Azure Storage built-in role
Elastic SAN Network Admin
Reads Azure Elastic SAN resources and approves, creates, updates, or deletes private endpoint connections on a SAN. It controls network reachability to the SAN but has no DataActions and does not by itself mount or read iSCSI volumes.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: fa6cecf6-5db3-4c43-8470-c540bcb4eafa
Control-plane actions (5)
Microsoft.ElasticSan/elasticSans/*/readMicrosoft.ElasticSan/elasticSans/PrivateEndpointConnectionsApproval/actionMicrosoft.ElasticSan/elasticSans/privateEndpointConnections/writeMicrosoft.ElasticSan/elasticSans/privateEndpointConnections/deleteMicrosoft.ElasticSan/locations/asyncoperations/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The role is assignable throughout the Azure hierarchy. Assign it on the Elastic SAN whose private endpoint connections the network administrator manages; a parent assignment is inherited by all child SAN resources. Its authority is control-plane network administration rather than volume data access.
Common use cases (2)
- Approve and maintain private endpoint connections for an Elastic SAN while allowing the network team to inspect SAN configuration.
- Separate private-connectivity administration from full SAN and volume-group lifecycle management.
Prerequisites (3)
- Plan the virtual network, subnet address capacity, private DNS, and endpoint architecture for each target volume group.
- Confirm which SAN resources the network administrator is authorized to expose through a private endpoint.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at the SAN scope.
Best practices (3)
- Use private endpoints and disable public network access when service endpoints are not required.
- Assign on the individual SAN rather than a subscription when one network team does not manage every SAN.
- Treat private endpoint approval as a data-path boundary change and review the source subnet before approval.
Security considerations (3)
- Approving a private endpoint grants implicit SAN traffic access from the endpoint subnet; apply network policies when more granular controls are required.
- The role can delete private endpoint connections and disrupt volume connectivity.
- No DataActions are present, but network reachability is a prerequisite for iSCSI data access and remains security-sensitive.
Assignment guidance
Assign Elastic SAN Network Admin to the private-connectivity team at the individual SAN scope. Require review of the endpoint subnet and DNS design before approval, and keep volume or SAN lifecycle authority in separate roles.
Editorial sources (5)
- Azure built-in roles for Storage →
Supports: Description, Practical scope, Common use cases, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-16.
- Azure Elastic SAN networking concepts →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.