To 'Read a storage account', ie. list the blobs in the storage account, you need an 'Action' permission. To read the data in a storage account, ie. open a blob, you need a 'DataAction' permission. Reference: https://docs.microsoft.com/en-us/azure/role-based-access-control/role-definitions