1
Design identity, governance, and monitoring solutions
hard
You are reviewing a custom RBAC role in Azure. The exhibit shows the role definition. A user with this role reports they cannot read diagnostic settings for a storage account in the Production resource group. What is the most likely cause?
Exhibit
Refer to the exhibit.
```json
{
"roleName": "Custom Storage Auditor",
"Description": "Can read storage account keys and monitor logs",
"Actions": [
"Microsoft.Storage/storageAccounts/listKeys/action",
"Microsoft.Storage/storageAccounts/providers/Microsoft.Insights/diagnosticSettings/read"
],
"NotActions": [],
"AssignableScopes": ["/subscriptions/12345-abcde/resourceGroups/Production"]
}
```