Hello Saurin Shah,
Greetings! Welcome to Microsoft Q&A Platform.
Pease note that for Malware Scanning and sensitive data threat detection at subscription and storage account levels, you need Owner roles (subscription owner/storage account owner) or specific roles with corresponding data actions.
The following table summarizes the permissions you need for each scenario. The permissions are either built-in Azure roles or action sets that you can assign to custom roles.
When you enable malware scanning in Defender for Storage, the StorageDataScanner resource is created and automatically assigned the Storage Blob Data Owner role. This role is necessary for the scanner to access and scan your data.
The malware scanning feature in Defender for Storage is designed to automatically scan files as they are uploaded or modified in your storage account. This is done using Microsoft Defender Antivirus capabilities. The scanning process is triggered by events such as file uploads or modifications.
If a malicious file is detected, Defender for Cloud generates security alerts. These alerts can include details about the detected malware and the actions taken, such as quarantining or deleting the malicious file. The automatic role assignment and malware scanning are part of the built-in functionality of Microsoft Defender for Storage. These actions are performed automatically by the system to ensure your storage accounts are protected from malicious content.
refer- https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-storage-malware-scan,
Details on unsupported features and services in Malware Scanning: https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-storage-malware-scan#limitations
Please let us know if you have any further queries. I’m happy to assist you further.
Please "Accept the answer” and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.