Permission error when adding disks or deploying new CVO using BlueXP
Applies to
- BlueXP
- Cloud Volumes ONTAP (CVO)
- Microsoft Azure
Issue
- When deploying new CVO or adding disks to extend existing CVO aggregate, the operation fails with error below in BlueXP timeline:
Error:You don't have permission to perform this action. For more information please refer to the OnCommand Cloud Manager policies documentation at https://mysupport.netapp.com/site/in...nager-policies
- Error below is seen from BlueXP server.log:
Simplicator request to http://localhost:8080/AzureProtocol/...urceGroupName=<resource_group_name> failed: The client '<client_ID>' with object id '<object_ID>' has permission to perform action 'Microsoft.Compute/virtualMachines/write' on scope '/subscriptions/<Azure_Subscription_ID_1>/resourceGroups/<resource_group_name>/providers/Microsoft.Compute/virtualMachines/<VM_name>'; however, it does not have permission to perform action(s) 'Microsoft.ManagedIdentity/userAssignedIdentities/assign/action' on the linked scope(s) '/subscriptions/<Azure_Subscription_ID_2>/resourceGroups/<resource_group_name>/providers/Microsoft.ManagedIdentity/userAssignedIdentities/' (respectively) or the linked scope(s) are invalid. Code: LinkedAuthorizationFailed