Azure Storage built-in role
Data Box Reader
Views Azure Data Box orders and status without creating an order or editing order details. The built-in definition also includes actions to list order secrets and unencrypted device credentials, making this more sensitive than an ordinary metadata-only reader.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 028f4ed7-e2a9-465e-a8f4-9c0ffdfdc027
Control-plane actions (10)
Microsoft.Authorization/*/readMicrosoft.Databox/*/readMicrosoft.Databox/jobs/listsecrets/actionMicrosoft.Databox/jobs/listcredentials/actionMicrosoft.Databox/locations/availableSkus/actionMicrosoft.Databox/locations/validateInputs/actionMicrosoft.Databox/locations/regionConfiguration/actionMicrosoft.Databox/locations/validateAddress/actionMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The role is assignable throughout the Azure hierarchy. An order-level assignment exposes that order; a resource-group or subscription assignment exposes all inheriting Data Box orders. It has no DataActions and does not grant access to the associated storage-account data.
Common use cases (2)
- Track Data Box order status, shipping, copy results, and completion information without changing the order.
- Retrieve device credentials for an authorized setup operator and review order logs for audit or troubleshooting.
Prerequisites (3)
- Confirm that the principal needs the credential-listing actions as well as order visibility; otherwise a custom role may be required.
- Identify the individual order scope whenever cross-order visibility is unnecessary.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at that scope.
Best practices (3)
- Assign at the individual Data Box order and only for the period in which status, logs, or device credentials are needed.
- Monitor ListCredentials access in the Azure Activity Log as Microsoft documents.
- Treat downloaded credentials, copy logs, audit logs, manifests, and order history as sensitive operational records.
Security considerations (3)
- The role can list device credentials and secrets even though it cannot edit the order.
- Device credentials enable local appliance access and must not be exposed to general monitoring users.
- The role does not grant storage-account data access, but broad scope exposes order and credential information for multiple transfers.
Assignment guidance
Use Data Box Reader only when the principal needs order visibility or authorized credential retrieval. Scope it to one order, monitor credential-listing events, and use a custom role if a monitoring user must not receive the built-in role's credential actions.
Related roles (1)
- Data Box Contributor: Microsoft documents Contributor for creating and managing orders while Reader is the view-oriented role.
Editorial sources (6)
- Azure built-in roles for Storage →
Supports: Description, Practical scope, Prerequisites, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-16.
- Track and log Azure Data Box events →
Supports: Description, Practical scope, Common use cases, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Manage Azure Data Box using the Azure portal →
Supports: Common use cases, Best practices, Security considerations. Retrieved 2026-07-16.