If the Application Workspace service runs under the Local System account, no additional permissions are required as these settings and files are always in the user’s own profile locations.
If the service runs under any other account (domain user, local user, Group Managed Service Account (gMSA), virtual account, LocalService/NetworkService, etc.), make sure both the Application Workspace service and the signed-in user have permission to modify the registry keys, files/folders, and the storage location you specify.
The App Settings Restore function runs in the context of the Agent service. Also, the user session does not write directly to (blob) storage: the Agent uploads the captured data to the server, and the server then copies it to blob storage (if applicable).