Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
The Get Permission operation gets a specified security descriptor in Security Descriptor Definition Language (SDDL) or in binary format. This API has been available as of version 2019-02-02.
Protocol availability
| Enabled file share protocol | Available | 
|---|---|
| SMB |  | 
| NFS |  | 
Request
The Get Permission request may be constructed as follows. We recommend that you use HTTPS.
| Method | Request URI | HTTP version | 
|---|---|---|
| GET | https://myaccount.file.core.windows.net/myshare?restype=share&comp=filepermission | HTTP/1.1 | 
Replace the path components that are shown in the request URI with your own, as follows:
| Path component | Description | 
|---|---|
| myaccount | The name of your storage account. | 
| myshare | The name of your file share. The name must contain only lowercase characters. | 
For information about path naming restrictions, see Name and reference shares, directories, files, and metadata.
URI parameters
The following additional parameters may be specified on the request URI:
| Parameter | Description | 
|---|---|
| timeout | Optional. The timeoutparameter is expressed in seconds. For more information, see Set time-outs for Azure Queue Storage operations. | 
Request headers
The required and optional request headers are described in the following table:
| Request header | Description | 
|---|---|
| Authorization | Required. Specifies the authorization scheme, storage account name, and signature. For more information, see Authorize requests to Azure Storage | 
| Dateorx-ms-date | Required. Specifies the Coordinated Universal Time (UTC) for the request. For more information, see Authorize requests to Azure Storage. | 
| x-ms-version | Optional. Specifies the version of the operation to use for this request. For more information, see Versioning for the Azure Storage services. | 
| x-ms-file-permission-key | Required. The security descriptor of the permission. | 
| x-ms-file-permission-format: { sddl ¦ binary } | Optional. Version 2024-11-04 or later. The format in which the the permission value should be returned. For Security Descriptor Definition Language (SDDL), set this header to sddl. For base64-encoded binary security descriptor format, set this header tobinary. If this header is omitted, the default value ofsddlis used. | 
| x-ms-client-request-id | Optional. Provides a client-generated, opaque value with a 1-kibibyte (KiB) character limit that's recorded in the logs when logging is configured. We highly recommend that you use this header to correlate client-side activities with requests that the server receives. For more information, see Monitor Azure Files. | 
| x-ms-file-request-intent | Required if Authorizationheader specifies an OAuth token. Acceptable value isbackup. This header specifies that theMicrosoft.Storage/storageAccounts/fileServices/readFileBackupSemantics/actionorMicrosoft.Storage/storageAccounts/fileServices/writeFileBackupSemantics/actionshould be granted if they are included in the RBAC policy assigned to the identity that is authorized using theAuthorizationheader. Available for version 2022-11-02 and later. | 
Request body
None.
Response
The response includes an HTTP status code and a set of response headers.
Status code
A successful operation returns status code 200 (OK).
For more information about status codes, see Status and error codes.
Response headers
The response for this operation includes the following headers. The response may also include additional standard HTTP headers. All standard headers conform to the HTTP/1.1 protocol specification.
| Response header | Description | 
|---|---|
| x-ms-request-id | Uniquely identifies the request that was made and can be used to troubleshoot the request. | 
| x-ms-version | The Azure Files version that was used to execute the request. | 
| Dateorx-ms-date | A UTC date/time value that's generated by the service, which indicates the time when the response was initiated. | 
| x-ms-client-request-id | Can be used to troubleshoot requests and their corresponding responses. The value of this header is equal to the value of the x-ms-client-request-idheader if it's present in the request and the value contains no more than 1,024 visible ASCII characters. If thex-ms-client-request-idheader isn't present in the request, it won't be present in the response. | 
Response body
The response body is a JSON document that describes the permission.
Before version 2024-11-04, the permission is always returned in the Security Descriptor Definition Language (SDDL):
{
    "permission": "<SDDL>"
}
In version 2024-11-04 or later, the returned permission is in SDDL format by default or if explicitly requested by setting x-ms-file-permission-format to sddl in the request headers:
{
    "format": "sddl",
    "permission": "<SDDL>"
}
In version 2024-11-04 or later, the returned permission is in base64-encoded binary format if explicitly requested by setting x-ms-file-permission-format to binary in the request headers:
{
    "format": "binary",
    "permission": "<base64>"
}
Sample response
HTTP/1.1 200 OK
Response headers:
x-ms-request-id: <id>
x-ms-date: Mon, 27 Jan 2014 22:15:50 GMT  
x-ms-version: 2014-02-14  
Response body:
{"permission": "O:S-1-5-21-2127521184-1604012920-1887927527-21560751G:S-1-5-21-2127521184-1604012920-1887927527-513D:AI(A;;FA;;;SY)(A;;FA;;;BA)(A;;0x1200a9;;;S-1-5-21-397955417-626881126-188441444-3053964)" }
Authorization
Only the account owner or a caller who has a share-level shared access signature with write and delete authorization may call this operation.