Azure Storage built-in role
Elastic SAN Reader
Provides control-path read access to Azure Elastic SAN resources and related role-assignment and health metadata. It cannot change SAN resources, network policy, private endpoints, or volume data and has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: af6a70f8-3c9f-4105-acf1-d719e9fca4ca
Control-plane actions (5)
Microsoft.Authorization/roleAssignments/readMicrosoft.Authorization/roleDefinitions/readMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.ElasticSan/elasticSans/*/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The role is assignable throughout the Azure hierarchy. An assignment on a SAN, resource group, or parent scope exposes Elastic SAN control-plane information for the selected resource and inherited children, but does not authorize an iSCSI client to access volume contents.
Common use cases (2)
- Inspect SAN, volume-group, volume, health, and access configuration for monitoring or audit.
- Troubleshoot control-plane configuration without granting storage lifecycle or network-policy changes.
Prerequisites (2)
- Identify the SAN or volume-group hierarchy the principal must inspect.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at that scope.
Best practices (3)
- Use this role for monitoring and audit instead of an owner role.
- Assign on the individual SAN when subscription-wide Elastic SAN inventory is unnecessary.
- Grant network reachability and workload data access separately; Reader does not provide either.
Security considerations (3)
- Read access exposes SAN topology, volume groups, volumes, network configuration, health, and RBAC metadata.
- The role has no write Actions or DataActions and cannot open the data path.
- A broad assignment reveals storage architecture across every inheriting SAN.
Assignment guidance
Assign Elastic SAN Reader at the SAN or narrower supported scope for view-only work. Do not add owner or network-administration roles unless the principal has a separately approved change responsibility.
Common questions
When should I assign the Elastic SAN Reader Azure role?
Assign Elastic SAN Reader when you need to: Inspect SAN, volume-group, volume, health, and access configuration for monitoring or audit.; and Troubleshoot control-plane configuration without granting storage lifecycle or network-policy changes.. Practical scope: The role is assignable throughout the Azure hierarchy. An assignment on a SAN, resource group, or parent scope exposes Elastic SAN control-plane information for the selected resource and inherited children, but does not authorize an iSCSI client to access volume contents.
What permissions does the Elastic SAN Reader Azure role grant?
The role definition grants 5 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/roleAssignments/read; Microsoft.Authorization/roleDefinitions/read; Microsoft.ResourceHealth/availabilityStatuses/read; Microsoft.Resources/subscriptions/resourceGroups/read; and Microsoft.ElasticSan/elasticSans/*/read. Review the permission sections above for the complete definition and exclusions.
What are the security risks of the Elastic SAN Reader Azure role?
Key considerations when assigning Elastic SAN Reader: Read access exposes SAN topology, volume groups, volumes, network configuration, health, and RBAC metadata.; The role has no write Actions or DataActions and cannot open the data path.; and A broad assignment reveals storage architecture across every inheriting SAN.. Follow the assignment guidance above and use the narrowest practical scope.
Editorial sources (4)
- Azure built-in roles for Storage →
Supports: Description, Practical scope, Common use cases, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Azure Elastic SAN networking concepts →
Supports: Practical scope, Common use cases, Security considerations. Retrieved 2026-07-16.