Skip to main content

Grant Azure resource permissions

Before you start

Prerequisite stages

Confirm the following stages have been completed:

Parameters

The following values from the parameters workbook are required:

  • {DataLoader-Storage-Account}
  • {Web-App-Name}
  • {Function-App-Name}
  • {Deployment-Accounts}

Permission required

Use an account with the following permissions:

  • Azure Administrator

Add Role Assignments

User with Owner or User Access Administrator role must execute these steps.

The following roles should be assigned to the Data Loader Storage Account {DataLoader-Storage-Account}:

RoleAssignee TypeAssignee
ContributorManaged IdentityFunction App
{Function-App-Name} in parameters workbook.
Storage Queue Data ContributorManaged IdentityFunction App
{Function-App-Name} in parameters workbook.
Storage Queue Data ContributorManaged IdentityWeb App
{Web-App-Name} in parameters workbook.
Storage Blob Data ContributorManaged IdentityFunction App
{Function-App-Name} in parameters workbook.
Storage Blob Data ContributorManaged IdentityWeb App
{Web-App-Name} in parameters workbook.
Storage Blob Data ContributorUserDeployment Account
{Deployment-Accounts} in parameters workbook.
Storage Blob Data ContributorUser or groupAny user or a group in addition to {Deployment-Accounts} who will require access to storage accounts to manage data loader files (optional).

See following link for Microsoft documentation on adding role assignments: https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal?tabs=delegate-condition The following steps should be executed for each role:

  • Navigate to the Data Loader Storage Account resource in Azure
  • Go to Access Control (IAM) -> Role assignments -> Add -> Add role assignment
  • On Role tab select role (Contributor is under Privileged administrator roles section).
  • On Members tab select Managed Identity or User, group, or service principal based on the assignee type.
  • Press Select members.
  • Select required members from the list. Repeat for each member. Press Select
  • Go to Review + Assign and press Review + assign.