Reader and Data Access Role for Storage Key Regeneration?
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure Storage account named storage1. You need to enable a user named User1 to list and regenerate storage account keys for storage1. Solution: You assign the Reader and Data Access role to User1. Does this meet the goal?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests whether Reader and Data Access grants key-management actions; the trap is assuming any role with 'Data Access' in the name can regenerate storage keys.
Assigning only the Reader and Data Access role to User1 on storage1 does not permit regenerating storage account keys, so the solution fails. This page explains why the Storage Account Key Operator Service Role is the correct built-in role for listing and rotating keys.
Choosing 'Yes' because Reader and Data Access lets a user list storage account keys, but it omits the regeneratekey action required to rotate them.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The solution assigns only the Reader and Data Access role to User1, but that role is for reading storage data and listing account keys, not for rotating them. Key regeneration is a control-plane action mapped to Microsoft.Storage/storageAccounts/regeneratekey/action, which the Reader and Data Access role does not include. To both list and regenerate keys, User1 needs the Storage Account Key Operator Service Role, a built-in role that grants listkeys and regeneratekey. Because the required action is missing, selecting "No" correctly reflects that the stated goal is not met.Why the Other Options Are Wrong
Option A ("Yes") would be correct only if Reader and Data Access covered both list and regenerate permissions, but it covers only read access and key listing. Treating any role that mentions "Data Access" as sufficient is a common RBAC mistake; Azure roles are additive and action-specific. There is no other role in the scenario that adds regeneratekey, so the solution cannot satisfy the requirement. Therefore A is incorrect and B is the only defensible choice.Community Comment Notes
As paula_ noted, the proper fix is to assign the "Storage Account Key Operator Service Role" for listing and regenerating keys. Megabyte10 similarly explained that "Reader roles don't have enough permissions to regenerate keys". arunyadav09 suggested Storage Account Encryption Scope Contributor, but that role manages encryption scopes rather than storage account key rotation, so it would not meet the goal either. The consensus in the comments aligns with the official RBAC action mapping and confirms that the original solution fails.Official Reference
Exam Strategy
Memorize the built-in storage roles: Storage Account Key Operator Service Role manages keys, while Reader and Data Access only reads data and lists keys. For AZ-104, map each required action to the exact RBAC action before deciding Yes or No.
Frequently Asked Questions
Why can't Reader and Data Access regenerate storage account keys?
It grants read access and lists keys but lacks Microsoft.Storage/storageAccounts/regeneratekey/action, so key rotation is not permitted.
Which role should I assign to list and regenerate storage account keys?
Assign the Storage Account Key Operator Service Role, which includes both listkeys and regeneratekey actions.
Related Analysis
Practice All AZ-104 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-104 Practice Test →