A developer is implementing role-based access control (RBAC) for an Azure Storage Account. A new custom role needs to be created that allows a specific Azure Function App to read and list blobs, but not write or delete them. Which `actions` property should be included in the custom role definition?
- A`Microsoft.Storage/storageAccounts/read`, `Microsoft.Storage/storageAccounts/write`
- B`Microsoft.Storage/storageAccounts/blobServices/containers/blobs/write`, `Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete`
- C`Microsoft.Storage/storageAccounts/blobServices/containers/blobs/*`
- D`Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read`, `Microsoft.Storage/storageAccounts/blobServices/containers/blobs/list`
Show answer & explanationAnswer & explanation
Correct answer: D. `Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read`, `Microsoft.Storage/storageAccounts/blobServices/containers/blobs/list`
The problem specifies that the custom role should allow reading and listing blobs, but not writing or deleting. Option B correctly includes the `read` and `list` actions for blobs, adhering to the principle of least privilege. Option A includes write/delete, Option C is for storage accounts themselves, not blobs, and Option D grants all permissions.
Why the other options are wrong
- A. These actions apply at the storage account level, not specifically for blob operations, and include write permissions.
- B. These actions grant write and delete permissions, which are explicitly forbidden by the requirement.
- C. The wildcard `*` grants all possible actions on blobs, violating the principle of least privilege and the explicit restriction on write/delete.
Azure RBAC Custom Role Definition
A JSON definition that specifies a set of permissions (actions, notActions, dataActions, notDataActions) that can be assigned to an Azure principal (user, group, managed identity, service principal).
- Allows fine-grained control over Azure resources
- Adheres to the principle of least privilege
- Can define both control plane and data plane actions
Memory trick: RBAC Custom Role: Only give the key for *what* they need to *do*.