How to Resolve 'Access Denied' Error When Deploying Azure Functions with Managed Identity?

RABİA ULUTAŞ 0 Saygınlık puanı
2025-02-18T08:40:09.2+00:00

Hi everyone,

I’m currently working on deploying an Azure Function that uses a Managed Identity to access other Azure resources (e.g., Key Vault and Storage Account). However, during the deployment process, I keep encountering an "Access Denied" error when the function tries to access these resources.

Here are the details of my setup:

  • Azure Function Runtime: .NET 6 (Isolated Process)
  • Managed Identity: System-Assigned Identity enabled
  • Target Resources:
    • Azure Key Vault (to retrieve secrets)
      • Azure Blob Storage (to read/write files)
      • Deployment Method: Azure DevOps Pipeline

Steps I’ve Taken So Far:

  1. Enabled System-Assigned Managed Identity for the Azure Function in the Azure Portal.
  2. Assigned the necessary RBAC roles to the Managed Identity:
    • "Key Vault Secrets User" for Key Vault access.
      • "Storage Blob Data Contributor" for Blob Storage access.
      1. Verified that the Managed Identity is correctly assigned and active.
      2. Used the DefaultAzureCredential class in my code to authenticate with Azure resources.

Despite these steps, I’m still getting the following error during runtime: **Access Denied: The client with object ID '<ManagedIdentityObjectID>' does not have authorization to perform action '<Action>' on resource '<ResourceName>'.**Hi everyone,

I’m currently working on deploying an Azure Function that uses a Managed Identity to access other Azure resources (e.g., Key Vault and Storage Account). However, during the deployment process, I keep encountering an "Access Denied" error when the function tries to access these resources.

Here are the details of my setup:

  • Azure Function Runtime: .NET 6 (Isolated Process)
  • Managed Identity: System-Assigned Identity enabled
  • Target Resources:
    • Azure Key Vault (to retrieve secrets)
      • Azure Blob Storage (to read/write files)
  • Deployment Method: Azure DevOps Pipeline

Steps I’ve Taken So Far:

  1. Enabled System-Assigned Managed Identity for the Azure Function in the Azure Portal.
  2. Assigned the necessary RBAC roles to the Managed Identity:
    • "Key Vault Secrets User" for Key Vault access.
    • "Storage Blob Data Contributor" for Blob Storage access.
  3. Verified that the Managed Identity is correctly assigned and active.
  4. Used the DefaultAzureCredential class in my code to authenticate with Azure resources.

Despite these steps, I’m still getting the following error during runtime:
Access Denied: The client with object ID '<ManagedIdentityObjectID>' does not have authorization to perform action '<Action>' on resource '<ResourceName>'.

Windows Ev | Windows 10 | Karma Gerçeklik
Toplum Merkezi | Soru-Yanıtları tartışma sitesi | Soru-Yanıt'ı kullanmaya başlama
Toplum Merkezi | İzlenmiyor
0 yorum Açıklama yok

1 yanıt

Sıralama ölçütü: En Yeni
  1. RABİA ULUTAŞ 0 Saygınlık puanı
    2025-02-18T08:40:36.1066667+00:00

    Bu yanıt yardımcı oldu mu?

    0 yorum Açıklama yok

Yanıtınız

Yanıtlar, soru sahibi tarafından ‘Kabul Edildi’ ve moderatörler tarafından ‘Önerildi’ olarak işaretlenebilir, bu da kullanıcıların yanıtın yazarın sorununu çözdüğünü bilmelerine yardımcı olur.