Azure Storage built-in role

Storage Actions Contributor

Authors and manages Azure Storage Actions storage tasks. It can create, read, update, delete, list, and preview tasks and view their assignments and reports, but it has no DataActions and does not assign a task to a storage account or execute blob operations.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: bd8acdb0-202c-4493-a7fe-ef98eefbfbc4

Control-plane actions (10)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy. Assign it on the storage task or the resource group containing approved tasks. Its permissions are limited to the Storage Actions control plane and supporting reads; target storage data access belongs to the task managed identity.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Storage Actions Contributor to storage-task authors at the task or dedicated resource-group scope. Keep target-account assignment and execution permissions separate, and require review before a task with delete or retention operations is assigned.

Related roles (2)

Editorial sources (5)

Official Microsoft Learn documentation →