Does Storage Account Encryption Scope Contributor Role Allow Key Regeneration?

Configure and manage storage accounts
Answer Correct answer: B — Assigning the Storage Account Encryption Scope Contributor Role does not grant the permissions needed to list and regenerate storage account keys.

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure Storage account named storage1. You need to enable a user named User1 to list and regenerate storage account keys for storage1. Solution: You assign the Storage Account Encryption Scope Contributor Role to User1. Does this meet the goal?

  1. Yes
  2. No Correct Answer

Community Votes

B
80%
A
20%

80% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests Azure RBAC roles for storage accounts, highlighting the trap of assuming a role with 'Contributor' in its name grants key management permissions.

The Storage Account Encryption Scope Contributor role does not grant permissions to list or regenerate storage account keys. This page confirms that assigning this role fails to meet the goal of enabling key management for an Azure Storage account.

Choosing 'Yes' because the role title contains 'Contributor,' leading to the false assumption that it includes key regeneration permissions.

Community Discussion (9 comments)

Dankho 👍 6
The Storage Account Encryption Scope Contributor role allows a user to manage encryption scopes in a storage account but does not grant the ability to list and regenerate storage account keys. To meet the goal, you would need to assign the Storage Account Key Operator Service Role or a role with broader access such as the Storage Account Contributor role, which includes permissions to list and regenerate keys.
Bravo_Dravel 👍 1 Selected: B
This role allows managing encryption scopes but does not grant permissions to list and regenerate storage account keys1. To enable User1 to list and regenerate storage account keys, you should assign the Storage Account Key Operator Service Role or the Storage Account Contributor Role
alsmk2 👍 1 Selected: B
SA Cont or Key operator role required.
Shakka 👍 2 Selected: B
the Storage Account Encryption Scope Contributor role does not have the permissions to list and regenerate storage account keys. These actions require specific permissions that are not included in this role. To list and regenerate storage account keys, you would need a role that includes the Microsoft.Storage/storageAccounts/listKeys/action and Microsoft.Storage/storageAccounts/regenerateKey/action permissions. Some roles that have these permissions are: Owner Contributor Storage Account Key Operator Service Role1.
Mentalfloss 👍 1 Selected: B
Cancelling my previous A vote.
arunyadav09 👍 2 Selected: B
It should be Storage Account Key Operator Service Role.
appyapurv 👍 1
• The Storage Account Encryption Scope Contributor role provides permissions to manage encryption scopes within a storage account. However, it does not grant permissions to list or regenerate storage account keys. • To allow a user to list and regenerate storage account keys, the user should be assigned the Storage Account Key Operator Service Role or a higher role like Contributor or Storage Account Contributor. Thus, assigning the Storage Account Encryption Scope Contributor role does not meet the goal of enabling User1 to list and regenerate storage account keys.
Alawi1990 👍 2
The Storage Account Encryption Scope Contributor role does not grant permissions to list and regenerate storage account keys. - No
Mentalfloss 👍 2 Selected: A
I wasn't sure if this was a real role so I Googled it, answer is A (Yes).

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is "No" because the Storage Account Encryption Scope Contributor role is specifically designed to manage encryption scopes within a storage account. It does not include the Microsoft.Storage/storageAccounts/listKeys/action or Microsoft.Storage/storageAccounts/regenerateKey/action permissions required to list and regenerate storage account keys.

Why the Other Options Are Wrong

Selecting "Yes" incorrectly assumes that any role with "Contributor" in its name inherently possesses full management rights, including key operations. In Azure RBAC, roles are highly granular, and the Encryption Scope Contributor role is narrowly scoped to encryption management only.

Community Comment Notes

Community members correctly pointed out that the required permissions are found in the Storage Account Key Operator Service Role, as Shakka noted by listing the specific "listKeys/action" and "regenerateKey/action" actions. Dankho also highlighted that "Storage Account Key Operator Service Role" is the correct role to assign for this goal.

Official Reference

Exam Strategy

When evaluating Azure RBAC role assignments, never rely solely on the role's name; always verify the specific actions (permissions) it grants. For key management tasks, look for roles explicitly containing 'Key Operator' or verify the presence of listKeys and regenerateKey actions.

Related Analysis

Practice All AZ-104 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-104 Practice Test →

← Back to AZ-104 Study Guide