Q: The same pipeline and artifact deploy successfully to DEV but PROD returns "AuthorizationFailed". How would you troubleshoot it?
Root-cause triage when an identical deployment artifact and pipeline succeeds in the DEV subscription but throws AuthorizationFailed (The client does not have authorization to perform action) in PROD.
🛠️ Production Runbook & Step-by-Step Resolution
Identify the Exact Action and Resource URI
Examine the error message details. Azure errors specify the exact missing action (e.g., Microsoft.Web/serverfarms/write) and target scope (resource group or subscription URI).
The client 'sp-azdo-prod' with object id '...' does not have authorization to perform
action 'Microsoft.Web/serverfarms/write' over scope '/subscriptions/.../resourceGroups/rg-prod-app'
Compare Service Principal RBAC Roles Across Subscriptions
Check what role the Service Connection's Service Principal holds in DEV versus PROD. Often DEV granted Contributor at the Subscription root, whereas PROD was scoped to Reader or limited to a specific Resource Group.
az role assignment list --assignee <prod-sp-id> --all --output table
Audit Azure Policy Deny Actions in PROD
Production subscriptions frequently enforce Azure Policy guardrails (e.g., denying non-standard SKUs, requiring specific tags, or disallowing public IPs) that return AuthorizationFailed with a policy violation details block.
- Extract the exact missing action and scope URI from the pipeline error log.
- Compare Service Principal role assignments between DEV and PROD subscriptions.
- Check if PROD Service Principal has Contributor rights on the target Resource Group.
- Inspect Azure Policy compliance logs for automated 'Deny' actions triggered by missing tags or SKUs.