Which Functions runtime and storage-extension/extension-bundle versions did you use for the role-removal test?
There is a distinction to capture here: Microsoft's current permissions table lists Storage Blob Data Owner + Storage Queue Data Contributor for the blob trigger, and additional Storage Queue Data Contributor + Storage Account Contributor permissions in host-required storage. This is separate from the base AzureWebJobsStorage requirement:
learn.microsoft.com/en-us/azure/azure-functions/m…
Since your host and trigger share an account, including the exact versions and a fresh host start after removing the role would help readers reproduce your result. The specific denied operation in storage logs would also help explain any difference from the documented permissions.
Which Functions runtime and storage-extension/extension-bundle versions did you use for the role-removal test?
There is a distinction to capture here: Microsoft's current permissions table lists Storage Blob Data Owner + Storage Queue Data Contributor for the blob trigger, and additional Storage Queue Data Contributor + Storage Account Contributor permissions in host-required storage. This is separate from the base AzureWebJobsStorage requirement: learn.microsoft.com/en-us/azure/azure-functions/m…
Since your host and trigger share an account, including the exact versions and a fresh host start after removing the role would help readers reproduce your result. The specific denied operation in storage logs would also help explain any difference from the documented permissions.