last sync: 2024-May-24 18:02:49 UTC

Backup Operator

Azure BuiltIn RBAC Role definition

NameBackup Operator
Id00c29273-979b-4161-815c-10b084fb9324
DescriptionLets you manage backup services, except removal of backup, vault creation and giving access to others
CreatedOn2017-01-03 13:21:11 UTC
UpdatedOn2024-05-02 10:11:01 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2024-05-03 17:44:59 change: Actions Actions: 'add Microsoft.DataProtection/backupVaults/backupInstances/operationResults/read; add Microsoft.DataProtection/backupVaults/backupInstances/write; add Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/delete; add Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/read; add Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/unlockDelete/action; add Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/write; add Microsoft.DataProtection/backupVaults/backupResourceGuardProxies/read; add Microsoft.DataProtection/backupVaults/backupResourceGuardProxies/write; add Microsoft.DataProtection/backupVaults/backupResourceGuardProxies/delete; add Microsoft.DataProtection/backupVaults/backupResourceGuardProxies/unlockDelete/action'
2023-07-18 17:56:23 change: Actions Actions: 'add Microsoft.DataProtection/locations/checkFeatureSupport/action'
2023-05-22 17:42:39 change: Actions Actions: 'add Microsoft.DataProtection/subscriptions/resourceGroups/providers/locations/crossRegionRestore/action; add Microsoft.DataProtection/subscriptions/resourceGroups/providers/locations/validateCrossRegionRestore/action; add Microsoft.DataProtection/subscriptions/resourceGroups/providers/locations/fetchCrossRegionRestoreJobs/action; add Microsoft.DataProtection/subscriptions/resourceGroups/providers/locations/fetchCrossRegionRestoreJob/action; add Microsoft.DataProtection/subscriptions/resourceGroups/providers/locations/fetchSecondaryRecoveryPoints/action'
2022-10-14 16:34:33 change: Actions Actions: 'add Microsoft.DataProtection/backupVaults/operationStatus/read'
2022-09-26 16:35:37 change: Actions Actions: 'remove Microsoft.DataProtection/providers/operations/read; add Microsoft.DataProtection/backupVaults/deletedBackupInstances/read; add Microsoft.DataProtection/operations/read; add Microsoft.DataProtection/backupVaults/validateForBackup/action; add Microsoft.DataProtection/backupVaults/backupInstances/backup/action; add Microsoft.DataProtection/backupVaults/backupInstances/validateRestore/action; add Microsoft.DataProtection/backupVaults/backupInstances/restore/action'
2021-12-16 17:24:54 change: Actions Actions: 'add Microsoft.RecoveryServices/Vaults/backupTriggerValidateOperation/action; add Microsoft.RecoveryServices/Vaults/backupValidateOperationResults/read; add Microsoft.RecoveryServices/Vaults/backupValidateOperationsStatuses/read'
2021-06-14 13:58:52 change: Actions Actions: 'add Microsoft.DataProtection/backupVaults/backupInstances/read; add Microsoft.DataProtection/backupVaults/backupInstances/read; add Microsoft.DataProtection/backupVaults/backupPolicies/read; add Microsoft.DataProtection/backupVaults/backupPolicies/read; add Microsoft.DataProtection/backupVaults/backupInstances/recoveryPoints/read; add Microsoft.DataProtection/backupVaults/backupInstances/recoveryPoints/read; add Microsoft.DataProtection/backupVaults/backupInstances/findRestorableTimeRanges/action; add Microsoft.DataProtection/backupVaults/read; add Microsoft.DataProtection/backupVaults/operationResults/read; add Microsoft.DataProtection/backupVaults/read; add Microsoft.DataProtection/backupVaults/read; add Microsoft.DataProtection/locations/operationStatus/read; add Microsoft.DataProtection/locations/operationResults/read; add Microsoft.DataProtection/providers/operations/read'
2021-01-19 16:07:23 change: Actions Actions: 'add Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/accessToken/action; add Microsoft.RecoveryServices/locations/backupAadProperties/read; add Microsoft.RecoveryServices/locations/backupCrrJobs/action; add Microsoft.RecoveryServices/locations/backupCrrJob/action; add Microsoft.RecoveryServices/locations/backupCrossRegionRestore/action; add Microsoft.RecoveryServices/locations/backupCrrOperationResults/read; add Microsoft.RecoveryServices/locations/backupCrrOperationsStatus/read'
Permissions summary Effective control plane and data plane operations: 148 (unique operations)
•action: 38
•delete: 3
•read: 93
•write: 14

