Azure Storage built-in role
Azure File Sync Reader
Reads Azure File Sync Storage Sync Service resources without changing sync topology, registering servers, assigning roles, or reading file contents. The built-in definition is control-plane read only and has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 754c1a27-40dc-4708-8ad4-2bffdeee09e8
Control-plane actions (1)
Microsoft.StorageSync/*/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The role is assignable throughout the Azure hierarchy. Assign it on the Storage Sync Service or the narrow resource group that contains the services to inspect; parent assignments are inherited by child Storage Sync Service resources but do not add Azure Files data access.
Common use cases (2)
- Monitor registered servers, sync groups, cloud endpoints, server endpoints, and service health without changing them.
- Give support or audit personnel visibility into Azure File Sync configuration while keeping file data and topology changes separate.
Prerequisites (2)
- Identify the Storage Sync Service resources the principal must inspect.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at that scope.
Best practices (3)
- Use this role instead of Azure File Sync Administrator for monitoring, inventory, or troubleshooting that requires no changes.
- Assign at the Storage Sync Service when visibility into other File Sync deployments is unnecessary.
- Grant any Azure Files data role separately and only if the support task explicitly requires file-content access.
Security considerations (3)
- The role exposes sync topology, registered-server, and endpoint metadata that can reveal file-server architecture.
- It has no DataActions and does not read synchronized files or grant access to storage account keys.
- A broad parent-scope assignment reveals multiple business units when several Storage Sync Services share the scope.
Assignment guidance
Assign Azure File Sync Reader on the specific Storage Sync Service for view-only operations. Add no storage data role unless file-content inspection is separately approved, and escalate temporarily to Azure File Sync Administrator only for a documented topology change.
Related roles (1)
- Azure File Sync Administrator: Adds full Storage Sync Service management and constrained role-assignment capabilities.
Editorial sources (5)
- Azure built-in roles for Storage →
Supports: Description, Practical scope, Common use cases, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Deploy Azure File Sync →
Supports: Common use cases, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Plan for an Azure File Sync deployment →
Supports: Practical scope, Best practices, Security considerations. Retrieved 2026-07-16.