Azure Storage built-in role

Data Box Reader

Views Azure Data Box orders and status without creating an order or editing order details. The built-in definition also includes actions to list order secrets and unencrypted device credentials, making this more sensitive than an ordinary metadata-only reader.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 028f4ed7-e2a9-465e-a8f4-9c0ffdfdc027

Control-plane actions (10)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy. An order-level assignment exposes that order; a resource-group or subscription assignment exposes all inheriting Data Box orders. It has no DataActions and does not grant access to the associated storage-account data.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Use Data Box Reader only when the principal needs order visibility or authorized credential retrieval. Scope it to one order, monitor credential-listing events, and use a custom role if a monitoring user must not receive the built-in role's credential actions.

Related roles (1)

Common questions

When should I assign the Data Box Reader Azure role?

Assign Data Box Reader when you need to: Track Data Box order status, shipping, copy results, and completion information without changing the order.; and Retrieve device credentials for an authorized setup operator and review order logs for audit or troubleshooting.. Practical scope: The role is assignable throughout the Azure hierarchy. An order-level assignment exposes that order; a resource-group or subscription assignment exposes all inheriting Data Box orders. It has no DataActions and does not grant access to the associated storage-account data.

What permissions does the Data Box Reader Azure role grant?

The role definition grants 10 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Databox/*/read; Microsoft.Databox/jobs/listsecrets/action; Microsoft.Databox/jobs/listcredentials/action; Microsoft.Databox/locations/availableSkus/action; and Microsoft.Databox/locations/validateInputs/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Data Box Reader Azure role?

Key considerations when assigning Data Box Reader: The role can list device credentials and secrets even though it cannot edit the order.; Device credentials enable local appliance access and must not be exposed to general monitoring users.; and The role does not grant storage-account data access, but broad scope exposes order and credential information for multiple transfers.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →