Permissions
The Azure CIS v2.0.0 - Section 3 - Storage Accounts policy pack requires 5 permissions:
microsoft.storage/storageaccounts/blobservices/write
microsoft.storage/storageaccounts/delete
microsoft.storage/storageaccounts/listkeys/action
microsoft.storage/storageaccounts/queueservices/write
microsoft.storage/storageaccounts/write