⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Senior DevOps / SRE Security Azure RBAC & Service Connections Enterprise Azure

Q: The same pipeline and artifact deploy successfully to DEV but PROD returns "AuthorizationFailed". How would you troubleshoot it?

Root-cause triage when an identical deployment artifact and pipeline succeeds in the DEV subscription but throws AuthorizationFailed (The client does not have authorization to perform action) in PROD.

#Azure #RBAC #Security #Azure DevOps #IAM
🎙️ Candidate Opening & Architectural Context
"In enterprise Azure environments, DEV and PROD live in separate Azure Subscriptions with independent Azure DevOps Service Connections and differing Azure Policy guardrails. 'AuthorizationFailed' indicates missing RBAC role assignments or Azure Policy denials."
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1

Identify the Exact Action and Resource URI

Examine the error message details. Azure errors specify the exact missing action (e.g., Microsoft.Web/serverfarms/write) and target scope (resource group or subscription URI).

The client 'sp-azdo-prod' with object id '...' does not have authorization to perform 
action 'Microsoft.Web/serverfarms/write' over scope '/subscriptions/.../resourceGroups/rg-prod-app'
2

Compare Service Principal RBAC Roles Across Subscriptions

Check what role the Service Connection's Service Principal holds in DEV versus PROD. Often DEV granted Contributor at the Subscription root, whereas PROD was scoped to Reader or limited to a specific Resource Group.

az role assignment list --assignee <prod-sp-id> --all --output table
3

Audit Azure Policy Deny Actions in PROD

Production subscriptions frequently enforce Azure Policy guardrails (e.g., denying non-standard SKUs, requiring specific tags, or disallowing public IPs) that return AuthorizationFailed with a policy violation details block.

💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Compare Azure RBAC assignments between DEV and PROD Service Principals and inspect Azure Policy compliance logs for automated deny actions."
⚡ 60-Second Elevator Pitch Talking Points
  • Extract the exact missing action and scope URI from the pipeline error log.
  • Compare Service Principal role assignments between DEV and PROD subscriptions.
  • Check if PROD Service Principal has Contributor rights on the target Resource Group.
  • Inspect Azure Policy compliance logs for automated 'Deny' actions triggered by missing tags or SKUs.
Advertisement
Want more Security scenarios?
Explore our complete collection of scenario-based Security interview runbooks.
Browse All Security Questions →

📚 Related Production Scenarios in Security