Azure Storage built-in role

Elastic SAN Owner

Provides full control-plane access to all resources under Azure Elastic SAN, including SANs, volume groups, volumes, and network security policies that can unblock data-path access. It has no DataActions, but it can materially change who can reach iSCSI volumes.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 80dcbedb-47ef-405d-95bd-188a1b4ac406

Control-plane actions (6)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy. An assignment on a SAN or parent scope covers every Elastic SAN resource beneath it. Its wildcard Microsoft.ElasticSan Actions are management-plane permissions; actual client volume I/O still uses the configured iSCSI and network path.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Elastic SAN Owner only to administrators who need complete SAN lifecycle and network-policy control, scoped to one SAN. Use narrower volume-group or network administration where the task does not require SAN-wide changes.

Editorial sources (5)

Official Microsoft Learn documentation →