Actions: 102
Resolved control plane operations from Actions: 148
Effective control plane operations: 148
•action: 38
•delete: 3
•read: 93
•write: 14

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 15502

DataActions: 0
Resolved data plane operations: 0
Effective data plane operations: 0

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3160
Actions
Operation Description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.DataProtection/backupVaults/backupInstances/backup/actionPerforms Backup on the Backup Instance
Microsoft.DataProtection/backupVaults/backupInstances/findRestorableTimeRanges/actionFinds Restorable Time Ranges
Microsoft.DataProtection/backupVaults/backupInstances/operationResults/readReturns Backup Operation Result for Backup Vault.
Microsoft.DataProtection/backupVaults/backupInstances/readReturns all Backup Instances
Microsoft.DataProtection/backupVaults/backupInstances/readReturns all Backup Instances
Microsoft.DataProtection/backupVaults/backupInstances/recoveryPoints/readReturns all Recovery Points
Microsoft.DataProtection/backupVaults/backupInstances/recoveryPoints/readReturns all Recovery Points
Microsoft.DataProtection/backupVaults/backupInstances/restore/actionTriggers restore on the Backup Instance
Microsoft.DataProtection/backupVaults/backupInstances/validateRestore/actionValidates for Restore of the Backup Instance
Microsoft.DataProtection/backupVaults/backupInstances/writeCreates a Backup Instance
Microsoft.DataProtection/backupVaults/backupPolicies/readReturns all Backup Policies
Microsoft.DataProtection/backupVaults/backupPolicies/readReturns all Backup Policies
Microsoft.DataProtection/backupVaults/backupResourceGuardProxies/deleteThe Delete ResourceGuard proxy operation deletes the specified Azure resource of type 'ResourceGuard proxy'
Microsoft.DataProtection/backupVaults/backupResourceGuardProxies/readGet ResourceGuard proxy operation gets an object representing the Azure resource of type 'ResourceGuard proxy'
Microsoft.DataProtection/backupVaults/backupResourceGuardProxies/unlockDelete/actionUnlock delete ResourceGuard proxy operation unlocks the next delete critical operation
Microsoft.DataProtection/backupVaults/backupResourceGuardProxies/writeCreate ResourceGuard proxy operation creates an Azure resource of type 'ResourceGuard Proxy'
Microsoft.DataProtection/backupVaults/deletedBackupInstances/readList soft-deleted Backup Instances in a Backup Vault.
Microsoft.DataProtection/backupVaults/operationResults/readGets Operation Result of a Patch Operation for a Backup Vault
Microsoft.DataProtection/backupVaults/operationStatus/readReturns Backup Operation Status for Backup Vault.
Microsoft.DataProtection/backupVaults/readGets list of Backup Vaults in a Resource Group
Microsoft.DataProtection/backupVaults/readGets list of Backup Vaults in a Resource Group
Microsoft.DataProtection/backupVaults/readGets list of Backup Vaults in a Resource Group
Microsoft.DataProtection/backupVaults/validateForBackup/actionValidates for backup of Backup Instance
Microsoft.DataProtection/locations/checkFeatureSupport/actionValidates if a feature is supported
Microsoft.DataProtection/locations/operationResults/readReturns Backup Operation Result for Backup Vault.
Microsoft.DataProtection/locations/operationStatus/readReturns Backup Operation Status for Backup Vault.
Microsoft.DataProtection/operations/readOperation returns the list of Operations for a Resource Provider
Microsoft.DataProtection/subscriptions/resourceGroups/providers/locations/crossRegionRestore/actionTriggers cross region restore operation on given backup instance.
Microsoft.DataProtection/subscriptions/resourceGroups/providers/locations/fetchCrossRegionRestoreJob/actionGet cross region restore job details from secondary region.
Microsoft.DataProtection/subscriptions/resourceGroups/providers/locations/fetchCrossRegionRestoreJobs/actionList cross region restore jobs of backup instance from secondary region.
