Azure Storage built-in role

Elastic SAN Network Admin

Reads Azure Elastic SAN resources and approves, creates, updates, or deletes private endpoint connections on a SAN. It controls network reachability to the SAN but has no DataActions and does not by itself mount or read iSCSI volumes.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: fa6cecf6-5db3-4c43-8470-c540bcb4eafa

Control-plane actions (5)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy. Assign it on the Elastic SAN whose private endpoint connections the network administrator manages; a parent assignment is inherited by all child SAN resources. Its authority is control-plane network administration rather than volume data access.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Elastic SAN Network Admin to the private-connectivity team at the individual SAN scope. Require review of the endpoint subnet and DNS design before approval, and keep volume or SAN lifecycle authority in separate roles.

Editorial sources (5)

Official Microsoft Learn documentation →