An Azure service that provides an enterprise-wide hyper-scale repository for big data analytic workloads and is integrated with Azure Blob Storage.
Hi @Namreddy, Sirisha ,
Thank you for reaching out in Microsoft Q&A forum.
Based on the information provided, we understand that the user has been assigned the Storage Blob Data Owner role but is receiving a "Forbidden" error when attempting to view or manage ACLs on the container.
This behavior can occur due to several reasons, including:
- The role assignment has not yet fully propagated.
- The role is assigned at a scope that does not cover the target container or storage account.
- The storage account has networking restrictions (such as firewalls or private endpoints) that prevent access.
- The user is accessing through an inactive PIM assignment.
- There is a deny assignment or other authorization restriction in place.
- The storage account configuration or authentication method is preventing ACL operations.
To help us further investigate, could you please provide the following details:
- Confirmation that the storage account has Hierarchical Namespace (HNS) enabled.
- The scope at which the Storage Blob Data Owner role is assigned (Storage Account, Resource Group, or Subscription).
- Whether the issue affects only one user or multiple users.
Once we have this information, we can perform a deeper analysis and determine the exact cause of the authorization failure.
For additional information regarding Azure Data Lake Storage access control and RBAC permissions, please refer to the following Microsoft documentation:
- https://learn.microsoft.com/azure/storage/blobs/data-lake-storage-access-control
- https://learn.microsoft.com/azure/storage/blobs/assign-azure-role-data-access
Kindly let us know if the above helps or you need further assistance on this issue.
Please do not forget to
and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.