We have a storage account that contains sensitive info. We need to remove certain groups that have inherited access. (the dev group for example) If I select the group and try to "Remove" the group from the storage account it tells me "Inherited role assignments cannot be removed" When I go to Deny assignments page it says that I need to use Azure Blueprints to add a rule. I'm struggling with building the right blueprint to remove access.
Can you give me an example blueprint that would accomplish this or if there is a better method for making this happen. I'm open to anyway to deny select inherited groups. Thanks.


and
wherever the information provided helps you, this can be beneficial to other community members.