> Source: [sk117552](https://support.checkpoint.com/results/sk/sk117552)

# sk117552 - "HTTP/1.1 403 Forbidden" and "The client 'XXX' with object id 'XXX' does not have authorization to perform action 'XXX' over scope" errors when running the $FWDIR/scripts/azure_ha_test.py script on vSEC Gateway for Azure

| Property | Value |
|----------|-------|
| Solution ID | sk117552 |
| Date Created | 2017-05-31 |
| Last Modified | 2017-09-26 |
| Technical Level | Advanced |
| Products | Cloud Firewall |
| Versions | R82.10, R81.20, R82 |
| OS | Gaia |
| Platform | Azure |

## Symptoms

- * Running the *$FWDIR/scripts/azure_ha_test.py* script on vSEC Gateway for Azure shows the following error:

  `Testing authorization on the network resource group...`  
  `
  Error:`  
  `
  HTTP/1.1 403 Forbidden`  
  `
  {"error":{"code":"AuthorizationFailed","message":"The client 'XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX' with object id 'XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX' does not have authorization to perform action 'Microsoft.Resources/subscriptions/resourceGroups/resources/read' over scope '/subscriptions/XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX/resourceGroups/testRG'."}}
  `
* Running the *$FWDIR/scripts/azure_ha_test.py* script returns the wrong resource group name.

## Cause

The *azure_ha_test.py* script verifies whether the vSEC Gateways for Azure are in the same resource group as the other entities (load balancers, etc.).

The returned resource group name is not the one containing the vSEC Gateways for Azure, but the other objects.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
