Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
Hi rain purple,
Welcome to Microsoft Q&A Platform.
You’re seeing “cannot open queues file in data storage (Error 5 – Access denied)” because your identity doesn’t have data-plane permissions on the storage account. You need to assign an Azure RBAC data role that grants you access to the specific storage service you’re using. Here’s how:
In the Azure portal, go to your Storage Account.
Open “Access control (IAM)” and click “+ Add” → “Add role assignment.”
From the Role list, pick the built-in data role that matches your scenario:
- Storage Blob Data Reader – read-only access to blob containers.
- Storage Blob Data Contributor – read/write/delete blobs.
- Storage Queue Data Reader – peek and read messages in Azure Queue Storage.
- Storage Queue Data Contributor – add, update, and delete queue messages.
- Storage File Data SMB Share Reader/Contributor – for Azure Files shares.
- Select the scope (subscription, resource group, or storage account) where the resources live.
- Assign the role to your user or service principal, and wait a few minutes for propagation.
If you’re using ADLS Gen2, also verify any ACLs on the container or directory under “Containers” → “Access control lists (ACL)”. Once the correct role is in place, retry your operation and you should no longer see the access-denied error.
Please
and “up-vote” wherever the information provided helps you, **this can be beneficial to other community members.