204005 - Could Not Determine Which Azure Subscription to Use
Uploading..Agent error code #204005 indicates that the knoc has no subscription ID set, and the agent could not work out which one to use on its own.
The subscription ID is optional. When it is blank, the agent asks Azure which subscriptions the integration's service principal can see. One enabled subscription is an unambiguous answer and the agent uses it. Anything else stops the agent rather than making it guess: picking one of several would write allow-rules into the wrong subscription, and picking a disabled one fails later with a permission error that hides the real cause.
The message says which case applied:
Neither case clears on its own, so the agent holds the verdict for a minute rather than asking Azure again on every operation. Setting the subscription ID takes effect at once, because the agent then stops making the discovery call. A fix made on the Azure side, such as removing a role assignment or disabling a spare subscription, is picked up within the minute.
Steps to Resolve
Set the Subscription ID
This resolves both cases. Open the knoc, enter the subscription ID that holds the network security group, and save. The agent then addresses that subscription directly and stops trying to discover one.
To find it in the Azure portal, open Subscriptions and copy the Subscription ID column for the subscription the NSG lives in. It is a GUID, in the form 12345678-1234-1234-1234-123456789abc.
Check the Role Assignment
If the message says the credentials can see no enabled subscription, the service principal is missing a role on one. In the Azure portal, open the subscription, then Access control (IAM), and confirm the app registration has a role that covers network security group rules (for example Network Contributor) scoped to the subscription or to the resource group holding the NSG.
A subscription that is disabled or past its end date answers the discovery call but refuses the write, so the agent does not treat it as a candidate. Confirm the subscription's state is Active.
Find Which Subscriptions the Credentials Can See
The error carries the count and not the names, because it also reaches the end user's portal tile. To see which ones they are, open each subscription in the Azure portal under Access control (IAM) > Role assignments and look for the app registration.