Issue with servicePrincipals and appRoleAssignedTo in some Entra Tenants
@eketo-msft ci sta già lavorando.
Dal 12/1/2026.
Valutazione
Questa issue non è ancora stata valutata.
Descrizione
Bicep version
0.39.26
Resource and API version
Microsoft.Graph/applications@beta→ works in Entra tenant A & BMicrosoft.Graph/servicePrincipals@beta→ works in Entra tenant A fails in Entra tenant BMicrosoft.Graph/appRoleAssignedTo@beta→ works in Entra tenant A fails in Entra tenant B
Auth flow
Automated deployment
Bicep executed on Azure DevOps Agent using a service principal (workload identity federation)..
The same configured service principal (same permissions and roles) is used in both Entra tenants.
Deployment details
Insufficient privileges to complete the operation.
Graph client request id: cbf743cc-bffd-443c-a2dd-b1da094d75ac.
Graph request timestamp: 2025-12-30T14:06:55Z.
Describe the bug
Using the same Bicep template, same service principal, and same permissions:
- Deployment works in Tenant A
- Deployment fails in Tenant B
Failures occur only for:
Microsoft.Graph/servicePrincipalsMicrosoft.Graph/appRoleAssignedTo
The same operations executed via direct Microsoft Graph REST API
(using PowerShell / az rest) succeed.
Expected behavior:
ARM/Bicep Graph deployments should behave consistently across tenants and align with direct Microsoft Graph API behavior.
Actual behavior:
Tenant-dependent failures occur only when using the ARM-based Microsoft Graph provider.
To Reproduce
No idea.
Additional context
- Admin consent to SP used by Azure DevOps is granted in both Entra tenants
- Same permissions, roles, API version, and payload
- Same service principal identity
- Tenant settings reviewed and appear identical
- The issue occurs only when operations are executed via Azure Resource Manager
- Direct Microsoft Graph API calls do not exhibit this tenant-dependent behavior
This suggests additional tenant-level enforcement applied only to
ARM-mediated Microsoft Graph operations.
- Lingua principale
- TypeScript
- Stelle
- 80
- Fork
- 15
- Merge medio
- 1h 21m
- PR unite (30g)
- 3
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di microsoftgraph/msgraph-bicep-types
-
bug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 55/100
microsoftgraph/msgraph-bicep-types#311 · 3 commenti ·
-
enhancement new type
Difficoltà 5/5 Più di una settimana Idoneità per principianti 45/100
-
enhancement
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
microsoftgraph/msgraph-bicep-types#304 · 3 commenti · 1 reazione ·
-
enhancement new type
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
microsoftgraph/msgraph-bicep-types#296 · 2 reazioni ·
-
enhancement
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
microsoftgraph/msgraph-bicep-types#266 · 1 reazione ·
Tutte le issue di microsoftgraph/msgraph-bicep-types
Issue simili
-
resources
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
railmapgen/rmg-palette#2445 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
danielmiessler/LifeOS#2242 ·
I maintainer di solito rispondono entro 5 giorni
-
good first issue hacktoberfest help wanted translation
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
callstackincubator/appduct#129 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 1-3 ore Idoneità per principianti 88/100