Which roles grant blob access and support RBAC conditions?

Answer Correct answer: D, E — Storage Blob Data Contributor and Storage Blob Data Owner are the roles that grant blob data access on storage1 and support RBAC conditions.

You have an Azure subscription that contains a storage account named storage1. The storage1 account contains blob data. You need to assign a role to a user named User1 to ensure that the user can access the blob data in storage1. The role assignment must support conditions. Which two roles can you assign to User1? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

  1. Owner
  2. Storage Account Contributor
  3. Storage Account Backup Contributor
  4. Storage Blob Data Contributor Correct Answer
  5. Storage Blob Data Owner Correct Answer

Community Votes

DE
100%

100% of anonymous learners picked answer DE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the split between Azure management-plane roles and blob data roles, and the trap is assuming any role that can reach storage data — such as Storage Account Contributor via account keys — can also carry a condition.

Azure RBAC conditions can only be attached to role assignments that contain blob (data-plane) actions, so the role must both grant access to blob data and be condition-capable. Storage Blob Data Contributor and Storage Blob Data Owner satisfy both requirements for User1 on storage1.

Picking Storage Account Contributor, because it can list the storage account keys and therefore reach blob data with Shared Key authorization; however, that is a management-plane role with no blob data actions, so an RBAC condition cannot be added to the assignment.

Community Discussion (4 comments)

alsmk2 👍 9 Selected: DE
Incorrect. Answer should be DE.
chrillelundmark 👍 1 Selected: DE
https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#storage
6c05b3d 👍 2 Selected: DE
Correct Answers: D. Storage Blob Data Contributor • Reason: This role allows the user to read, write, and delete blob data. It supports conditions, which means you can use Azure Role-Based Access Control (RBAC) to set conditions on the role assignment if necessary. E. Storage Blob Data Owner • Reason: This role allows the user to manage blob data including reading, writing, and deleting, and also managing the blob container and data. It supports conditions, making it possible to apply RBAC conditions on the role assignment.
arunyadav09 👍 1 Selected: BD
Storage Account Contributor Role permits management of storage accounts. It provides access to the account key, which can be used to access data via Shared Key authorization. Storage Blob Data Contributor Role permits Read, write, and delete Azure Storage containers and blobs.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Azure RBAC conditions can only be added to role assignments whose role definition includes data actions, such as Microsoft.Storage/storageAccounts/blobServices/containers/blobs/*. Storage Blob Data Contributor (D) provides exactly those blob data actions — read, write and delete containers and blobs — so a condition (for example scoped to a container path or a blob index tag) can be layered onto the assignment. Storage Blob Data Owner (E) grants the same data actions plus ownership/POSIX ACL management for Data Lake Storage Gen2, and it equally supports conditions, so it is a complete solution on its own. Because the question says each correct selection is a complete solution, both data roles qualify independently, which is why the source key and the community consensus land on D and E.

Why the Other Options Are Wrong

Owner (A) and Storage Account Contributor (B) are management-plane roles: they manage the storage account resource itself (configuration, keys, networking) and do not contain blob data actions, so no condition can be attached to their assignments. Storage Account Contributor is the seductive trap because it can list account keys that unlock data through Shared Key authorization, but that path bypasses RBAC entirely and cannot be constrained by a role-assignment condition. Storage Account Backup Contributor (C) is scoped to Azure Backup operations (backup/restore actions and read) rather than general container and blob operations, and it likewise has no condition support. None of A, B or C satisfies the "must support conditions" requirement while granting blob data access through RBAC.

Community Comment Notes

One voter (6c05b3d) laid out the reasoning compactly, describing D as a role that lets the user read, write and delete blob data and noting "It supports conditions," then adding E for full blob data management. aslsmk2 stated flatly that the suggested answer was "Incorrect. Answer should be DE." chrillelundmark pointed readers at Microsoft Learn's built-in roles reference for storage. arunyadav09 instead argued for BD on the grounds that Storage Account Contributor exposes the account key for Shared Key access — a tempting but flawed argument, since key-based access is outside RBAC and therefore cannot carry a condition.

Official Reference

Exam Strategy

When an AZ-104 stem says the role assignment "must support conditions," immediately filter out every management-plane role (Owner, Contributor, Storage Account Contributor, Backup Contributor) and keep only role definitions containing blob, queue or table data actions. Then verify the role actually grants the data operation the scenario demands.

Frequently Asked Questions

Why can't Owner or Storage Account Contributor support a conditioned assignment?

Conditions can only be added to role assignments containing blob, queue or table data actions. Owner and Storage Account Contributor are management-plane roles without blob data actions, so no condition can be attached.

Why is Storage Account Backup Contributor not a valid choice here?

It only covers Azure Backup backup/restore and read operations on the storage account, not general container and blob access, and it does not support RBAC conditions.

Related Analysis

Practice All AZ-104 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-104 Practice Test →

← Back to AZ-104 Study Guide