You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Bicep+Azure DevOps部署MCA订阅至管理组遇权限问题求助

解决MCA订阅创建时的InsufficientPermissionsOnInvoiceSection错误

问题背景

尝试通过Bicep结合Azure DevOps Pipeline,将新的Azure订阅部署到指定管理组,计费模式为Microsoft Customer Agreement(MCA)。已遵循官方指南编写代码,但部署时抛出InsufficientPermissionsOnInvoiceSection错误,尽管操作账号拥有Owner权限。

Bicep代码

targetScope = 'managementGroup'

@description('Provide a name for the alias. This name will also be the display name of the subscription.')
param subscriptionAliasName string

@description('Provide the full resource ID of billing scope to use for subscription creation.')
param billingScope string

resource subscriptionAlias 'Microsoft.Subscription/aliases@2021-10-01' = {
  scope: tenant()
  name: subscriptionAliasName
  properties: {
    workload: 'Production'
    displayName: subscriptionAliasName
    billingScope: billingScope
  }
}

Azure DevOps Pipeline脚本

trigger:
- none

pool:
  vmImage: 'ubuntu-latest'

steps:
- task: AzureCLI@2
  inputs:
    azureSubscription: 'Jo' 
    scriptType: 'bash'
    scriptLocation: 'inlineScript'
    inlineScript: |
      echo "Installing the Bicep CLI"
      az bicep version
      echo "Deploying Bicep template to Management Group Jo"
      az deployment mg create --location australiaeast --management-group-id Jo --template-file ./idsub.bicep

错误信息

Deploying Bicep template to Management Group Jo
ERROR: {"status":"Failed","error":{"code":"DeploymentFailed","target":"/providers/Microsoft.Management/managementGroups/Jo/providers/Microsoft.Resources/deployments/idsub","message":"At least one resource deployment operation failed. Please list deployment operations for details. Please see https://aka.ms/arm-deployment-operations for usage details.","details":[{"code":"InsufficientPermissionsOnInvoiceSection","message":"Cannot create subscription since either invoice section is not found or you do not have sufficient permissions under the provided invoice section. Try again with a different invoice section or contact invoice section owner for permissions"}]}}
##[error]Script failed with exit code: 1
/usr/bin/az account clear
Finishing: AzureCLI

解决方案

  • 明确发票段的权限要求:MCA订阅创建需要的不是订阅或管理组的Owner权限,而是**目标发票段(Invoice Section)**上的Microsoft.Subscription/aliases/write权限,直接分配「发票段参与者(Invoice Section Contributor)」角色最便捷。管理组或订阅级的Owner权限无法覆盖发票段的操作权限。

  • 验证服务连接的权限:Pipeline使用的服务连接(azureSubscription: 'Jo')对应的服务主体,必须在目标发票段的「访问控制(IAM)」中拥有权限:

    1. 登录Azure门户,找到对应计费账户下的目标发票段
    2. 进入该发票段的「访问控制(IAM)」页面
    3. 搜索服务连接对应的服务主体,确认已分配「发票段参与者」或包含Microsoft.Subscription/aliases/write权限的自定义角色
  • 确认billingScope格式正确:确保billingScope参数的资源ID格式完全符合要求,MCA的billingScope格式为:

    /providers/Microsoft.Billing/billingAccounts/{billingAccountId}/billingProfiles/{billingProfileId}/invoiceSections/{invoiceSectionId}
    

    可通过Azure CLI命令az billing invoice-section list --billing-account-id {billingAccountId} --billing-profile-id {billingProfileId}获取准确的发票段ID,避免拼写或格式错误。

  • 检查双重权限覆盖:执行部署的身份(服务主体)需同时拥有:

    • 目标管理组的Owner/Contributor权限(用于管理组级部署)
    • 目标发票段的对应权限(用于创建订阅)
      两者缺一不可,且计费资源(发票段)不继承管理组的权限,必须直接分配。

内容的提问来源于stack exchange,提问作者Joshua Martin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 14:22:45