Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
Hi Prithvi Singh ,
Thank you for reaching out on Microsoft Q&A forum.Your observation is partly correct, but it needs clarification.
Azure Storage does not expose “Application permissions” in the App Registration (API permissions blade) like Microsoft Graph or other APIs. This is expected behavior.
The reason is that Azure Storage follows a different authorization model:
Azure Storage APIs do not support configurable application permissions via App Registration because:
- Application permissions require the API to define app roles
- Azure Storage is a Microsoft-managed resource and does not expose such roles for configuration, so they do not appear in the portal
Even though you don’t see “Application permissions”, application (app-only) access is fully supported using Microsoft Entra ID + RBAC:
- Register an application (Service Principal)
- Assign an Azure RBAC role to it (for example):Storage Blob Data Reader, Storage Blob Data Contributor,Use OAuth (client credentials flow) to get a token
Azure Storage will:
- Authenticate the application via Entra ID
- Authorize access based on the assigned RBAC role
Azure uses two separate authorization models:
API Permissions->Used by APIs like Microsoft Graph
RBAC Role Assignments->Used by Azure resources like Storage
For Azure Storage, RBAC is the primary mechanism to control access, including for applications. [learn.microsoft.com].
Kindly let us know if the above helps or you need further assistance on this issue.
If the answer is helpful, kindly upvote it. If you have extra questions about this answer, please click "Comment".