Azure Storage built-in role

Elastic SAN Volume Group Owner

Provides full control-plane access to an Elastic SAN volume group, including its volumes and network security policies that can unblock data-path access. It does not grant full SAN-wide lifecycle authority and has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: a8281131-f312-4f34-8d98-ae12be9f0d23

Control-plane actions (4)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy, but its Microsoft.ElasticSan permissions are limited to volume-group resources. Assign it on the target volume group so its wildcard does not extend to every volume group under a SAN through a broader parent scope.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Elastic SAN Volume Group Owner to the administrator of one approved workload boundary, directly on that volume group. Keep SAN-wide control separate and require review for network-policy or destructive volume changes.

Common questions

When should I assign the Elastic SAN Volume Group Owner Azure role?

Assign Elastic SAN Volume Group Owner when you need to: Delegate lifecycle management of one workload's Elastic SAN volume group and its volumes.; and Let a workload storage administrator maintain the volume group's network security policies without granting control of the entire SAN.. Practical scope: The role is assignable throughout the Azure hierarchy, but its Microsoft.ElasticSan permissions are limited to volume-group resources. Assign it on the target volume group so its wildcard does not extend to every volume group under a SAN through a broader parent scope.

What permissions does the Elastic SAN Volume Group Owner Azure role grant?

The role definition grants 4 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/roleAssignments/read; Microsoft.Authorization/roleDefinitions/read; Microsoft.ElasticSan/elasticSans/volumeGroups/*; and Microsoft.ElasticSan/locations/asyncoperations/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Elastic SAN Volume Group Owner Azure role?

Key considerations when assigning Elastic SAN Volume Group Owner: The role can create, modify, and delete volume-group resources and alter policies that permit data-path access to all volumes in the group.; Every volume inherits the group's network configuration, so one change can expose or disconnect the entire workload set.; and No DataActions are present, but control of volumes and their network boundary remains highly privileged.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →