Azure Storage built-in role

Storage Table Data Reader

Reads Azure Storage tables and queries table entities with Microsoft Entra authorization. It cannot create or delete tables and cannot add, update, merge, replace, or delete entities.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 76199698-9eea-4c19-bc75-cec21354c6b6

Control-plane actions (1)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role can be assigned at an individual table, storage account, resource group, subscription, or management group and is inherited by entities. Table scope confines reads to one table; Microsoft notes that table-scoped assignment currently requires PowerShell, Azure CLI, or a template.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Storage Table Data Reader to the query identity on the individual table using PowerShell, Azure CLI, or a template. Escalate to Table Data Contributor only when entity or table mutation is explicitly required.

Related roles (1)

Editorial sources (5)

Official Microsoft Learn documentation →