AKS resource deletion blocked due to cross-subscription VM Scale Set dependency

Ben Divsalar 0 Reputation points
2025-12-15T12:13:22.34+00:00

We are unable to delete an AKS-managed Network Security Group because Azure reports it is still in use by multiple Virtual Machine Scale Sets. However, the VM Scale Sets referenced in the error message exist in a different subscription that is not visible or accessible to our current tenant/account.
Error received:

Cannot delete network security group ... since it is in use by virtual machine scale set ...
(Code: NetworkSecurityGroupInUseByVirtualMachineScaleSet)

The error references VM Scale Sets under subscription ID:

<Personal data>

When attempting to switch to this subscription using Azure CLI, we receive:

<personal data >

This indicates that the AKS managed infrastructure (VMSS) is owned by a subscription or tenant that we do not currently have access to, while the Network Security Group exists in our visible subscription.

Azure Kubernetes Service
Azure Kubernetes Service
An Azure service that provides serverless Kubernetes, an integrated continuous integration and continuous delivery experience, and enterprise-grade security and governance.
{count} votes

2 answers

Sort by: Most helpful
  1. Ben Divsalar 0 Reputation points
    2025-12-15T13:35:44.4166667+00:00

    Hi Shraddha

    I ran the cli command and noticed there are three networkInterfaces in different subscription under my NSG listed below. When I go to netword interfaces in portal, it says I dont have access where I am the admin. I dont know who's this subscription: fdd74609-b664-49fe-8877-97471142250f

    "networkInterfaces": [

    {
    
      "id": "/subscriptions/fdd74609-b664-49fe-8877-97471142250f/resourceGroups/MC_BLUECLIFF-0EA529F0-RG_BLUECLIFF-0EA529F0_UKSOUTH/PROVIDERS/MICROSOFT.COMPUTE/VIRTUALMACHINESCALESETS/AKS-SYSTEMPOOL-41551473-VMSS/VIRTUALMACHINES/0/NETWORKINTERFACES/AKS-SYSTEMPOOL-41551473-VMSS",
    
      "resourceGroup": "MC_BLUECLIFF-0EA529F0-RG_BLUECLIFF-0EA529F0_UKSOUTH"
    
    },
    
    {
    
      "id": "/subscriptions/fdd74609-b664-49fe-8877-97471142250f/resourceGroups/MC_BLUECLIFF-0EA529F0-RG_BLUECLIFF-0EA529F0_UKSOUTH/PROVIDERS/MICROSOFT.COMPUTE/VIRTUALMACHINESCALESETS/AKS-SYSTEMPOOL-41551473-VMSS/VIRTUALMACHINES/1/NETWORKINTERFACES/AKS-SYSTEMPOOL-41551473-VMSS",
    
      "resourceGroup": "MC_BLUECLIFF-0EA529F0-RG_BLUECLIFF-0EA529F0_UKSOUTH"
    
    },
    
    {
    
      "id": "/subscriptions/fdd74609-b664-49fe-8877-97471142250f/resourceGroups/MC_BLUECLIFF-0EA529F0-RG_BLUECLIFF-0EA529F0_UKSOUTH/PROVIDERS/MICROSOFT.COMPUTE/VIRTUALMACHINESCALESETS/AKS-SYSTEMPOOL-41551473-VMSS/VIRTUALMACHINES/25/NETWORKINTERFACES/AKS-SYSTEMPOOL-41551473-VMSS",
    
      "resourceGroup": "MC_BLUECLIFF-0EA529F0-RG_BLUECLIFF-0EA529F0_UKSOUTH"
    
    }
    

    ],

    0 comments No comments

  2. Ben Divsalar 0 Reputation points
    2025-12-15T17:40:43.48+00:00

    It seems Azure is creating this RG for internal use by CAE. Removed all Container Apps and Container App Environment, then this MC_..._ resource group has been removed. I create the Container again (using Bicep) a new MC_ names are creating with two public IP, NSG and Load balancer.

    Surprisingly when I ran "az network nsg show" command, it is now showing networkInterfaces for the creating nsg in different subscription and only two NI this time

    "networkInterfaces": [

    {
    
      "id": "/subscriptions/ec506cc4-04f0-4919-9c24-d6e44c975089/resourceGroups/MC_SALMONBAY-F31C6596-RG_SALMONBAY-F31C6596_UKSOUTH/PROVIDERS/MICROSOFT.COMPUTE/VIRTUALMACHINESCALESETS/AKS-SYSTEMPOOL-33427451-VMSS/VIRTUALMACHINES/0/NETWORKINTERFACES/AKS-SYSTEMPOOL-33427451-VMSS",
    
      "resourceGroup": "MC_SALMONBAY-F31C6596-RG_SALMONBAY-F31C6596_UKSOUTH"
    
    },
    
    {
    
      "id": "/subscriptions/ec506cc4-04f0-4919-9c24-d6e44c975089/resourceGroups/MC_SALMONBAY-F31C6596-RG_SALMONBAY-F31C6596_UKSOUTH/PROVIDERS/MICROSOFT.COMPUTE/VIRTUALMACHINESCALESETS/AKS-SYSTEMPOOL-33427451-VMSS/VIRTUALMACHINES/1/NETWORKINTERFACES/AKS-SYSTEMPOOL-33427451-VMSS",
    
      "resourceGroup": "MC_SALMONBAY-F31C6596-RG_SALMONBAY-F31C6596_UKSOUTH"
    
    }
    

    ],


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.