Azure Storage built-in role

Elastic SAN Reader

Provides control-path read access to Azure Elastic SAN resources and related role-assignment and health metadata. It cannot change SAN resources, network policy, private endpoints, or volume data and has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: af6a70f8-3c9f-4105-acf1-d719e9fca4ca

Control-plane actions (5)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy. An assignment on a SAN, resource group, or parent scope exposes Elastic SAN control-plane information for the selected resource and inherited children, but does not authorize an iSCSI client to access volume contents.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Elastic SAN Reader at the SAN or narrower supported scope for view-only work. Do not add owner or network-administration roles unless the principal has a separately approved change responsibility.

Editorial sources (4)

Official Microsoft Learn documentation →