Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
This usually means the resource group is locked, and the lock may be inherited, system-owned, or tied to a managed application.
- Check whether the lock is on the resource group itself or inherited from a parent scope.
- A lock applied at a parent scope is inherited by resources in that scope.
- If a Delete lock exists on any resource in the group, deleting the resource group is blocked.
- Verify whether this is a managed application scenario.
- Some services create a locked infrastructure resource group that is owned by a system application.
- In that case, the lock cannot be deleted directly.
- The correct action is to delete the parent service, which then deletes the managed resource group.
- If the lock is a normal management lock and permissions are sufficient, remove it from the correct scope.
- To create or delete management locks, access to
Microsoft.Authorization/*orMicrosoft.Authorization/locks/*is required. - Owner and User Access Administrator have the required access.
- To create or delete management locks, access to
- In Azure portal, inspect the lock directly:
- Open the resource group or affected resource.
- Go to Settings > Locks.
- Look for a Delete lock (
CanNotDelete). - If it is removable, use the ellipsis menu and select Delete.
- In Azure CLI, list locks and remove the exact lock by ID:
If the lock exists and is removable, delete it by ID:az group lock list --output tablelockid=$(az lock show --resource-group lockedRG --name deleteLock --output tsv --query id) az lock delete --ids $lockid - If deletion still fails with resource-not-found for the storage account, check whether the lock references a resource that no longer exists.
- That can happen when deletion is blocked by service-managed or inherited locks.
- If the resource group is part of a managed application, delete the parent service instead of trying to delete the lock directly.
- Also confirm the resource group delete prerequisites.
- Deleting a resource group requires the delete action for
Microsoft.Resources/subscriptions/resourceGroups. - Deletion can also fail because of locks or because resources are connected to resources in other resource groups.
- Deleting a resource group requires the delete action for
Important: deleting a resource group removes the group and all associated resources.
- Lock your Azure resources to protect your infrastructure
- Lock your Azure resources to protect your infrastructure
- Lock your Azure resources to protect your infrastructure
- Azure Resource Manager resource group and resource deletion
- Log Forwarding Persists After Service Is Disabled
- Automatic deletions from deployment history
- How to manage Azure resource groups with the Azure CLI
- az lock delete