Azure Containers built-in role

Azure Container Storage Contributor

Installs and manages the Azure Container Storage Kubernetes extension and ARM deployments. It can create or delete role assignments only for Azure Container Storage Operator under the built-in condition. It has no Microsoft.ElasticSan or Microsoft.Storage Actions and no storage DataActions, so it does not itself manage Elastic SAN or Azure Storage resources.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 95dd08a6-00bd-4661-84bf-f6726f83a4d0

Control-plane actions (12)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Conditions (1)

Assignable scopes (1)

Practical scope

Microsoft documents this role at subscription scope for installation, although the resulting Operator assignment can be narrowed to a resource group. Because Azure assignments inherit, subscription scope gives the contributor its published Container Storage management authority across that subscription.

Common use cases (1)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure Container Storage Contributor to the approved installer at the documented subscription scope only where it owns the extension deployment. Preserve the built-in condition and use its delegation solely to assign Operator to the AKS kubelet or agent-pool identity at the narrowest infrastructure scope.

Related roles (2)

Editorial sources (7)

Official Microsoft Learn documentation →