Azure Storage built-in role

Elastic SAN Volume Group Owner

Provides full control-plane access to an Elastic SAN volume group, including its volumes and network security policies that can unblock data-path access. It does not grant full SAN-wide lifecycle authority and has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: a8281131-f312-4f34-8d98-ae12be9f0d23

Control-plane actions (4)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy, but its Microsoft.ElasticSan permissions are limited to volume-group resources. Assign it on the target volume group so its wildcard does not extend to every volume group under a SAN through a broader parent scope.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Elastic SAN Volume Group Owner to the administrator of one approved workload boundary, directly on that volume group. Keep SAN-wide control separate and require review for network-policy or destructive volume changes.

Editorial sources (5)

Official Microsoft Learn documentation →