Azure Storage built-in role

Data Box Reader

Views Azure Data Box orders and status without creating an order or editing order details. The built-in definition also includes actions to list order secrets and unencrypted device credentials, making this more sensitive than an ordinary metadata-only reader.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 028f4ed7-e2a9-465e-a8f4-9c0ffdfdc027

Control-plane actions (10)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy. An order-level assignment exposes that order; a resource-group or subscription assignment exposes all inheriting Data Box orders. It has no DataActions and does not grant access to the associated storage-account data.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Use Data Box Reader only when the principal needs order visibility or authorized credential retrieval. Scope it to one order, monitor credential-listing events, and use a custom role if a monitoring user must not receive the built-in role's credential actions.

Related roles (1)

Editorial sources (6)

Official Microsoft Learn documentation →