Microsoft.DataProtection/subscriptions/resourceGroups/providers/locations/fetchSecondaryRecoveryPoints/actionReturns recovery points from secondary region for cross region restore enabled Backup Vaults.
Microsoft.DataProtection/subscriptions/resourceGroups/providers/locations/validateCrossRegionRestore/actionPerforms validations for cross region restore operation.
Microsoft.Network/virtualNetworks/readGet the virtual network definition
Microsoft.RecoveryServices/locations/backupAadProperties/readGet AAD Properties for authentication in the third region for Cross Region Restore.
Microsoft.RecoveryServices/locations/backupCrossRegionRestore/actionTrigger Cross region restore.
Microsoft.RecoveryServices/locations/backupCrrJob/actionGet Cross Region Restore Job Details in the secondary region for Recovery Services Vault.
Microsoft.RecoveryServices/locations/backupCrrJobs/actionList Cross Region Restore Jobs in the secondary region for Recovery Services Vault.
Microsoft.RecoveryServices/locations/backupCrrOperationResults/readReturns CRR Operation Result for Recovery Services Vault.
Microsoft.RecoveryServices/locations/backupCrrOperationsStatus/readReturns CRR Operation Status for Recovery Services Vault.
Microsoft.RecoveryServices/locations/backupPreValidateProtection/actionno description given
Microsoft.RecoveryServices/locations/backupStatus/actionCheck Backup Status for Recovery Services Vaults
Microsoft.RecoveryServices/locations/backupValidateFeatures/actionValidate Features
Microsoft.RecoveryServices/locations/operationStatus/readGets Operation Status for a given Operation
Microsoft.RecoveryServices/operations/readOperation returns the list of Operations for a Resource Provider
Microsoft.RecoveryServices/Vaults/backupEngines/readReturns all the backup management servers registered with vault.
Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/readGet a backup Protection Intent
Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/writeCreate a backup Protection Intent
Microsoft.RecoveryServices/Vaults/backupFabrics/operationResults/readReturns status of the operation
Microsoft.RecoveryServices/Vaults/backupFabrics/protectableContainers/readGet all protectable containers
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/inquire/actionDo inquiry for workloads within a container
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/items/readGet all items in a container
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/operationResults/readGets result of Operation performed on Protection Container.
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/backup/actionPerforms Backup for Protected Item.
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationResults/readGets Result of Operation Performed on Protected Items.
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationsStatus/readReturns the status of Operation performed on Protected Items.
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/readReturns object details of the Protected Item
Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/accessToken/actionGet AccessToken for Cross Region Restore.
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/provisionInstantItemRecovery/actionProvision Instant Item Recovery for Protected Item
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/readGet Recovery Points for Protected Items.
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/restore/actionRestore Recovery Points for Protected Items.
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/revokeInstantItemRecovery/actionRevoke Instant Item Recovery for Protected Item
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/writeCreate a backup Protected Item
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/readReturns all registered containers
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/writeCreates a registered container
Microsoft.RecoveryServices/Vaults/backupFabrics/refreshContainers/actionRefreshes the container list
Microsoft.RecoveryServices/Vaults/backupJobs/*wildcarded / no description
Microsoft.RecoveryServices/Vaults/backupJobsExport/actionExport Jobs
