Does Storage Account Encryption Scope Contributor Role Allow Key Regeneration?
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure Storage account named storage1. You need to enable a user named User1 to list and regenerate storage account keys for storage1. Solution: You assign the Storage Account Encryption Scope Contributor Role to User1. Does this meet the goal?
Community Votes
80% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests Azure RBAC roles for storage accounts, highlighting the trap of assuming a role with 'Contributor' in its name grants key management permissions.
The Storage Account Encryption Scope Contributor role does not grant permissions to list or regenerate storage account keys. This page confirms that assigning this role fails to meet the goal of enabling key management for an Azure Storage account.
Choosing 'Yes' because the role title contains 'Contributor,' leading to the false assumption that it includes key regeneration permissions.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct answer is "No" because the Storage Account Encryption Scope Contributor role is specifically designed to manage encryption scopes within a storage account. It does not include theMicrosoft.Storage/storageAccounts/listKeys/action or Microsoft.Storage/storageAccounts/regenerateKey/action permissions required to list and regenerate storage account keys.Why the Other Options Are Wrong
Selecting "Yes" incorrectly assumes that any role with "Contributor" in its name inherently possesses full management rights, including key operations. In Azure RBAC, roles are highly granular, and the Encryption Scope Contributor role is narrowly scoped to encryption management only.Community Comment Notes
Community members correctly pointed out that the required permissions are found in the Storage Account Key Operator Service Role, as Shakka noted by listing the specific "listKeys/action" and "regenerateKey/action" actions. Dankho also highlighted that "Storage Account Key Operator Service Role" is the correct role to assign for this goal.Official Reference
Exam Strategy
When evaluating Azure RBAC role assignments, never rely solely on the role's name; always verify the specific actions (permissions) it grants. For key management tasks, look for roles explicitly containing 'Key Operator' or verify the presence of listKeys and regenerateKey actions.
Related Analysis
Practice All AZ-104 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-104 Practice Test →