You have an Azure Storage account named storage1.
You need to enable a user named User1 to list and regenerate storage account keys for storage1.
Solution: You assign the Storage Account Key Operator Service Role to User1.
Does this meet the goal?
The built-in Storage Account Key Operator Service Role grants exactly the Microsoft.Storage/storageAccounts/listkeys/action and Microsoft.Storage/storageAccounts/regeneratekey/action permissions, which allow a principal to list and regenerate the account's shared keys without granting broader data-plane or control-plane rights (it cannot create/delete storage accounts, configure networking, or manage RBAC). This matches the stated requirement precisely and follows least-privilege practice, since roles like Contributor or Owner would also work but grant unnecessary additional permissions. Reader and Storage Blob Data Reader would not permit key operations at all. Because the assigned role's actions match the task exactly, this solution meets the goal.
Official Reference
Azure built-in roles --- Storage Account Key Operator Service Role --- https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles/storage#storage-account-key-operator-service-role
Currently there are no comments in this discussion, be the first to comment!