Azure Storage built-in role

Azure File Sync Reader

Reads Azure File Sync Storage Sync Service resources without changing sync topology, registering servers, assigning roles, or reading file contents. The built-in definition is control-plane read only and has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 754c1a27-40dc-4708-8ad4-2bffdeee09e8

Control-plane actions (1)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy. Assign it on the Storage Sync Service or the narrow resource group that contains the services to inspect; parent assignments are inherited by child Storage Sync Service resources but do not add Azure Files data access.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Azure File Sync Reader on the specific Storage Sync Service for view-only operations. Add no storage data role unless file-content inspection is separately approved, and escalate temporarily to Azure File Sync Administrator only for a documented topology change.

Related roles (1)

Common questions

When should I assign the Azure File Sync Reader Azure role?

Assign Azure File Sync Reader when you need to: Monitor registered servers, sync groups, cloud endpoints, server endpoints, and service health without changing them.; and Give support or audit personnel visibility into Azure File Sync configuration while keeping file data and topology changes separate.. Practical scope: The role is assignable throughout the Azure hierarchy. Assign it on the Storage Sync Service or the narrow resource group that contains the services to inspect; parent assignments are inherited by child Storage Sync Service resources but do not add Azure Files data access.

What permissions does the Azure File Sync Reader Azure role grant?

The role definition grants 1 combined control-plane and data-plane actions. Representative operations include: Microsoft.StorageSync/*/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure File Sync Reader Azure role?

Key considerations when assigning Azure File Sync Reader: The role exposes sync topology, registered-server, and endpoint metadata that can reveal file-server architecture.; It has no DataActions and does not read synchronized files or grant access to storage account keys.; and A broad parent-scope assignment reveals multiple business units when several Storage Sync Services share the scope.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →