Reader and Data Access Role for Storage Key Regeneration?

Configure access to storage Manage access to Azure resources
Answer Correct answer: B — Reader and Data Access does not allow regenerating storage account keys; use the Storage Account Key Operator Service Role instead.

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure Storage account named storage1. You need to enable a user named User1 to list and regenerate storage account keys for storage1. Solution: You assign the Reader and Data Access role to User1. Does this meet the goal?

  1. Yes
  2. No Correct Answer

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests whether Reader and Data Access grants key-management actions; the trap is assuming any role with 'Data Access' in the name can regenerate storage keys.

Assigning only the Reader and Data Access role to User1 on storage1 does not permit regenerating storage account keys, so the solution fails. This page explains why the Storage Account Key Operator Service Role is the correct built-in role for listing and rotating keys.

Choosing 'Yes' because Reader and Data Access lets a user list storage account keys, but it omits the regeneratekey action required to rotate them.

Community Discussion (3 comments)

paula_ 👍 6 Selected: B
NO To enable User1 to list and regenerate storage account keys, you should assign the Storage Account Key Operator Service Role1.
Megabyte10 👍 1 Selected: B
Reader roles don't have enough permissions to regenerate keys.
arunyadav09 👍 2
I think, You need to assign the “Storage Account Encryption Scope Contributor” role to the user. So given answer is right.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The solution assigns only the Reader and Data Access role to User1, but that role is for reading storage data and listing account keys, not for rotating them. Key regeneration is a control-plane action mapped to Microsoft.Storage/storageAccounts/regeneratekey/action, which the Reader and Data Access role does not include. To both list and regenerate keys, User1 needs the Storage Account Key Operator Service Role, a built-in role that grants listkeys and regeneratekey. Because the required action is missing, selecting "No" correctly reflects that the stated goal is not met.

Why the Other Options Are Wrong

Option A ("Yes") would be correct only if Reader and Data Access covered both list and regenerate permissions, but it covers only read access and key listing. Treating any role that mentions "Data Access" as sufficient is a common RBAC mistake; Azure roles are additive and action-specific. There is no other role in the scenario that adds regeneratekey, so the solution cannot satisfy the requirement. Therefore A is incorrect and B is the only defensible choice.

Community Comment Notes

As paula_ noted, the proper fix is to assign the "Storage Account Key Operator Service Role" for listing and regenerating keys. Megabyte10 similarly explained that "Reader roles don't have enough permissions to regenerate keys". arunyadav09 suggested Storage Account Encryption Scope Contributor, but that role manages encryption scopes rather than storage account key rotation, so it would not meet the goal either. The consensus in the comments aligns with the official RBAC action mapping and confirms that the original solution fails.

Official Reference

Exam Strategy

Memorize the built-in storage roles: Storage Account Key Operator Service Role manages keys, while Reader and Data Access only reads data and lists keys. For AZ-104, map each required action to the exact RBAC action before deciding Yes or No.

Frequently Asked Questions

Why can't Reader and Data Access regenerate storage account keys?

It grants read access and lists keys but lacks Microsoft.Storage/storageAccounts/regeneratekey/action, so key rotation is not permitted.

Which role should I assign to list and regenerate storage account keys?

Assign the Storage Account Key Operator Service Role, which includes both listkeys and regeneratekey actions.

Related Analysis

Practice All AZ-104 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-104 Practice Test →

← Back to AZ-104 Study Guide