What you need to know
The role used to create the volume-group endpoint and the operation used to approve its connection are distinct checks.
Potentially affected
Elastic SAN private-endpoint provisioning and approval workflows, including cross-subscription deployments.
DSE recommendation
Identify the endpoint creator and connection approver before starting the workflow.
Source facts
Microsoft requires the Elastic SAN Volume Group Owner role to create the volume-group private endpoint. Approving a new connection requires Microsoft.ElasticSan/elasticSans/PrivateEndpointConnectionsApproval/action. Elastic SAN Network Admin includes that operation, and a custom role can also grant it.
If the SAN and private endpoint are in different subscriptions, Microsoft.ElasticSan must be registered in the subscription containing the endpoint. Microsoft Learn.
Applicability
Record the SAN, volume group, endpoint subscription and each participating identity. Review the actual role permissions and scopes instead of treating a successful creation step as evidence that the approval step is authorized.
DSE recommendation
DSE recommends assigning responsibility for creation and approval explicitly in the network change record. Use the documented operation and scope to diagnose a pending or denied approval before requesting a broader administrative role. Coordinate cross-subscription provider registration with its owner. Keep the approval decision tied to the intended endpoint and network, not merely to a recognizable requester name.
Verification
Inspect the endpoint’s target resource and connection state, then have the authorized approver review the precise request. After approval, test the intended connection independently; a permitted approval operation is not itself a connectivity test. Retain creator and approver evidence with resource identifiers and confirm that any temporary grants are handled through the organization’s approved access lifecycle.
Official references
Microsoft Learn: Configure private endpoints for Azure Elastic SAN. Source retrieved September 9, 2026.
Review the official source
Configure private endpoints for Azure Elastic SAN | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE