last sync: 2020-Dec-02 15:37:50 UTC

Azure RBAC Role definition

Backup Operator

NameBackup Operator
Microsoft docs
Id00c29273-979b-4161-815c-10b084fb9324
DescriptionLets you manage backup services, except removal of backup, vault creation and giving access to others
CreatedOn2017-01-03 13:21:11 UTC
UpdatedOn2019-12-17 11:02:43 UTC
Historynone
Actions
Operation Description Used in other Roles
Microsoft.Authorization/*/readno description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Contributor, Backup Reader, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Collaborative Data Contributor, Cosmos DB Account Reader Role, Cosmos DB Operator, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Backup Contributor Role, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Network/virtualNetworks/readGet the virtual network definition Avere Contributor, Avere Operator, Backup Contributor , Private DNS Zone Contributor, Site Recovery Contributor, Site Recovery Operator, Virtual Machine Administrator Login, Virtual Machine Contributor, Virtual Machine User Login
Microsoft.RecoveryServices/locations/backupPreValidateProtection/actionno description given Backup Contributor
Microsoft.RecoveryServices/locations/backupStatus/actionCheck Backup Status for Recovery Services Vaults Backup Contributor, Backup Reader
Microsoft.RecoveryServices/locations/backupValidateFeatures/actionValidate Features Backup Contributor, Backup Reader
Microsoft.RecoveryServices/locations/operationStatus/readGets Operation Status for a given Operation Backup Contributor, Backup Reader
Microsoft.RecoveryServices/operations/readOperation returns the list of Operations for a Resource Provider Backup Contributor, Backup Reader
Microsoft.RecoveryServices/Vaults/backupEngines/readReturns all the backup management servers registered with vault. Backup Contributor, Backup Reader
Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/readGet a backup Protection Intent Backup Reader
Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/writeCreate a backup Protection Intent Virtual Machine Contributor
Microsoft.RecoveryServices/Vaults/backupFabrics/operationResults/readReturns status of the operation Backup Reader
Microsoft.RecoveryServices/Vaults/backupFabrics/protectableContainers/readGet all protectable containers Backup Contributor
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/inquire/actionDo inquiry for workloads within a container none
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/items/readGet all items in a container Backup Reader
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/operationResults/readGets result of Operation performed on Protection Container. Backup Reader
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/backup/actionPerforms Backup for Protected Item. none
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationResults/readGets Result of Operation Performed on Protected Items. Backup Reader
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationsStatus/readReturns the status of Operation performed on Protected Items. Backup Reader
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/readReturns object details of the Protected Item Backup Reader, Virtual Machine Contributor
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/provisionInstantItemRecovery/actionProvision Instant Item Recovery for Protected Item none
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/readGet Recovery Points for Protected Items. Backup Reader
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/restore/actionRestore Recovery Points for Protected Items. none
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/revokeInstantItemRecovery/actionRevoke Instant Item Recovery for Protected Item none
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/writeCreate a backup Protected Item Virtual Machine Contributor
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/readReturns all registered containers Backup Reader
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/writeCreates a registered container none
Microsoft.RecoveryServices/Vaults/backupFabrics/refreshContainers/actionRefreshes the container list Backup Contributor
Microsoft.RecoveryServices/Vaults/backupJobs/*no description given Backup Contributor
Microsoft.RecoveryServices/Vaults/backupJobsExport/actionExport Jobs Backup Contributor, Backup Reader
Microsoft.RecoveryServices/Vaults/backupOperationResults/*no description given Backup Contributor
Microsoft.RecoveryServices/Vaults/backupOperations/readReturns Backup Operation Status for Recovery Services Vault. Backup Contributor, Backup Reader
Microsoft.RecoveryServices/Vaults/backupPolicies/operationResults/readGet Results of Policy Operation. Backup Reader
Microsoft.RecoveryServices/Vaults/backupPolicies/operations/readGet Status of Policy Operation. Backup Reader
Microsoft.RecoveryServices/Vaults/backupPolicies/readReturns all Protection Policies Backup Reader, Virtual Machine Contributor
Microsoft.RecoveryServices/Vaults/backupProtectableItems/*no description given Backup Contributor
Microsoft.RecoveryServices/Vaults/backupProtectedItems/readReturns the list of all Protected Items. Backup Reader
Microsoft.RecoveryServices/Vaults/backupProtectionContainers/readReturns all containers belonging to the subscription Backup Reader
Microsoft.RecoveryServices/Vaults/backupProtectionIntents/readList all backup Protection Intents Backup Contributor, Backup Reader
Microsoft.RecoveryServices/Vaults/backupstorageconfig/*no description given Backup Contributor
Microsoft.RecoveryServices/Vaults/backupUsageSummaries/readReturns summaries for Protected Items and Protected Servers for a Recovery Services . Backup Contributor, Backup Reader
Microsoft.RecoveryServices/Vaults/backupValidateOperation/actionValidate Operation on Protected Item Backup Contributor
Microsoft.RecoveryServices/Vaults/certificates/writeThe Update Resource Certificate operation updates the resource/vault credential certificate. Site Recovery Contributor
Microsoft.RecoveryServices/Vaults/extendedInformation/readThe Get Extended Info operation gets an object's Extended Info representing the Azure resource of type ?vault? Backup Reader, Site Recovery Operator, Site Recovery Reader
Microsoft.RecoveryServices/Vaults/extendedInformation/writeThe Get Extended Info operation gets an object's Extended Info representing the Azure resource of type ?vault? none
Microsoft.RecoveryServices/Vaults/monitoringAlerts/readGets the alerts for the Recovery services vault. Backup Contributor, Backup Reader, Site Recovery Reader
Microsoft.RecoveryServices/Vaults/monitoringAlerts/writeResolves the alert. Backup Contributor, Backup Reader
Microsoft.RecoveryServices/Vaults/monitoringConfigurations/*no description given Backup Contributor, Backup Reader
Microsoft.RecoveryServices/Vaults/readThe Get Vault operation gets an object representing the Azure resource of type 'vault' Backup Contributor, Backup Reader, Site Recovery Contributor , Site Recovery Operator, Site Recovery Reader, Virtual Machine Contributor
Microsoft.RecoveryServices/Vaults/registeredIdentities/operationResults/readThe Get Operation Results operation can be used get the operation status and result for the asynchronously submitted operation Backup Reader, Site Recovery Operator, Site Recovery Reader
Microsoft.RecoveryServices/Vaults/registeredIdentities/readThe Get Containers operation can be used get the containers registered for a resource. Backup Reader, Site Recovery Operator, Site Recovery Reader
Microsoft.RecoveryServices/Vaults/registeredIdentities/writeThe Register Service Container operation can be used to register a container with Recovery Service. none
Microsoft.RecoveryServices/Vaults/usages/readRead any Vault Usages Backup Reader, Site Recovery Contributor, Site Recovery Operator , Site Recovery Reader, Virtual Machine Contributor
Microsoft.Resources/deployments/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Kubernetes Service Contributor Role, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Contributor, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Collaborative Data Contributor, Cosmos DB Operator, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Log Analytics Contributor, Logic App Contributor, Managed Application Contributor Role, Managed Applications Reader, Managed Identity Contributor, Managed Identity Operator, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Services Hub Operator, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups. API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Avere Operator, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Contributor, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, Experimentation Administrator, Experimentation Contributor, HDInsight Cluster Operator, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Monitoring Metrics Publisher, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Reservation Purchaser, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Backup Contributor Role, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Storage/storageAccounts/readReturns the list of storage accounts or gets the properties for the specified storage account. Backup Contributor, Logic App Contributor, Reader and Data Access , Site Recovery Contributor, Site Recovery Operator, Storage Account Backup Contributor Role, Virtual Machine Contributor
Microsoft.Support/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Contributor, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Log Analytics Contributor, Log Analytics Reader, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Monitoring Contributor, Monitoring Metrics Publisher, Monitoring Reader, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Resource Policy Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), SignalR AccessKey Reader, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, User Access Administrator, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in Policy none
Json
{
  "Name": "Backup Operator",
  "Id": "00c29273-979b-4161-815c-10b084fb9324",
  "IsCustom": false,
  "Description": "Lets you manage backup services, except removal of backup, vault creation and giving access to others",
  "Actions": [
    "Microsoft.Authorization/*/read",
    "Microsoft.Network/virtualNetworks/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/operationResults/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/operationResults/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/backup/action",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationResults/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationsStatus/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/provisionInstantItemRecovery/action",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/restore/action",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/revokeInstantItemRecovery/action",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/write",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/refreshContainers/action",
    "Microsoft.RecoveryServices/Vaults/backupJobs/*",
    "Microsoft.RecoveryServices/Vaults/backupJobsExport/action",
    "Microsoft.RecoveryServices/Vaults/backupOperationResults/*",
    "Microsoft.RecoveryServices/Vaults/backupPolicies/operationResults/read",
    "Microsoft.RecoveryServices/Vaults/backupPolicies/read",
    "Microsoft.RecoveryServices/Vaults/backupProtectableItems/*",
    "Microsoft.RecoveryServices/Vaults/backupProtectedItems/read",
    "Microsoft.RecoveryServices/Vaults/backupProtectionContainers/read",
    "Microsoft.RecoveryServices/Vaults/backupUsageSummaries/read",
    "Microsoft.RecoveryServices/Vaults/certificates/write",
    "Microsoft.RecoveryServices/Vaults/extendedInformation/read",
    "Microsoft.RecoveryServices/Vaults/extendedInformation/write",
    "Microsoft.RecoveryServices/Vaults/monitoringAlerts/read",
    "Microsoft.RecoveryServices/Vaults/monitoringConfigurations/*",
    "Microsoft.RecoveryServices/Vaults/read",
    "Microsoft.RecoveryServices/Vaults/registeredIdentities/operationResults/read",
    "Microsoft.RecoveryServices/Vaults/registeredIdentities/read",
    "Microsoft.RecoveryServices/Vaults/registeredIdentities/write",
    "Microsoft.RecoveryServices/Vaults/usages/read",
    "Microsoft.Resources/deployments/*",
    "Microsoft.Resources/subscriptions/resourceGroups/read",
    "Microsoft.Storage/storageAccounts/read",
    "Microsoft.RecoveryServices/Vaults/backupstorageconfig/*",
    "Microsoft.RecoveryServices/Vaults/backupValidateOperation/action",
    "Microsoft.RecoveryServices/Vaults/backupOperations/read",
    "Microsoft.RecoveryServices/Vaults/backupPolicies/operations/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/write",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/inquire/action",
    "Microsoft.RecoveryServices/Vaults/backupEngines/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/write",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectableContainers/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/items/read",
    "Microsoft.RecoveryServices/locations/backupStatus/action",
    "Microsoft.RecoveryServices/locations/backupPreValidateProtection/action",
    "Microsoft.RecoveryServices/locations/backupValidateFeatures/action",
    "Microsoft.RecoveryServices/Vaults/monitoringAlerts/write",
    "Microsoft.RecoveryServices/operations/read",
    "Microsoft.RecoveryServices/locations/operationStatus/read",
    "Microsoft.RecoveryServices/Vaults/backupProtectionIntents/read",
    "Microsoft.Support/*"
  ],
  "NotActions": [
    
  ],
  "DataActions": [
    
  ],
  "NotDataActions": [
    
  ],
  "AssignableScopes": [
    "/"
  ]
}