Microsoft.RecoveryServices/Vaults/backupOperationResults/*wildcarded / no description
Microsoft.RecoveryServices/Vaults/backupOperations/readReturns Backup Operation Status for Recovery Services Vault.
Microsoft.RecoveryServices/Vaults/backupPolicies/operationResults/readGet Results of Policy Operation.
Microsoft.RecoveryServices/Vaults/backupPolicies/operations/readGet Status of Policy Operation.
Microsoft.RecoveryServices/Vaults/backupPolicies/readReturns all Protection Policies
Microsoft.RecoveryServices/Vaults/backupProtectableItems/*wildcarded / no description
Microsoft.RecoveryServices/Vaults/backupProtectedItems/readReturns the list of all Protected Items.
Microsoft.RecoveryServices/Vaults/backupProtectionContainers/readReturns all containers belonging to the subscription
Microsoft.RecoveryServices/Vaults/backupProtectionIntents/readList all backup Protection Intents
Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/deleteThe Delete ResourceGuard proxy operation deletes the specified Azure resource of type 'ResourceGuard proxy'
Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/readGet the list of ResourceGuard proxies for a resource
Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/unlockDelete/actionUnlock delete ResourceGuard proxy operation unlocks the next delete critical operation
Microsoft.RecoveryServices/Vaults/backupResourceGuardProxies/writeCreate ResourceGuard proxy operation creates an Azure resource of type 'ResourceGuard Proxy'
Microsoft.RecoveryServices/Vaults/backupstorageconfig/*wildcarded / no description
Microsoft.RecoveryServices/Vaults/backupTriggerValidateOperation/actionValidate Operation on Protected Item
Microsoft.RecoveryServices/Vaults/backupUsageSummaries/readReturns summaries for Protected Items and Protected Servers for a Recovery Services .
Microsoft.RecoveryServices/Vaults/backupValidateOperation/actionValidate Operation on Protected Item
Microsoft.RecoveryServices/Vaults/backupValidateOperationResults/readValidate Operation on Protected Item
Microsoft.RecoveryServices/Vaults/backupValidateOperationsStatuses/readValidate Operation on Protected Item
Microsoft.RecoveryServices/Vaults/certificates/writeThe Update Resource Certificate operation updates the resource/vault credential certificate.
Microsoft.RecoveryServices/Vaults/extendedInformation/readThe Get Extended Info operation gets an object's Extended Info representing the Azure resource of type ?vault?
Microsoft.RecoveryServices/Vaults/extendedInformation/writeThe Get Extended Info operation gets an object's Extended Info representing the Azure resource of type ?vault?
Microsoft.RecoveryServices/Vaults/monitoringAlerts/readGets the alerts for the Recovery services vault.
Microsoft.RecoveryServices/Vaults/monitoringAlerts/writeResolves the alert.
Microsoft.RecoveryServices/Vaults/monitoringConfigurations/*wildcarded / no description
Microsoft.RecoveryServices/Vaults/readThe Get Vault operation gets an object representing the Azure resource of type 'vault'
Microsoft.RecoveryServices/Vaults/registeredIdentities/operationResults/readThe Get Operation Results operation can be used get the operation status and result for the asynchronously submitted operation
Microsoft.RecoveryServices/Vaults/registeredIdentities/readThe Get Containers operation can be used get the containers registered for a resource.
Microsoft.RecoveryServices/Vaults/registeredIdentities/writeThe Register Service Container operation can be used to register a container with Recovery Service.
Microsoft.RecoveryServices/Vaults/usages/readRead any Vault Usages
Microsoft.Resources/deployments/*wildcarded / no description
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups.
Microsoft.Storage/storageAccounts/readReturns the list of storage accounts or gets the properties for the specified storage account.
Microsoft.Support/*wildcarded / no description
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in
BuiltIn Policy
none
JSON
api-version=2023-07-01-preview
Condition none