Ensure that the roles are assigned on the subscription level and account for https://learn.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-aws#prerequisites and https://learn.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-gcp#prerequisites
- If CIEM is enabled as part of Defender for CSPM the user enabling the connector will also need Security Admin role and Application.ReadWrite.All permission for your tenant.
You'll also need to have sufficient permissions on the corresponding AWS account and GCP project
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
hth
Marcin