{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval/",
        "slug": "dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval/"
        },
        "title": "Separate Elastic SAN private-endpoint creation authority from connection approval",
        "summary": "The role used to create the volume-group endpoint and the operation used to approve its connection are distinct checks.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "managed-it",
            "label": "Managed IT operations",
            "alt": "A controlled technology lifecycle progressing from assessment to approved production.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/managed-it-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/managed-it-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:22:40+00:00",
        "modified_at": "2026-09-10T02:14:30+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 230,
        "potentially_affected": "Elastic SAN private-endpoint provisioning and approval workflows, including cross-subscription deployments.",
        "dse_recommendation": "Identify the endpoint creator and connection approver before starting the workflow.",
        "primary_source": {
            "name": "Configure private endpoints for Azure Elastic SAN | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-configure-private-endpoints",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft requires the Elastic SAN Volume Group Owner role to create the volume-group private endpoint. Approving a new connection requires Microsoft.ElasticSan/elasticSans/PrivateEndpointConnectionsApproval/action. Elastic SAN Network Admin includes that operation, and a custom role can also grant it.</p>\n<p>If the SAN and private endpoint are in different subscriptions, Microsoft.ElasticSan must be registered in the subscription containing the endpoint. <a href=\"https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-configure-private-endpoints\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Record the SAN, volume group, endpoint subscription and each participating identity. Review the actual role permissions and scopes instead of treating a successful creation step as evidence that the approval step is authorized.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends assigning responsibility for creation and approval explicitly in the network change record. Use the documented operation and scope to diagnose a pending or denied approval before requesting a broader administrative role. Coordinate cross-subscription provider registration with its owner. Keep the approval decision tied to the intended endpoint and network, not merely to a recognizable requester name.</p>\n<h2>Verification</h2>\n<p>Inspect the endpoint&#8217;s target resource and connection state, then have the authorized approver review the precise request. After approval, test the intended connection independently; a permitted approval operation is not itself a connectivity test. Retain creator and approver evidence with resource identifiers and confirm that any temporary grants are handled through the organization&#8217;s approved access lifecycle.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-configure-private-endpoints\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure private endpoints for Azure Elastic SAN</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nMicrosoft requires the Elastic SAN Volume Group Owner role to create the volume-group private endpoint. Approving a new connection requires Microsoft.ElasticSan/elasticSans/PrivateEndpointConnectionsApproval/action. Elastic SAN Network Admin includes that operation, and a custom role can also grant it.\nIf the SAN and private endpoint are in different subscriptions, Microsoft.ElasticSan must be registered in the subscription containing the endpoint. Microsoft Learn.\nApplicability\nRecord the SAN, volume group, endpoint subscription and each participating identity. Review the actual role permissions and scopes instead of treating a successful creation step as evidence that the approval step is authorized.\nDSE recommendation\nDSE recommends assigning responsibility for creation and approval explicitly in the network change record. Use the documented operation and scope to diagnose a pending or denied approval before requesting a broader administrative role. Coordinate cross-subscription provider registration with its owner. Keep the approval decision tied to the intended endpoint and network, not merely to a recognizable requester name.\nVerification\nInspect the endpoint’s target resource and connection state, then have the authorized approver review the precise request. After approval, test the intended connection independently; a permitted approval operation is not itself a connectivity test. Retain creator and approver evidence with resource identifiers and confirm that any temporary grants are handled through the organization’s approved access lifecycle.\nOfficial references\nMicrosoft Learn: Configure private endpoints for Azure Elastic SAN. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft requires the Elastic SAN Volume Group Owner role to create the volume-group private endpoint. Approving a new connection requires Microsoft.ElasticSan/elasticSans/PrivateEndpointConnectionsApproval/action. Elastic SAN Network Admin includes that operation, and a custom role can also grant it.\n\nIf the SAN and private endpoint are in different subscriptions, Microsoft.ElasticSan must be registered in the subscription containing the endpoint. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-configure-private-endpoints).\n\n## Applicability\n\nRecord the SAN, volume group, endpoint subscription and each participating identity. Review the actual role permissions and scopes instead of treating a successful creation step as evidence that the approval step is authorized.\n\n## DSE recommendation\n\nDSE recommends assigning responsibility for creation and approval explicitly in the network change record. Use the documented operation and scope to diagnose a pending or denied approval before requesting a broader administrative role. Coordinate cross-subscription provider registration with its owner. Keep the approval decision tied to the intended endpoint and network, not merely to a recognizable requester name.\n\n## Verification\n\nInspect the endpoint’s target resource and connection state, then have the authorized approver review the precise request. After approval, test the intended connection independently; a permitted approval operation is not itself a connectivity test. Retain creator and approver evidence with resource identifiers and confirm that any temporary grants are handled through the organization’s approved access lifecycle.\n\n## Official references\n\n[Microsoft Learn: Configure private endpoints for Azure Elastic SAN](https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-configure-private-endpoints). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate Elastic SAN private-endpoint creation authority from connection approval",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval/",
                "headline": "Separate Elastic SAN private-endpoint creation authority from connection approval",
                "description": "The role used to create the volume-group endpoint and the operation used to approve its connection are distinct checks.",
                "abstract": "The role used to create the volume-group endpoint and the operation used to approve its connection are distinct checks.",
                "articleBody": "Source facts\nMicrosoft requires the Elastic SAN Volume Group Owner role to create the volume-group private endpoint. Approving a new connection requires Microsoft.ElasticSan/elasticSans/PrivateEndpointConnectionsApproval/action. Elastic SAN Network Admin includes that operation, and a custom role can also grant it.\nIf the SAN and private endpoint are in different subscriptions, Microsoft.ElasticSan must be registered in the subscription containing the endpoint. Microsoft Learn.\nApplicability\nRecord the SAN, volume group, endpoint subscription and each participating identity. Review the actual role permissions and scopes instead of treating a successful creation step as evidence that the approval step is authorized.\nDSE recommendation\nDSE recommends assigning responsibility for creation and approval explicitly in the network change record. Use the documented operation and scope to diagnose a pending or denied approval before requesting a broader administrative role. Coordinate cross-subscription provider registration with its owner. Keep the approval decision tied to the intended endpoint and network, not merely to a recognizable requester name.\nVerification\nInspect the endpoint’s target resource and connection state, then have the authorized approver review the precise request. After approval, test the intended connection independently; a permitted approval operation is not itself a connectivity test. Retain creator and approver evidence with resource identifiers and confirm that any temporary grants are handled through the organization’s approved access lifecycle.\nOfficial references\nMicrosoft Learn: Configure private endpoints for Azure Elastic SAN. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:22:40+00:00",
                "dateModified": "2026-09-10T02:14:30+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate Elastic SAN private-endpoint creation authority from connection approval"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Microsoft 365 & Identity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Microsoft 365 & Identity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 230,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure private endpoints for Azure Elastic SAN | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-configure-private-endpoints"
                }
            }
        ]
    }
}