You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
description: Troubleshoot common issues when your Azure File Sync deployment is configured to use managed identities.
4
4
ms.service: azure-file-storage
5
5
ms.topic: troubleshooting
6
-
ms.date: 04/02/2025
6
+
ms.date: 06/05/2025
7
7
author: khdownie
8
8
ms.author: kendownie
9
9
---
@@ -65,6 +65,28 @@ When you try to delete a Storage Sync Service, you might get the following error
65
65
66
66
This issue occurs when your file share has unused Azure File Sync snapshots. To reduce your cost, the unused snapshots are deleted before removing the Storage Sync Service. The snapshot count varies with the dataset size. If you can't delete the Storage Sync Service after a few hours, try again the next day.
67
67
68
+
## Error "Failed to perform resource identity operation" when creating Storage Sync Service
69
+
70
+
When creating a Storage Sync Service, you might get the following error: "Failed to perform resource identity operation." This error occurs when you delete a Storage Sync Service and then attempt to recreate it using the same name within the same tenant.
71
+
72
+
To resolve this issue, you can create a new name for the Storage Sync Service, investigate the conflicting app in Microsoft Entra ID (and delete it manually if needed), or wait for the system to auto-clean up the app.
73
+
74
+
-**Use a different Storage Sync Service name**
75
+
Create the Storage Sync Service with a different name than the one previously used.
76
+
77
+
-**How to investigate the conflicting service principal in Microsoft Entra ID**
78
+
A conflicting service principal app might still exist in Microsoft Entra ID (formerly Azure AD). This app was likely created during the initial provisioning of the Storage Sync Service.
79
+
80
+
-**Choose manual deletion (optional)**
81
+
If you need immediate resolution, you can manually delete the conflicting app:
82
+
1. Go to the Microsoft Entra admin center.
83
+
1. Navigate to **Enterprise applications**.
84
+
1. Search for the app name that matches the Storage Sync Service.
85
+
1. Select the app and then select **Delete**.
86
+
87
+
-**Wait for automatic cleanup**
88
+
If the app was created by the Storage Sync Service provisioning process, the system will automatically delete it within 24 hours. If the service isn't urgently needed, you may choose to wait for this automatic cleanup to complete.
89
+
68
90
## Permissions required to access a storage account and Azure file share
69
91
70
92
When Azure File Sync is configured to use a managed identity, your cloud and server endpoints need the following permissions to access a storage account and Azure file share:
@@ -78,10 +100,6 @@ Server endpoint:
78
100
79
101
When you run the `Set-AzStorageSyncServiceIdentity` cmdlet or create new cloud and server endpoints, these permissions are granted. If these permissions are removed, operations fail with the errors listed in the following section.
80
102
81
-
## Unable to recreate Storage Sync Service due to dangling enterprise app
82
-
83
-
When you attempt to recreate a Storage Sync Service, you might encounter a failure due to a dangling enterprise app left by the previous Storage Sync Service. If this occurs, you can wait for a few hours for ARM to automatically delete the apps. Alternatively, you can manually delete the app in Microsoft Entra ID by navigating to **Enterprise applications** and deleting the associated app.
84
-
85
103
## Common issues
86
104
87
105
This section covers common issues that occur when permissions or configuration settings are incorrect.
0 commit comments