An Azure service that provides an event-driven serverless compute platform.
Hello Agustin Cano,
Welcome to Microsoft Q&A,
This happens because of a leftover certificate resource in the source resource group, not because of your app's current bindings.
Even with no hostname or SSL bindings active today, a Microsoft.Web/certificates resource (an uploaded/imported TLS certificate, or a free App Service Managed Certificate) can still exist in the resource group from an earlier setup. Azure requires all App Service related resources in a resource group to move together, so the validation pulls that orphaned certificate into the move request.
The key detail that trips people up: certificate resources have different move support depending on scope. Per Microsoft's resource move support table, Microsoft.Web/certificates supports moving across subscriptions but not across resource groups, and managed certificates (the free ones) support neither. So if that leftover certificate is sitting in your source resource group, the resource-group move will keep failing validation no matter what you do, until the certificate is out of the picture.
Steps to fix it:
- In the Azure Portal, go to your source resource group and turn on Show hidden types in the resource list (or in the move blade itself). This reveals certificate resources that don't show up by default.
- Check what type of certificate it is:
- If it is a free App Service Managed Certificate, delete it. It cannot be moved to any resource group or subscription. Recreate it in the destination resource group later if you set up a custom domain again.
- If it is an uploaded or imported certificate, back it up (export the PFX) if you will need it again, then delete it from the source resource group. It cannot move resource group to resource group in the same subscription, only across subscriptions, so deleting and re-uploading in the destination is the workaround.
- Retry the move. With the certificate resource gone, only the sites and server farm remain, both of which support resource group moves, so validation should pass.
- Re-upload or recreate the certificate in the destination resource group afterward if you still need it bound to a custom domain.
- If it is a free App Service Managed Certificate, delete it. It cannot be moved to any resource group or subscription. Recreate it in the destination resource group later if you set up a custom domain again.
Reference: Move App Service resources to a new resource group or subscription, Azure resource types for move operations – Microsoft.Web
Please click Accept Answer and upvote if this helped.