A built-in role whose sole permission, at account scope or higher, is obtaining a user delegation key (generateUserDelegationKey) for signing a user delegation SAS. It gives no access to blob data.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Storage Blob Delegator in context, with comparison tables and the common traps.
Terms in this definition
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Scope
Where an access or policy assignment takes effect. It can be set on a single resource, a resource group, a subscription or a management group, and settings flow down from higher levels.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - User delegation SAS
The most secure kind of SAS, signed using Microsoft Entra credentials, so it still works when Shared Key is disabled. Valid for up to 7 days, it covers Blob (ADLS Gen2 included), Queue, Table and Azure Files over REST, but not stored access policies.
- BLOB
Short for binary large object: raw binary data, like pictures, audio, video or documents, that only an application can make sense of. Azure keeps these files as blobs in Blob Storage.