I created a role but cannot delete it

Assaf Katz 21 Reputation points
2021-02-03T15:56:11.263+00:00

Hi,
I worked with 5-exercise-manage-custom-roles and create a role, and assignment for it. But now I cannot find any assignment (by portal or azure CLI) but it isn't possible to delete the role since it has assignments...
Thanks,
Assaf

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
710 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 36,151 Reputation points Microsoft Employee
    2021-02-03T22:47:08.047+00:00

    Hi Assaf,

    Sorry to hear that you are having this issue!

    Please follow the steps to remove the role assignment and open Access control (IAM) if you're dealing with an inherited role assignment.

    1. Open Access control (IAM) at a scope, such as management group, subscription, resource group, or resource, where you want to remove access.
    2. Click the Role assignments tab to view all the role assignments at this scope.
    3. In the list of role assignments, add a checkmark next to the security principal with the role assignment you want to remove.
    4. Click Remove.

    If you see a message that inherited role assignments cannot be removed, you are trying to remove a role assignment at a child scope. You should open Access control (IAM) at the scope where the role was assigned and try again. A quick way to open Access control (IAM) at the correct scope is to look at the Scope column and click the link next to (Inherited).