Azure Storage built-in role

Storage File Data Privileged Reader

Reads Azure file data by using privileged backup semantics that override existing file and directory NTFS permissions. It cannot write, delete, or change ACLs, but Microsoft documents no equivalent built-in role on Windows file servers because of its ACL-bypassing read access.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b8eda974-7b85-4f76-af95-65846b26df6d

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (2)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

This is an Azure Files data-plane role with no management-plane Actions. Assign it at an individual file share or storage account; within that scope, privileged OAuth REST reads can supersede file and directory ACLs. Storage-account and file-share management permissions remain separate.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Storage File Data Privileged Reader only to a trusted service identity that must perform ACL-bypassing reads, at the narrowest file-share scope. Require explicit backup intent and choose SMB Share Reader instead when normal ACL enforcement is required.

Related roles (2)

Editorial sources (5)

Official Microsoft Learn documentation →