Azure Storage built-in role

Elastic SAN Reader

Provides control-path read access to Azure Elastic SAN resources and related role-assignment and health metadata. It cannot change SAN resources, network policy, private endpoints, or volume data and has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: af6a70f8-3c9f-4105-acf1-d719e9fca4ca

Control-plane actions (5)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy. An assignment on a SAN, resource group, or parent scope exposes Elastic SAN control-plane information for the selected resource and inherited children, but does not authorize an iSCSI client to access volume contents.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Elastic SAN Reader at the SAN or narrower supported scope for view-only work. Do not add owner or network-administration roles unless the principal has a separately approved change responsibility.

Common questions

When should I assign the Elastic SAN Reader Azure role?

Assign Elastic SAN Reader when you need to: Inspect SAN, volume-group, volume, health, and access configuration for monitoring or audit.; and Troubleshoot control-plane configuration without granting storage lifecycle or network-policy changes.. Practical scope: The role is assignable throughout the Azure hierarchy. An assignment on a SAN, resource group, or parent scope exposes Elastic SAN control-plane information for the selected resource and inherited children, but does not authorize an iSCSI client to access volume contents.

What permissions does the Elastic SAN Reader Azure role grant?

The role definition grants 5 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/roleAssignments/read; Microsoft.Authorization/roleDefinitions/read; Microsoft.ResourceHealth/availabilityStatuses/read; Microsoft.Resources/subscriptions/resourceGroups/read; and Microsoft.ElasticSan/elasticSans/*/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Elastic SAN Reader Azure role?

Key considerations when assigning Elastic SAN Reader: Read access exposes SAN topology, volume groups, volumes, network configuration, health, and RBAC metadata.; The role has no write Actions or DataActions and cannot open the data path.; and A broad assignment reveals storage architecture across every inheriting SAN.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (4)

Official Microsoft Learn documentation →