Data action in Azure Files required by callers using OAuth over REST, paired with writeFileBackupSemantics for writing. It is included only in the SMB Admin roles and the Storage File Data Privileged roles.
Also called Microsoft.Storage/storageAccounts/fileServices/readFileBackupSemantics/action.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains readFileBackupSemantics in context, with comparison tables and the common traps.
Terms in this definition
- Azure Files
Azure's managed file shares over SMB or NFS. There is no Archive tier, and a single encryption key applies across the whole storage account.
- OAuth
An authorisation standard allowing software to act for someone. In Azure Pipelines, choosing it for a GitHub service connection ties the connection to your own GitHub account; for integrations with Azure DevOps APIs, Microsoft Entra ID OAuth is the right choice.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- REST
Short for representational state transfer, the style of HTTP API that Azure services expose.
- SMB
Protocol for Windows file shares, used by Azure Files and supporting authentication based on identity.
- General-purpose v1
The older storage account kind (
Storage), which lacks access tiers, Archive and premium file shares and retires on 13 October 2026. Converting to ZRS requires first upgrading to GPv2, a one-way change.
Related terms
- Azure Files OAuth over REST
Capability allowing Microsoft Entra users, groups and managed identities to use OAuth tokens against the FileREST data API. The roles that grant it carry
readFileBackupSemanticsorwriteFileBackupSemantics; the SMB share roles don't apply. - Storage File Data Privileged Reader
Reads any Azure Files data over OAuth and REST, ignoring NTFS ACLs, via readFileBackupSemantics. A managed identity that only needs to read Azure Files through REST should get this role.