Azure Storage built-in role

Storage Blob Data Reader

Reads and lists Azure Blob Storage containers and blob data with Microsoft Entra authorization. It cannot write or delete blobs, but it includes the action to request a Blob user delegation key when the assignment is effective at storage-account scope or higher.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 2a2b9908-6ea1-4ae2-8e65-a410df84e7d1

Control-plane actions (2)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role can be assigned at a container, storage account, resource group, subscription, or management group and is inherited by child blobs. Container scope limits blob reads to that container; requesting a user delegation key requires storage-account scope or higher.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Storage Blob Data Reader on the specific container the principal must read. Add Reader only for portal navigation, and do not widen the role to storage-account scope merely to obtain a delegation key unless SAS issuance is an explicit requirement.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →