Azure Storage built-in role
Elastic SAN Reader
Provides control-path read access to Azure Elastic SAN resources and related role-assignment and health metadata. It cannot change SAN resources, network policy, private endpoints, or volume data and has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: af6a70f8-3c9f-4105-acf1-d719e9fca4ca
Control-plane actions (5)
Microsoft.Authorization/roleAssignments/readMicrosoft.Authorization/roleDefinitions/readMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.ElasticSan/elasticSans/*/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The role is assignable throughout the Azure hierarchy. An assignment on a SAN, resource group, or parent scope exposes Elastic SAN control-plane information for the selected resource and inherited children, but does not authorize an iSCSI client to access volume contents.
Common use cases (2)
- Inspect SAN, volume-group, volume, health, and access configuration for monitoring or audit.
- Troubleshoot control-plane configuration without granting storage lifecycle or network-policy changes.
Prerequisites (2)
- Identify the SAN or volume-group hierarchy the principal must inspect.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at that scope.
Best practices (3)
- Use this role for monitoring and audit instead of an owner role.
- Assign on the individual SAN when subscription-wide Elastic SAN inventory is unnecessary.
- Grant network reachability and workload data access separately; Reader does not provide either.
Security considerations (3)
- Read access exposes SAN topology, volume groups, volumes, network configuration, health, and RBAC metadata.
- The role has no write Actions or DataActions and cannot open the data path.
- A broad assignment reveals storage architecture across every inheriting SAN.
Assignment guidance
Assign Elastic SAN Reader at the SAN or narrower supported scope for view-only work. Do not add owner or network-administration roles unless the principal has a separately approved change responsibility.
Editorial sources (4)
- Azure built-in roles for Storage →
Supports: Description, Practical scope, Common use cases, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Azure Elastic SAN networking concepts →
Supports: Practical scope, Common use cases, Security considerations. Retrieved 2026-07-16.