Separate Elastic SAN private-endpoint creation authority from connection approval

The role used to create the volume-group endpoint and the operation used to approve its connection are distinct checks.

A controlled technology lifecycle progressing from assessment to approved production.
DSE visual intelligenceManaged IT operationsGuide · 2 min read
Executive summary

What you need to know

The role used to create the volume-group endpoint and the operation used to approve its connection are distinct checks.

Potentially affected

Elastic SAN private-endpoint provisioning and approval workflows, including cross-subscription deployments.

DSE recommendation

Identify the endpoint creator and connection approver before starting the workflow.

Source facts

Microsoft requires the Elastic SAN Volume Group Owner role to create the volume-group private endpoint. Approving a new connection requires Microsoft.ElasticSan/elasticSans/PrivateEndpointConnectionsApproval/action. Elastic SAN Network Admin includes that operation, and a custom role can also grant it.

If the SAN and private endpoint are in different subscriptions, Microsoft.ElasticSan must be registered in the subscription containing the endpoint. Microsoft Learn.

Applicability

Record the SAN, volume group, endpoint subscription and each participating identity. Review the actual role permissions and scopes instead of treating a successful creation step as evidence that the approval step is authorized.

DSE recommendation

DSE recommends assigning responsibility for creation and approval explicitly in the network change record. Use the documented operation and scope to diagnose a pending or denied approval before requesting a broader administrative role. Coordinate cross-subscription provider registration with its owner. Keep the approval decision tied to the intended endpoint and network, not merely to a recognizable requester name.

Verification

Inspect the endpoint’s target resource and connection state, then have the authorized approver review the precise request. After approval, test the intended connection independently; a permitted approval operation is not itself a connectivity test. Retain creator and approver evidence with resource identifiers and confirm that any temporary grants are handled through the organization’s approved access lifecycle.

Official references

Microsoft Learn: Configure private endpoints for Azure Elastic SAN. Source retrieved September 9, 2026.

Primary reference

Review the official source

Configure private endpoints for Azure Elastic SAN | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE