Support storage-account-level Azure RBAC authentication in attach (WAT) flow
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 55/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- azure
- Domain
- authentication, cloud
Research direction
Start by locating the existing data-plane attach machinery used for single containers, then trace how the attach flow handles the blob/dfs endpoint and List Containers operation. Done means an account-scoped Blob or ADLS endpoint can attach and browse with an Azure AD token without subscription Reader, while ARM-only account management actions remain unavailable.
Written by the indexing model from the issue text.
Description
Feature request
Support storage-account-level Azure RBAC authentication in the "attach with Azure AD" (WAT / Connect) flow.
Problem
Customers following least-privilege want to grant a user a data-plane role - Storage Blob Data Reader or Storage Blob Data Contributor - scoped directly to a single storage account, without granting Reader at the subscription level (which would let the user discover/enumerate every other storage account in the subscription).
Today:
- Container-level RBAC -> the user can attach and browse that container via Azure AD (data-plane OAuth attach works).
- Storage-account-level Blob Data RBAC -> the user cannot attach the whole storage account via Azure AD. Account discovery is bound to subscription/ARM enumeration, which requires subscription Reader.
As a result, users with account-scoped Blob Data roles are effectively forced to use subscription Reader + sign-in (over-permissioned) or fall back to SAS/account-key authentication - both of which defeat the least-privilege goal.
Requested improvement
Allow a user who holds Storage Blob Data Reader/Contributor scoped to a specific storage account to attach and browse that account's blob/ADLS data plane via Azure AD, by supplying the account's blob/dfs endpoint (e.g. https://<account>.blob.core.windows.net) and an Azure AD token - without requiring subscription-level Reader.
The natural implementation reuses the existing data-plane attach machinery (already used for single containers) and enumerates the account's containers using the data-plane List Containers operation, which is permitted for Storage Blob Data Reader.
Scope / caveats
- This is a data-plane capability (browse containers/blobs/ADLS paths). Account management operations that are ARM-only (viewing keys, account properties/config) would remain unavailable for a data-plane-only attach and should be greyed out or hidden.
- Applies to Blob and ADLS Gen2 endpoints; File/Queue/Table data-plane RBAC could be considered separately.
Why now
Repeatedly requested by customers via CSS. Complements the broader RBAC-experience investigation in #8650, but is a specific, self-contained gap: account-scoped Blob Data RBAC cannot be used to attach an account today.
- Dominant language
- No language data
- Stars
- 455
- Forks
- 92
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from microsoft/AzureStorageExplorer
-
:beetle: regression :copilot: copilot :test_tube: testing
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
microsoft/AzureStorageExplorer#9191 · 1 comment ·
-
Difficulty 2/5 1-2 days Newbie friendliness 76/100
microsoft/AzureStorageExplorer#9186 ·
-
:globe_with_meridians: hard-coded string :globe_with_meridians: localization :test_tube: testing
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
microsoft/AzureStorageExplorer#9152 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 25/100
microsoft/AzureStorageExplorer#9207 ·
-
Sign-in errorOpen
Difficulty 4/5 3-5 days Newbie friendliness 45/100
microsoft/AzureStorageExplorer#9206 · 4 comments · 1 reaction ·
All issues in microsoft/AzureStorageExplorer
Similar issues
-
cosh prompt_scanner_hook.py crashes with AttributeError on a non-object JSON payload (every sibling hook guards this)Possibly taken @zjncs claimed this today. Opencomponent:cosh
Difficulty 1/5 Under an hour Newbie friendliness 92/100
agentic-os-org/ANOLISA#6114 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Gentleman-Programming/gentle-ai#5280 ·
Maintainers usually reply within 1 day
-
The shim's mount reader runs awk in the caller's locale, so its answer can differ from the sh reader'sPossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
FluidNumerics/fluid-walk-blocker#162 ·
Maintainers usually reply within 1 day
-
fix(security): dependency-pinning misses list-item run steps and npm options before installPossibly taken @MohammedAlkindi claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
GET /api/v1/system/api_keys returns the full API token in plaintextPossibly taken @Harsh23Kashyap claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
infiniflow/ragflow#20555 · 1 reaction ·
Maintainers usually reply within 1 day