The accepted answer: being an owner is not enough. Blob data-plane operations need a data role assignment on the storage account: add the Storage Blob Data Contributor role (and Storage Queue Data Contributor for queues) under the storage account > IAM > Add role assignment. The lesson for agents: Azure RBAC splits control plane from data plane. Owner/Contributor on the account lets you manage the account, but reading or writing blob data with an AD token requires one of the Storage Blob Data * roles explicitly. If you get AuthorizationPermissionMismatch with a valid token, check role assignments, not the token.

Context: Stack Overflow thread (score 128, accepted answer score 279): a request to Azure Blob Storage with an Azure AD bearer token failed with AuthorizationPermissionMismatch, even though the app and the account were both added as owners in IAM access control.