An Azure network security service that is used to protect Azure Virtual Network resources.
The error indicates that Azure is rejecting another rule-collection-group update while the parent Firewall Policy still has an unfinished update. Don't continue retrying Terraform until the policy leaves the Updating state.
First, confirm the current provisioning state with Azure CLI:
az network firewall policy show \
--resource-group <resource-group> \
--name <firewall-policy-name> \
--query "{provisioningState:provisioningState,id:id}" \
--output json
You can also wait for the existing update to complete:
az network firewall policy wait \
--resource-group <resource-group> \
--name <firewall-policy-name> \
--updated \
--interval 30 \
--timeout 3600
These are Azure CLI commands and can be run from Azure Cloud Shell or a local shell with Azure CLI installed. Both show and wait for the Azure Firewall Policy, including waiting until provisioningState becomes Succeeded.
Next, open the policy or its resource group in the Azure portal and review the Activity log. Locate the operation ID or correlation ID from the original update and inspect its JSON details. Azure Activity Log records control-plane writes, their status, timestamps, correlation IDs, and response details.
Also check Resource Health and Service Health for Azure Firewall or networking incidents in East US 2.
Once the policy returns to Succeeded, run a fresh terraform plan before applying again. Ensure that another pipeline, portal operation, or deployment isn’t updating the same policy concurrently.
If the state remains Updating after the original operation should reasonably have completed, open an Azure support request and provide the subscription ID, policy resource ID, region, timestamp, operation ID, and correlation ID. Microsoft’s Azure Firewall support guidance directs unresolved service-side problems to Azure Support.
References:
Find Azure Resource Manager error codes
Azure Service Health documentation
Azure Firewall support and troubleshooting
Create an Azure support request
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.