The root management group requires special elevated permissions for interaction. My guess is you trying to create a management group under root. Do you get the same problem if you target none root management group and permissions assigned there? I will try and run a test tomorrow and see if my theory accurate.
clean-truck-93285
05/06/2022, 2:39 PM
Confirmed I had to have user access enabled to create management groups under root. I got the same error you posted in original message.
s
straight-sunset-92336
05/06/2022, 5:56 PM
What RBAC role does the serviceprincipal need.
I'm trying to create the management group under a sub-management group.,
c
clean-truck-93285
05/06/2022, 6:02 PM
This where things gets weird. I also had to be on user access for sub management groups. I also couldn't enable hierarchical permissions with user access enabled. Provisioning manually through the portal works fine without user access. I missing something or something broke. I would pop a Microsoft ticket and see if they can provide any insight.
No matter how you like to participate in developer communities, Pulumi wants to meet you there. If you want to meet other Pulumi users to share use-cases and best practices, contribute code or documentation, see us at an event, or just tell a story about something cool you did with Pulumi, you are part of our community.