Azure Storage built-in role
Data Box Contributor
Creates and manages Azure Data Box orders and other Microsoft.DataBox resources without granting Azure RBAC access to others. Its Microsoft.Databox/* wildcard includes jobs/listsecrets/action and jobs/listcredentials/action, so the role can retrieve device secrets and credentials in addition to changing the physical data-transfer workflow. It does not itself grant destination storage-account access.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: add466c9-e687-43fc-8d98-dfcf8d720be5
Control-plane actions (6)
Microsoft.Authorization/*/readMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*Microsoft.Databox/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The role is assignable throughout the Azure hierarchy. At an individual order it manages that order and can retrieve its device secrets and credentials; at resource-group or subscription scope those capabilities apply to all inheriting Data Box resources. Its permissions are control-plane only and do not grant access to destination storage data.
Common use cases (2)
- Create and administer a Data Box import or export order, including supported order changes, tracking, and completion workflows.
- Manage Data Box resources for a migration team while leaving Azure RBAC access delegation to a separate administrator.
Prerequisites (3)
- For order creation, the principal must already have write access to the destination storage account.
- Confirm the shipping, notification, destination, and data-transfer requirements before creating the physical-device order.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at the Data Box order or containing scope.
Best practices (3)
- Assign at the individual order when the principal does not need to manage every order in a resource group.
- Keep destination storage permissions separate and no broader than the transfer workflow requires.
- Treat retrieved device passwords, secrets, credentials, order history, copy logs, audit logs, and bills of materials as sensitive records.
Security considerations (4)
- The Microsoft.Databox/* wildcard includes listsecrets and listcredentials, which expose device access material such as the device password documented in the Data Box administration workflow.
- The role can create, change, cancel, clone, or delete Data Box resources according to the order state and can affect a physical data-transfer workflow.
- Order records include shipping, contact, device, and transfer metadata, so both credentials and order visibility should be limited to the responsible team.
- The role does not itself grant storage-account access, so adding a broad storage role would materially expand its effective authority.
Assignment guidance
Assign Data Box Contributor only to an operator authorized both to administer the order and retrieve its device secrets and credentials, preferably at the individual-order scope. Grant destination storage write access separately; do not treat this role as ordinary order-status access.
Related roles (1)
- Data Box Reader: Microsoft documents Reader as the view-oriented Data Box role and Contributor as the role that can create and manage orders.
Editorial sources (6)
- Azure built-in roles for Storage →
Supports: Description, Practical scope, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-16.
- Track and log Azure Data Box events →
Supports: Common use cases, Prerequisites, Best practices, Related roles. Retrieved 2026-07-16.
- Manage Azure Data Box using the Azure portal →
Supports: Description, Practical scope, Common use cases, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.