Which roles grant blob access and support RBAC conditions?
You have an Azure subscription that contains a storage account named storage1. The storage1 account contains blob data. You need to assign a role to a user named User1 to ensure that the user can access the blob data in storage1. The role assignment must support conditions. Which two roles can you assign to User1? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
Community Votes
100% of anonymous learners picked answer DE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the split between Azure management-plane roles and blob data roles, and the trap is assuming any role that can reach storage data — such as Storage Account Contributor via account keys — can also carry a condition.
Azure RBAC conditions can only be attached to role assignments that contain blob (data-plane) actions, so the role must both grant access to blob data and be condition-capable. Storage Blob Data Contributor and Storage Blob Data Owner satisfy both requirements for User1 on storage1.
Picking Storage Account Contributor, because it can list the storage account keys and therefore reach blob data with Shared Key authorization; however, that is a management-plane role with no blob data actions, so an RBAC condition cannot be added to the assignment.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Azure RBAC conditions can only be added to role assignments whose role definition includes data actions, such asMicrosoft.Storage/storageAccounts/blobServices/containers/blobs/*. Storage Blob Data Contributor (D) provides exactly those blob data actions — read, write and delete containers and blobs — so a condition (for example scoped to a container path or a blob index tag) can be layered onto the assignment. Storage Blob Data Owner (E) grants the same data actions plus ownership/POSIX ACL management for Data Lake Storage Gen2, and it equally supports conditions, so it is a complete solution on its own. Because the question says each correct selection is a complete solution, both data roles qualify independently, which is why the source key and the community consensus land on D and E.Why the Other Options Are Wrong
Owner (A) and Storage Account Contributor (B) are management-plane roles: they manage the storage account resource itself (configuration, keys, networking) and do not contain blob data actions, so no condition can be attached to their assignments. Storage Account Contributor is the seductive trap because it can list account keys that unlock data through Shared Key authorization, but that path bypasses RBAC entirely and cannot be constrained by a role-assignment condition. Storage Account Backup Contributor (C) is scoped to Azure Backup operations (backup/restore actions and read) rather than general container and blob operations, and it likewise has no condition support. None of A, B or C satisfies the "must support conditions" requirement while granting blob data access through RBAC.Community Comment Notes
One voter (6c05b3d) laid out the reasoning compactly, describing D as a role that lets the user read, write and delete blob data and noting "It supports conditions," then adding E for full blob data management. aslsmk2 stated flatly that the suggested answer was "Incorrect. Answer should be DE." chrillelundmark pointed readers at Microsoft Learn's built-in roles reference for storage. arunyadav09 instead argued for BD on the grounds that Storage Account Contributor exposes the account key for Shared Key access — a tempting but flawed argument, since key-based access is outside RBAC and therefore cannot carry a condition.Official Reference
Exam Strategy
When an AZ-104 stem says the role assignment "must support conditions," immediately filter out every management-plane role (Owner, Contributor, Storage Account Contributor, Backup Contributor) and keep only role definitions containing blob, queue or table data actions. Then verify the role actually grants the data operation the scenario demands.
Frequently Asked Questions
Why can't Owner or Storage Account Contributor support a conditioned assignment?
Conditions can only be added to role assignments containing blob, queue or table data actions. Owner and Storage Account Contributor are management-plane roles without blob data actions, so no condition can be attached.
Why is Storage Account Backup Contributor not a valid choice here?
It only covers Azure Backup backup/restore and read operations on the storage account, not general container and blob access, and it does not support RBAC conditions.
Related Analysis
Practice All AZ-104 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-104 Practice Test →