App Service - What is the exact permission to retrieve custom error pages via APIs?

Jean Luo 0 Reputation points
2026-09-28T15:57:11.2066667+00:00

Hi,

I tried asking Azure support team with this question; meanwhile, I thought I may be able to seek some help here as well - what is the exact permission to retrieve custom error pages for web apps?

Setup:

  • This is the Azure public documentation site where all permissions are listed, to be able to retrieve/update/modify/delete an App Service (web app).
  • The Azure Service Principal that I'm using may not have all the permissions enabled for security reasons. Also I cannot use wildcard permissions for my Azure Service Principal.
  • I have a web app loaded with custom error page. Setting up custom error page is done via Azure Portal.

Scenario:

  • I attempted to run the following Azure CLI to retrieve custom error pages for an app:
az rest \
--method GET \
--url "https://management.azure.com/subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Web/sites/<app>/errorpages/403?api-version=2022-03-01"

Error observed:

{"code":"AuthorizationFailed","message":"The client 'abc' with object id 'def' does not have authorization to perform action 'Microsoft.Web/sites/errorpages/read' over scope '/subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Web/sites/<app>/errorpages/403' or the scope is invalid. If access was recently granted, please refresh your credentials."}}

The 'Microsoft.Web/sites/errorpages/read' permission mentioned in the error message is neither documented on the Azure public documentation site, nor allowed to be added to an Azure Service Principal.

My question is, what is the exact permissions that can allow me to retrieve custom error pages via APIs/CLIs?

Thank you.

Azure Role-based access control
Azure Role-based access control

An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Salamat Shah 750 Reputation points MVP
    2026-09-28T16:54:01.1333333+00:00

    Use Microsoft.Web/*/read in a custom role scoped only to the required App Service. If wildcard permissions are prohibited, the operation currently cannot be granted individually.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.