in report creation, check IAM > View my access.
- Ensure you have App Compliance Automation Administrator and Resource Policy Contributor on every corresponding subscription involved (not just the one where you checked with
az role assignment list).
- Re-check the operation from the same account context
- Since you already tried waiting for propagation and re-signing, the remaining likely causes are scope coverage (additional subscriptions) or effective RBAC evaluation differences.
- If you’re using preview tooling / evaluator
- With the info provided, we can’t confirm a known preview-evaluator issue from the documents you supplied, so it’s safest to treat this as a permissions/scope coverage evaluation until proven otherwise
Thanks,
Suchitra.