Azure Storage built-in role

Azure File Sync Reader

Reads Azure File Sync Storage Sync Service resources without changing sync topology, registering servers, assigning roles, or reading file contents. The built-in definition is control-plane read only and has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 754c1a27-40dc-4708-8ad4-2bffdeee09e8

Control-plane actions (1)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy. Assign it on the Storage Sync Service or the narrow resource group that contains the services to inspect; parent assignments are inherited by child Storage Sync Service resources but do not add Azure Files data access.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Azure File Sync Reader on the specific Storage Sync Service for view-only operations. Add no storage data role unless file-content inspection is separately approved, and escalate temporarily to Azure File Sync Administrator only for a documented topology change.

Related roles (1)

Editorial sources (5)

Official Microsoft Learn documentation →