RBAC Scope Management Group Not Supported

usabilityActiveRising

The command 'az ad sp create-for-rbac' fails when trying to scope to a management group, causing operational disruptions.

Opportunity Score (Heuristic (unvalidated)):67 · High · heuristic
First seen: 11/17/2020
Last seen: 10/5/2026

Score Breakdown

Heuristic ranking from public discussion signals — not a validated prediction of commercial opportunity, demand, or willingness to pay.

Composite 67/100 (High, unvalidated). Top driver: Willingness to pay (30% weight, 22.5 pts).

Frequency · 25% · 11.8 pts · XPS relevance47

Heuristic only — often urgency map or random scaffolding on ingest, not measured mention frequency. Maps to XPS relevance (with market size).

Severity · 25% · 20 pts · XPS quality80

LLM/mock judgment of intensity from title/summary text — not ops or ticket data. Maps to XPS quality (with willingness to pay).

Willingness to pay · 30% · 22.5 pts · XPS quality75

LLM/mock purchase-intent guess from text — not invoices, surveys, or paid seats. Maps to XPS quality.

Trend · 10% · 6.9 pts · XPS novelty69

Heuristic/scaffold (often random or fixed on insert) — not a verified mention trajectory. Maps to XPS novelty.

Market size · 10% · 6.3 pts · XPS relevance63

Heuristic/scaffold (often random or fixed) — not TAM research. Maps to XPS relevance (with frequency).

Catalog notes (not predictive analysis)

RBAC Scope Management Group Not Supported (usability). Catalog heuristic opportunity score: 67/100 — a chosen formula over discussion-signal facets, not evidence of demand, conversion, or willingness to pay. Treat as browsing rank, not a commercial prediction.

The command 'az ad sp create-for-rbac' fails when trying to scope to a management group, causing operational disruptions.

Source Examples

azure/azure-cli Issues·Nov 17, 2020
“"az ad sp create-for-rbac" does not support scope management group **Describe the bug** `az ad sp create-for-rbac` does not support scoping to management group and fails with error *Subscription 'Microsoft.Management' not found*. **To Reproduce** `az ad sp create-for-rbac --name "<MANAGEMENT_GROUP_NAME>-Contributor" --role "Contributor" --scopes /providers/Microsoft.Management/managementGroups/<MANAGEMENT_GROUP_NAME> --sdk-auth --debug` After this Azure API Request... ```PUT /providers/Microsoft.Management/managementGroups/<MANAGEMENT_GROUP_NAME>/providers/Microsoft.Authorization/roleAssignments/<ROLE_ASSIGNMENT_ID>?api-version=2020-04-01-preview HTTP/1.1``` ... you will see the following error message: ``` azure.cli.core.util.handle_exception is called with an exception: Traceback (most recent call last): File "/opt/az/lib/python3.6/site-packages/knack/cli.py", line 215, in invoke cmd_result = self.invocation.execute(args) File "/opt/az/lib/python3.6/site-packages/azure/cli/core/commands/__init__.py", line 654, in execute raise ex File "/opt/az/lib/python3.6/site-packages/azure/cli/core/commands/__init__.py", line 718, in _run_jobs_serially results.append(self._run_job(expanded_arg, cmd_copy)) File "/opt/az/lib/python3.6/site-packages/azure/cli/core/commands/__init__.py", line 709, in _run_job cmd_copy.exception_handler(ex) File "/opt/az/lib/python3.6/site-packages/azure/cli/command_modules/role/commands.py", line 69, in graph_err_handler raise ex File "/opt/az/lib/python3.6/site-packages/azure/cli/core/commands/__init__.py", line 688, in _run_job result = cmd_copy(params) File "/opt/az/lib/python3.6/site-packages/azure/cli/core/commands/__init__.py", line 325, in __call__ return self.handler(*args, **kwargs) File "/opt/az/lib/python3.6/site-packages/azure/cli/core/__init__.py", line 784, in default_command_handler return op(**command_args) File "/opt/az/lib/python3.6/site-packages/azure/cli/command_modules/role/custom.py", line 1507, in create_service_principal_for_rbac app_id, password, cert_file) File "/opt/az/lib/python3.6/site-packages/azure/cli/core/_profile.py", line 714, in get_sp_auth_info account = self.get_subscription(subscription_id) File "/opt/az/lib/python3.6/site-packages/azure/cli/core/_profile.py", line 511, in get_subscription "Check the spelling and casing and try again.".format(subscription)) knack.util.CLIError: Subscription 'Microsoft.Management' not found. Check the spelling and casing and try again. cli.azure.cli.core.azclierror : Subscription 'Microsoft.Management' not found. Check the spelling and casing and try again. Subscription 'Microsoft.Management' not found. Check the spelling and casing and try again. ``` _**Site note:**_ <MANAGEMENT_GROUP_NAME> and <ROLE_ASSIGNMENT_ID> masked for security concerns. **Expected behavior** Successful creation and role assignment of service principal to management group incl. output of the JSON with client ID and client secret - just like for subscriptions. **Environment summary** <!--- Install Method (e.g. pip, interactive script, apt-get, Docker, MSI, edge build) / CLI version (`az --version`) / OS version / Shell Type (e.g. bash, cmd.exe, Bash on Windows) ---> Azure Cloud Shell with Azure CLI 2.14.0”
— fawohlsc↗

Competitive Landscape

  • Existing solutions are either too expensive or too limited
  • Most competitors target enterprise, leaving mid-market underserved
  • Community scripts and manual processes are the primary alternative

Recommended Next Steps

  1. ✓Validate pain intensity with 5-10 target customer interviews
  2. ✓Build minimal viable solution addressing the core workflow
  3. ✓Test pricing with early adopters from community forums

Related Pain Points

Target Customers

  • IT teams at mid-size organizations (100-2000 employees)
  • MSPs and consultants managing multiple client environments
  • Teams without dedicated specialist staff for this domain

Monetization Ideas

  1. 1SaaS subscription model ($99-$499/month depending on scale)
  2. 2Usage-based pricing aligned with value delivered
  3. 3Freemium tier to drive adoption and prove value