Skip to content

unable to create sp from MacOS #18466

Description

@wccropper

This is autogenerated. Please review and update as needed.

Describe the bug

Command Name
az ad sp create-for-rbac

Errors:

The command failed with an unexpected error. Here is the traceback:
APIVersion 2016-09-01 is not available
Traceback (most recent call last):
  File "/usr/local/Cellar/azure-cli/2.24.2/libexec/lib/python3.8/site-packages/knack/cli.py", line 231, in invoke
    cmd_result = self.invocation.execute(args)
  File "/usr/local/Cellar/azure-cli/2.24.2/libexec/lib/python3.8/site-packages/azure/cli/core/commands/__init__.py", line 657, in execute
    raise ex
  File "/usr/local/Cellar/azure-cli/2.24.2/libexec/lib/python3.8/site-packages/azure/cli/core/commands/__init__.py", line 720, in _run_jobs_serially
    results.append(self._run_job(expanded_arg, cmd_copy))
  File "/usr/local/Cellar/azure-cli/2.24.2/libexec/lib/python3.8/site-packages/azure/cli/core/commands/__init__.py", line 712, in _run_job
    return cmd_copy.exception_handler(ex)
  File "/usr/local/Cellar/azure-cli/2.24.2/libexec/lib/python3.8/site-packages/azure/cli/command_modules/role/commands.py", line 69, in graph_err_handler
    raise ex
  File "/usr/local/Cellar/azure-cli/2.24.2/libexec/lib/python3.8/site-packages/azure/cli/core/commands/__init__.py", line 691, in _run_job
    result = cmd_copy(params)
  File "/usr/local/Cellar/azure-cli/2.24.2/libexec/lib/python3.8/site-packages/azure/cli/core/commands/__init__.py", line 328, in __call__
    return self.handler(*args, **kwargs)
  File "/usr/local/Cellar/azure-cli/2.24.2/libexec/lib/python3.8/site-packages/azure/cli/core/commands/command_operation.py", line 121, in handler
    return op(**command_args)
  File "/usr/local/Cellar/azure-cli/2.24.2/libexec/lib/python3.8/site-packages/azure/cli/command_modules/role/custom.py", line 1400, in create_service_principal_for_rbac
    role_client = _auth_client_factory(cmd.cli_ctx).role_assignments
  File "/usr/local/Cellar/azure-cli/2.24.2/libexec/lib/python3.8/site-packages/azure/mgmt/authorization/_authorization_management_client.py", line 201, in role_assignments
    raise NotImplementedError("APIVersion {} is not available".format(api_version))
NotImplementedError: APIVersion 2016-09-01 is not available

To Reproduce:

Steps to reproduce the behavior. Note that argument values have been redacted, as they may contain sensitive information.

  • Put any pre-requisite steps here...
  • az ad sp create-for-rbac --name {} --skip-assignment

Expected Behavior

Environment Summary

macOS-11.4-x86_64-i386-64bit
Python 3.8.10
Installer: HOMEBREW

azure-cli 2.24.2

Extensions:
k8sconfiguration 0.2.4
connectedk8s 1.1.5
aks-preview 0.5.19
azure-devops 0.18.0
acrtransfer 1.0.0
costmanagement 0.1.1

Additional Context

Activity

  1. ghost added
    needs-triageThis is a new issue that needs to be triaged to the appropriate team.
    on Jun 11, 2021
  2. ghost added
    questionThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
    on Jun 11, 2021
  3. added
    Graph(doesn't work with label-triggered comments; use Graph.Microsoft instead) az ad
    on Jun 12, 2021
  4. ghost removed
    needs-triageThis is a new issue that needs to be triaged to the appropriate team.
    on Jun 12, 2021
  5. removed
    questionThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
    on Jun 12, 2021
  6. added this to the S189 milestone on Jun 12, 2021
  7. yonzhan commented on Jun 12, 2021

    @yonzhan
    Collaborator

    Jiashuo Li (@jiasli) for awareness

  8. MaddyMicrosoft commented on Oct 6, 2026

    @MaddyMicrosoft
    Member

    This looks likely to have been addressed by changes in this area since the report. The failure happened after the application/service principal creation step, while az ad sp create-for-rbac was performing its older role-assignment flow. Current Azure CLI no longer creates a role assignment by default when running az ad sp create-for-rbac, so the command should no longer hit this path unless role assignment is explicitly requested.
    Please upgrade and retry. If service principal creation still fails on a current Azure CLI, please open a fresh issue with the exact command and --debug output.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Graph(doesn't work with label-triggered comments; use Graph.Microsoft instead) az adact-identity-squadfeature-request

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions