Storage Account Queue Contributor Role Access

Afif 40 Reputation points
2026-04-01T11:14:59.8033333+00:00

Hello,

I have a question and an issue regarding my azure storage account queue roles.

I have setup my account (IAM) with Storage Queue Data Contributor at storage account level as follow:

User's image

However, I could not access my queue after. is there something I missed?

User's image

Thanks,

Afif

Azure Queue Storage
Azure Queue Storage

An Azure service that provides messaging queues in the cloud.

0 comments No comments

Answer accepted by question author
Vallepu Venkateswarlu 10,595 Reputation points Microsoft External Staff Moderator
2026-04-01T17:15:54.5533333+00:00

Hi @ Afif,

Welcome to Microsoft Q&A Platform.

I understand that you are unable to access the storage account even though you have the required role. Please note that RBAC is used for authentication; however, if the storage account is not reachable from your device, you may still encounter access errors.

To resolve this issue, first verify whether the storage account is reachable from your device. If the storage account is configured with a private endpoint and public access is disabled, ensure that your network has proper connectivity to the private endpoint.

Note: Another important consideration when validating this solution is that nslookup is not the appropriate tool to validate private endpoint DNS resolution, Windows 10 includes a feature called the Network Resolution Policy Table, and VPN connections add DNS configuration entries into the NRPT, which affects name resolution behavior.

Please test the DNS result using the command below.

Resolve-DNSName teststorage1rtg.blob.core.windows.net

If the IP is resolving to a public IP instead of the private endpoint IP, the issue is likely related to DNS rather than authentication (RBAC).

There are multiple ways to resolve DNS issues when a storage account is configured with a private endpoint:

Option 1: Add the private endpoint IP and corresponding FQDN entry in the local hosts file. This is a simple and quick workaround.

Option 2: Configure a DNS Private Resolver and set up a conditional forwarder on your local DNS server to forward requests to the Azure DNS resolver.Architecture diagram that shows DNS Private Resolver name resolution traffic when an on-premises server queries an Azure private DNS service record.

Refer: Traffic flow for an on-premises DNS query for more details

Please210246-screenshot-2021-12-10-121802.pngand “up-vote” wherever the information provided helps you, this can be beneficial to other community members.

Was this answer helpful?


Answer accepted by question author
TP 164K Reputation points Volunteer Moderator
2026-04-01T11:34:57.0066667+00:00

Hi,

Looking at your screenshot it appears you are not permitted to access the account due to Networking restrictions. If you navigate your storage account -- Networking + security -- Networking, does it show Public network access: Enabled from all networks, or does it say Secured by perimeter or Disabled?

If you have restrictions in place you will need to connect via private endpoint or via approved VNet or IP, depending on how you have it configured.

Please click Accept Answer and upvote if the above was helpful.

Thanks.

-TP

Was this answer helpful?


1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-04-01T11:15:19.65+00:00

    The Storage Queue Data Contributor role gives data-plane permissions on the queue, but it does not grant permission to navigate to the storage account and queue in the Azure portal.

    To access the queue in the Azure portal using Microsoft Entra ID, both of the following are required:

    1. A data access role on queues – which is already assigned (Storage Queue Data Contributor).
    2. An Azure Resource Manager role on the storage account (or higher scope) such as Reader.

    Without the Reader (or another management-plane) role, the portal cannot show the storage account and queue resources, and a 403 error is displayed even though data permissions exist.

    Resolution:

    1. In the Azure portal, go to the storage account → Access control (IAM).
    2. Add a role assignment.
    3. Select the Reader role (or another appropriate management role with minimal permissions).
    4. Assign it to the same user at the storage account, resource group, or subscription scope.
    5. Wait for role assignment propagation (can take up to ~30 minutes), then refresh the portal and reopen the queue.

    After the Reader role is added, the portal navigation should succeed, and the existing Storage Queue Data Contributor role will allow reading/writing/deleting queue data.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.