Azure Storage built-in role

Storage File Data SMB Admin

Provides end users with administrative SMB access equivalent to using the storage account key. Its data permissions include reading, writing, deleting, changing permissions, using read and write backup semantics, and taking ownership of Azure Files data.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: bbf004e3-0e4b-4f86-ae4f-1f8fb47b357b

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (7)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

This is a data-plane role with no management-plane Actions. It can be assigned at a file-share or storage-account scope, but its administrative permissions can bypass ordinary ACL barriers and act across all file data in the effective scope. Storage-account configuration remains a separate control-plane concern.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Storage File Data SMB Admin only to designated file administrators for a documented administrative task, preferably on one file share and for a limited time. Use Take Ownership for ownership-only recovery or Elevated Contributor for routine ACL changes that do not require full admin equivalence.

Related roles (2)

Editorial sources (5)

Official Microsoft Learn documentation →