资源组级ARM模板能否部署其他资源组及资源?dependsOn如何配置?
Absolutely, this scenario is fully supported in Azure Resource Manager (ARM) templates—you just need to fix how you reference the new resource group in your dependsOn block. The failure happens because the deployment to SecondResourceGroup tries to run before the group itself is created, and ARM doesn’t automatically infer this dependency for cross-resource-group operations.
How to configure the correct dependsOn reference
Since Microsoft.Resources/resourceGroups are subscription-level resources (not part of your firstResourceGroup), you can’t just reference their name directly in dependsOn. Instead, you need to use the resourceId() function to generate the full, valid resource ID for the new group.
Correct dependsOn syntax
For a same-subscription deployment, the resourceId() call only needs the resource type and the name of your new resource group:
"dependsOn": [ "[resourceId('Microsoft.Resources/resourceGroups', parameters('secondResourceGroupName'))]" ]
If you’re deploying across subscriptions (less common here), add the subscription ID as the first parameter:
"dependsOn": [ "[resourceId(subscription().subscriptionId, 'Microsoft.Resources/resourceGroups', parameters('secondResourceGroupName'))]" ]
Full working template example
Here’s a complete template that creates SecondResourceGroup first, then deploys a storage account to it—with the correct dependency configured:
{ "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { "secondResourceGroupName": { "type": "string", "defaultValue": "SecondResourceGroup" }, "location": { "type": "string", "defaultValue": "eastus" } }, "resources": [ // Step 1: Create the second resource group { "type": "Microsoft.Resources/resourceGroups", "apiVersion": "2021-04-01", "name": "[parameters('secondResourceGroupName')]", "location": "[parameters('location')]" }, // Step 2: Deploy resources to the second group, dependent on its creation { "type": "Microsoft.Resources/deployments", "apiVersion": "2021-04-01", "name": "DeployToSecondRG", "resourceGroup": "[parameters('secondResourceGroupName')]", "dependsOn": [ "[resourceId('Microsoft.Resources/resourceGroups', parameters('secondResourceGroupName'))]" ], "properties": { "mode": "Incremental", "template": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "resources": [ { "type": "Microsoft.Storage/storageAccounts", "apiVersion": "2021-06-01", "name": "[concat('stor', uniqueString(parameters('secondResourceGroupName')))]", "location": "[parameters('location')]", "sku": { "name": "Standard_LRS" }, "kind": "StorageV2" } ] } } } ] }
Key notes to avoid issues
- Permissions: Make sure the account running
New-AzResourceGroupDeploymenthas permissions to create resource groups and deploy resources to them (e.g.,Contributorrole at the subscription level, or a custom role with the required actions). - Don’t hardcode names: Use parameters/variables for resource group names to keep the template reusable.
- Bicep alternative: If you’re open to using Bicep instead of JSON templates, this dependency becomes even simpler—you can just reference the resource group symbol directly in
dependsOn, no need for manualresourceId()calls.
内容的提问来源于stack exchange,提问作者Mathias Indermühle

