Azure Containers built-in role

Azure Container Storage Owner

Installs Azure Container Storage, grants its managed identity access, and configures Azure Elastic SAN resources. It has broad Azure control-plane deployment and support operations plus role-assignment write and delete authority constrained by a built-in condition to Azure Container Storage Operator; it has no storage data-plane DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 95de85bd-744d-4664-9dde-11430bc34793

Control-plane actions (17)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Conditions (1)

Assignable scopes (1)

Practical scope

Microsoft documents this role at subscription scope for installation and Elastic SAN setup. The assignment is inherited throughout the subscription, while Operator assignments should be narrowed to the AKS infrastructure resource group when supported.

Common use cases (1)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure Container Storage Owner only to the storage platform owner for subscriptions that require its full installation and Elastic SAN workflow. Prefer Contributor when sufficient, preserve the built-in condition, and scope Operator to the AKS managed identity and infrastructure boundary.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →