Manages storage accounts at the management plane, yet because listKeys is among its permissions it can reach every piece of data via Shared Key. For data access, that is broader than least privilege.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Storage Account Contributor in context, with comparison tables and the common traps.
Terms in this definition
- General-purpose v1
The older storage account kind (
Storage), which lacks access tiers, Archive and premium file shares and retires on 13 October 2026. Converting to ZRS requires first upgrading to GPv2, a one-way change. - AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- Management plane
Layer of Azure operations that act on a resource itself, such as changing a key vault's properties, firewall or access policies. Azure RBAC authorises it, and it gives no access to the data inside the resource.
- Shared Key
For storage, signing requests with one of two 512-bit account keys; this bypasses RBAC and opens every service fully unless Shared Key is disabled. In VPN Gateway the term means the pre-shared secret entered on the peer device and on an S2S or VNet-to-VNet connection.
- Least privilege
The security practice of giving each task only the permissions it requires, scoped as narrowly as possible.