application type of permission for Azure Storage

Prithvi Singh 60 Reputation points
2026-06-05T07:20:56.62+00:00

there is no application type of permission for Azure Storage. It not about having permissions or admins rights, its just that there is no application permission to be used. is it correct? if not then how to hendle it. Need to CPI to storage account intiguration. please help

Azure Storage
Azure Storage

Globally unique resources that provide access to data management services and serve as the parent namespace for the services.

0 comments No comments

Answer accepted by question author
Thanmayi Godithi 11,905 Reputation points Microsoft External Staff Moderator
2026-06-05T09:28:34.1866667+00:00

Hi Prithvi Singh ,

Thank you for reaching out on Microsoft Q&A forum.Your observation is partly correct, but it needs clarification.

Azure Storage does not expose “Application permissions” in the App Registration (API permissions blade) like Microsoft Graph or other APIs. This is expected behavior.

The reason is that Azure Storage follows a different authorization model:

Azure Storage APIs do not support configurable application permissions via App Registration because:

  • Application permissions require the API to define app roles
  • Azure Storage is a Microsoft-managed resource and does not expose such roles for configuration, so they do not appear in the portal

Even though you don’t see “Application permissions”, application (app-only) access is fully supported using Microsoft Entra ID + RBAC:

  • Register an application (Service Principal)
  • Assign an Azure RBAC role to it (for example):Storage Blob Data Reader, Storage Blob Data Contributor,Use OAuth (client credentials flow) to get a token

Azure Storage will:

  • Authenticate the application via Entra ID
  • Authorize access based on the assigned RBAC role

Azure uses two separate authorization models:

API Permissions->Used by APIs like Microsoft Graph

RBAC Role Assignments->Used by Azure resources like Storage

For Azure Storage, RBAC is the primary mechanism to control access, including for applications. [learn.microsoft.com].

Kindly let us know if the above helps or you need further assistance on this issue.

If the answer is helpful, kindly upvote it. If you have extra questions about this answer, please click "Comment".

Was this answer helpful?

3 people found this answer helpful.

Answer accepted by question author
Vinodh247-1375 44,801 Reputation points Volunteer Moderator
2026-06-05T09:14:08.96+00:00

Hi ,

Thanks for reaching out to Microsoft Q&A.

Short answer: your understanding is partially correct but incomplete.

In Azure Storage, there are no “application permissions” exposed via API scopes like you see in Graph. Azure Storage does not use the typical delegated vs application permission model from Microsoft Entra ID.

Instead, it uses RBAC (role-based access control) for application access.

For your CPI (app-to-storage integration), this is how it works:

  • You register an app in Entra ID (service principal)

Then assign it RBAC roles on the Storage Account, such as:

Storage Blob Data Contributor

  Storage Blob Data Reader
  
  Authentication is done using:
  
     Client secret or certificate (OAuth2 client credentials flow)
     
     Authorization is enforced via Azure RBAC, not API permissions
     

So the key point:

There is no “Application permission” tab entry for Azure Storage APIs

But application-level access absolutely exists via RBAC roles

If you are integrating CPI → Storage:

Use service principal + RBAC role assignment on storage

Use OAuth2 (client credentials) for token acquisition

Ensure you target the correct resource: https://storage.azure.com/

That is the correct and supported pattern.

Please 'Upvote'(Thumbs-up) and 'Accept' as answer if the reply was helpful. This will be benefitting other community members who face the same issue.

Was this answer helpful?

2 people found this answer helpful.

Answer accepted by question author
Rayyan Fawad 1,170 Reputation points
2026-06-05T08:49:20.7566667+00:00

You are entirely correct that Azure Storage does not use legacy Microsoft Graph "Application Permissions" (App Roles) within the App Registration portal, but you can absolutely configure secure non-interactive access for your SAP CPI integration using Azure Role-Based Access Control (RBAC) instead. To handle this, go to your Azure Storage Account, click on Access Control (IAM), choose Add role assignment, and assign a specific storage role like Storage Blob Data Contributor or Storage Blob Data Owner directly to your registered Application's service principal. This grants your background integration the exact data-plane access it needs to read or write blobs without relying on user interaction, allowing you to successfully authenticate from SAP CPI using your standard client ID and client secret credentials.

Was this answer helpful?

2 people found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.