An Azure service that provides secure managed services and access control for partners and customers.
Hello WarwickW-5009
Thank you for posting this, the error you're seeing is a timeout during the delegation de-provisioning process. When you delete a service provider offer, Azure needs to remove the underlying registration assignment first. If that job doesn't finish within 30 minutes, the deletion fails with the message you shared. This is typically a transient backend issue, not a permissions problem on your end.
Since you've confirmed you have Owner on the subscription (which satisfies the required Microsoft.Authorization/roleAssignments/write, delete, and read permissions), here's what I'd recommend:
Option 1 — Retry the deletion from the portal after some time
Wait 30–60 minutes and retry. Transient delays on the Azure Managed Services backend can resolve on their own. Navigate to Service providers → Service provider offers, locate the offer, and click the trash can icon again.
Option 2 — Remove the delegation using PowerShell or Azure CLI
If the portal keeps timing out, try removing the registration assignment directly via command line. This bypasses the portal's timeout handling.
PowerShell:
Connect-AzAccount
Select-AzSubscription -SubscriptionName "<subscriptionName>"
# List the registration assignments
Get-AzManagedServicesAssignment -Scope "/subscriptions/<delegatedSubscriptionId>"
# Delete the specific registration assignment
Remove-AzManagedServicesAssignment -Name "<AssignmentName>" -Scope "/subscriptions/<delegatedSubscriptionId>"
Azure CLI:
az login
az account set -s <subscriptionId>
# List registration assignments
az managedservices assignment list
# Delete the specific assignment
az managedservices assignment delete --assignment <id or full resourceId>
Once the delegation is successfully removed, the offer should then be deletable from the Service provider offers page.
Important note: If your subscription has multiple delegations from the same service provider, removing one delegation could affect access granted by others — specifically when the same principalId + roleDefinitionId combination exists in more than one delegation. If that happens, you can re-onboard the offers that should remain.
If neither option works and the timeout persists, I'd recommend raising a support ticket through the Azure portal under Azure Lighthouse so the backend team can investigate the stuck de-provisioning job.
Official Microsoft documentation:
- Remove access to a delegation – Azure Lighthouse
- View and manage service providers – Azure Lighthouse
- Tenants, users, and roles in Azure Lighthouse
Hope this helps — please let us know how it goes!
Thanks,
Suchitra.