Does Storage Account Key Operator Service Role Allow Listing and Regenerating Keys?

Configure and manage storage accounts Manage access to Azure resources
Answer Correct answer: A — Yes, the Storage Account Key Operator Service Role grants User1 listkeys and regeneratekey actions on storage1, which is exactly the stated goal.

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure Storage account named storage1. You need to enable a user named User1 to list and regenerate storage account keys for storage1. Solution: You assign the Storage Account Key Operator Service Role to User1. Does this meet the goal?

  1. Yes Correct Answer
  2. No

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tested: the exact permission boundary of the Storage Account Key Operator Service Role; the trap is confusing it with Storage Account Contributor or Contributor, which can manage the account but are broader than the key-management task.

This AZ-104 scenario asks whether assigning the Storage Account Key Operator Service Role to User1 grants the ability to list and regenerate keys for an Azure Storage account. The role does exactly that — it can list and regenerate storage account access keys but grants no other data or configuration permissions.

The most common wrong answer is 'No', based on the assumption that key management requires Contributor or Storage Account Contributor, or that a custom role is needed — the built-in key operator role already covers listing and regenerating keys.

Community Discussion (3 comments)

Dash_888 👍 7 Selected: A
Storage Account Key Operator Service Role - Permits listing and regenerating storage account access keys. https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles
lumax007 👍 1 Selected: A
https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles/storage#storage-account-key-operator-service-role
cosmicT73 👍 1 Selected: A
A is definitely correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Azure RBAC ships a built-in role purpose-built for this exact task: Storage Account Key Operator Service Role. Its documented permission set is Microsoft.Storage/storageAccounts/listkeys/action and Microsoft.Storage/storageAccounts/regeneratekey/action, which map precisely to "list and regenerate storage account keys" for storage1. Because the actions are scoped to the storage account (and can be assigned at the subscription, resource group, or storage account scope), assigning it to User1 satisfies the stated goal with least privilege. No custom role, and no broader Contributor role, is required. Note that this role grants only key operations — it does not give access to blob, file, queue, or table data.

Why the Other Options Are Wrong

Option B ("No") would only be right if the role lacked the regenerate-key permission or if the goal also required data-plane access or account configuration. It does not — the requirement is limited to listing and regenerating keys. Choosing B usually stems from conflating this narrow role with Storage Account Contributor, which manages the account but is far broader than needed. It may also stem from assuming a custom role is mandatory, which is unnecessary when a built-in role covers the scenario exactly. Since the role's action list matches the requirement one-to-one, the correct choice is "Yes."

Community Comment Notes

Virtually every learner in the thread selected the affirmative option, and Dash_888 supplied the rationale directly: "Permits listing and regenerating storage account access keys," linking the built-in RBAC roles page. lumax007 pointed to the dedicated role sub-page under the storage section of the same documentation set, and cosmicT73 simply stated the choice was "definitely correct." The unanimity here matches the vendor documentation, so there is no dissenting technical argument to weigh against it.

Official Reference

Exam Strategy

For AZ-104 role questions, match the required action list to the smallest built-in role that contains exactly those actions — key listing and regeneration always points to the Key Operator Service Role. Watch for distractors that swap in Storage Account Contributor, which also manages the account but is broader than the stated goal.

Frequently Asked Questions

Does the Storage Account Key Operator Service Role let User1 read blob or file data?

No. It only grants listkeys and regeneratekey on the storage account; reading blob or file data requires a data-plane role such as Storage Blob Data Reader.

Would Storage Account Contributor also work, and why is it a poorer fit?

It can manage the account, but it is far broader than required; the key operator role follows least privilege for listing and regenerating keys only.

Related Analysis

Practice All AZ-104 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-104 Practice Test →

← Back to AZ-104 Study Guide