Refer to the exhibit. You are deploying an ARM template that assigns the 'Storage Blob Data Contributor' role to the managed identity of an App Service named 'myapp' at the storage account 'mystorageacct' scope. The deployment fails with an error that 'principalId' is null. What is the most likely cause?
For an Azure resource like an App Service to be assigned an Azure RBAC role, it must possess an associated Azure Active Directory identity, which is provided by a managed identity. If the App Service 'myapp' does not have a system-assigned or user-assigned managed identity enabled, it lacks the necessary `principalId` (object ID) that Azure RBAC requires to create the role assignment. Consequently, the deployment fails because the `principalId` property cannot be resolved or is null, preventing the role from being assigned to the service.
Why this answer
The error 'principalId' is null indicates that the ARM template is attempting to assign a role to a principal that does not exist. In this scenario, the principal is the managed identity of the App Service 'myapp'. If the App Service does not have a managed identity enabled, the 'principalId' property in the role assignment resource will be null, causing the deployment to fail.
Enabling a system-assigned or user-assigned managed identity on the App Service is required before the role assignment can succeed.
Exam trap
The trap here is that candidates may assume the error is due to a missing storage account or incorrect role definition, but the null 'principalId' directly points to the managed identity not being enabled on the App Service.
How to eliminate wrong answers
Option A is wrong because an incorrect role definition ID would cause a 'RoleDefinitionIdNotFound' or similar error, not a null 'principalId'. Option B is wrong because a non-existent storage account would result in a 'ResourceNotFound' error, not a null 'principalId'. Option C is wrong because a non-unique role assignment name would produce a 'RoleAssignmentExists' conflict error, not a null 'principalId'.