privateDnsZoneGroups/default has invalid private dns zone ids

Viewed 590

I'm getting the below error while creating the Azure Automation account.

Can you please assist with this? error

{ "status": "Failed", "error": { "code": "DeploymentFailed", "message": "At least one resource deployment operation failed. Please list deployment operations for details. Please see https://aka.ms/DeployOperations for usage details.", "details": [ { "code": "BadRequest", "message": "{\r\n "error": {\r\n "code": "InvalidPrivateDnsZoneIds",\r\n "message": "Private Dns Zone group /subscriptions/012a3201-bf61-4cd6-b0cb-05213d7410b4/resourceGroups/AzureAutomation/providers/Microsoft.Network/privateEndpoints/AVD-Auto/privateDnsZoneGroups/default has invalid private dns zone ids .",\r\n "details": []\r\n }\r\n}" } ] } }

1 Answers

This error indicates that a reference to a private DNS zone is incorrect. Consider the bicep example below:

resource privateDnsZone 'Microsoft.Network/privateEndpoints/privateDnsZoneGroups@2020-11-01' = {
  parent: appPrivateEndpoint_resource
  name: 'default'
  properties: {
    privateDnsZoneConfigs: [
      {
        name: 'privatelink_azurewebsites_net'
        properties: {
          privateDnsZoneId: resourceId(dnsZoneSubscriptionId, dnsZoneResourceGroup, 'Microsoft.Network/privateDnsZones', dnsZoneName)
        }
      }
    ]
  }
}

dnsZoneName must exist in the resource group dnsZoneResourceGroup in the subscription whose id is dnsZoneSubscriptionId

If any of these are wrong, you end up trying to link to a non-existent private DNS zone, and that's when the error occurs.

There might be a hardcoded resource Id reference for privateDnsZoneId. If this is the case, try to work out which subscription/resource group it is referring to and check that the private DNS zone actually exists there. If it doesn't, you will need to change the reference to where the zone actually is, or create the private DNS zone if it isn't already there.

Related