# Separate Elastic SAN private-endpoint creation authority from connection approval

> The role used to create the volume-group endpoint and the operation used to approve its connection are distinct checks.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:40+00:00
- Modified: 2026-09-10T02:14:30+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Microsoft 365 & Identity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

The role used to create the volume-group endpoint and the operation used to approve its connection are distinct checks.

## Potentially affected

Elastic SAN private-endpoint provisioning and approval workflows, including cross-subscription deployments.

## DSE recommendation

Identify the endpoint creator and connection approver before starting the workflow.

## Article

## Source facts

Microsoft requires the Elastic SAN Volume Group Owner role to create the volume-group private endpoint. Approving a new connection requires Microsoft.ElasticSan/elasticSans/PrivateEndpointConnectionsApproval/action. Elastic SAN Network Admin includes that operation, and a custom role can also grant it.

If the SAN and private endpoint are in different subscriptions, Microsoft.ElasticSan must be registered in the subscription containing the endpoint. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-configure-private-endpoints).

## Applicability

Record the SAN, volume group, endpoint subscription and each participating identity. Review the actual role permissions and scopes instead of treating a successful creation step as evidence that the approval step is authorized.

## DSE recommendation

DSE recommends assigning responsibility for creation and approval explicitly in the network change record. Use the documented operation and scope to diagnose a pending or denied approval before requesting a broader administrative role. Coordinate cross-subscription provider registration with its owner. Keep the approval decision tied to the intended endpoint and network, not merely to a recognizable requester name.

## Verification

Inspect the endpoint’s target resource and connection state, then have the authorized approver review the precise request. After approval, test the intended connection independently; a permitted approval operation is not itself a connectivity test. Retain creator and approver evidence with resource identifiers and confirm that any temporary grants are handled through the organization’s approved access lifecycle.

## Official references

[Microsoft Learn: Configure private endpoints for Azure Elastic SAN](https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-configure-private-endpoints). Source retrieved September 9, 2026.

## Primary reference

- Name: Configure private endpoints for Azure Elastic SAN | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-configure-private-endpoints
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate Elastic SAN private-endpoint creation authority from connection approval,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-556-separate-elastic-san-private-endpoint-creation-authority-from-connection-approval/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
