Azure Storage built-in role
Storage Table Delegator
Requests a Table service user delegation key that can sign a user delegation SAS for an Azure Storage table. The key cannot access table data directly and the role has no DataActions; separate table data permissions bound the SAS operations and entity ranges.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 965033a5-c8eb-4f35-b82f-fef460a3606d
Control-plane actions (1)
Microsoft.Storage/storageAccounts/tableServices/generateUserDelegationKey/action
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The delegation-key action operates at storage-account level, so assign this role on the storage account, resource group, or subscription. Keep the broker's separate table data role scoped to the intended table so key generation does not automatically grant account-wide entity access.
Common use cases (2)
- Let a trusted SAS broker issue short-lived user delegation SAS tokens for an approved table or entity range.
- Keep direct table data permissions table-scoped while granting account-level delegation-key authority.
Prerequisites (3)
- Use a storage service version that supports Table user delegation SAS and grant the broker a separate table data role that defines its maximum delegated operations.
- Design table and partition or row-key ranges, permissions, expiry, HTTPS, distribution, logging, and revocation.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at storage-account scope or higher.
Best practices (3)
- Assign to a dedicated SAS-broker managed identity at one storage account.
- Constrain SAS access by table and entity range, grant the minimum operations, use a short expiry, and require HTTPS.
- Log issuance in the broker and maintain a revocation process because Azure Storage does not inventory generated SAS tokens.
Security considerations (3)
- A delegation key can sign multiple bearer SAS tokens during its lifetime.
- The role alone cannot query or mutate tables, but the broker's table data role determines the maximum delegated authority.
- A leaked SAS can expose or modify entities in its signed table and range until expiry or revocation.
Assignment guidance
Assign Storage Table Delegator to a trusted SAS-broker identity on the storage account, with a separate table data role constrained to the intended table. Limit each SAS by entity range, operations, HTTPS, and lifetime, and record issuance for audit and revocation.
Related roles (2)
- Storage Table Data Reader: A separate role that can bound delegated table access to queries.
- Storage Table Data Contributor: A separate role that can bound delegated table access to entity mutation.
Editorial sources (5)
- Azure built-in roles for Storage →
Supports: Description. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope. Retrieved 2026-07-16.
- Grant limited access to data with shared access signatures →
Supports: Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Create a user delegation SAS →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.