last sync: 2020-Nov-30 15:25:08 UTC

Azure RBAC Role definition

Backup Contributor

NameBackup Contributor
Microsoft docs
Id5e467623-bb1f-42f4-a55d-6e525e11384b
DescriptionLets you manage backup service,but can't create vaults and give access to others
CreatedOn2017-01-03 13:12:15 UTC
UpdatedOn2019-12-17 10:44:35 UTC
Historynone
Actions
Operation Description Used in other Roles
Microsoft.Authorization/*/readno description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Operator, Backup Reader, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Collaborative Data Contributor, Cosmos DB Account Reader Role, Cosmos DB Operator, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Backup Contributor Role, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Network/virtualNetworks/readGet the virtual network definition Avere Contributor, Avere Operator, Backup Operator , Private DNS Zone Contributor, Site Recovery Contributor, Site Recovery Operator, Virtual Machine Administrator Login, Virtual Machine Contributor, Virtual Machine User Login
Microsoft.RecoveryServices/locations/*no description given Virtual Machine Contributor
Microsoft.RecoveryServices/locations/backupPreValidateProtection/actionno description given Backup Operator
Microsoft.RecoveryServices/locations/backupStatus/actionCheck Backup Status for Recovery Services Vaults Backup Operator, Backup Reader
Microsoft.RecoveryServices/locations/backupValidateFeatures/actionValidate Features Backup Operator, Backup Reader
Microsoft.RecoveryServices/locations/operationStatus/readGets Operation Status for a given Operation Backup Operator, Backup Reader
Microsoft.RecoveryServices/operations/readOperation returns the list of Operations for a Resource Provider Backup Operator, Backup Reader
Microsoft.RecoveryServices/Vaults/backupconfig/*no description given none
Microsoft.RecoveryServices/Vaults/backupEngines/readReturns all the backup management servers registered with vault. Backup Operator, Backup Reader
Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/*no description given none
Microsoft.RecoveryServices/Vaults/backupFabrics/operationResults/*no description given none
Microsoft.RecoveryServices/Vaults/backupFabrics/protectableContainers/readGet all protectable containers Backup Operator
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/*no description given none
Microsoft.RecoveryServices/Vaults/backupFabrics/refreshContainers/actionRefreshes the container list Backup Operator
Microsoft.RecoveryServices/Vaults/backupJobs/*no description given Backup Operator
Microsoft.RecoveryServices/Vaults/backupJobsExport/actionExport Jobs Backup Operator, Backup Reader
Microsoft.RecoveryServices/Vaults/backupOperationResults/*no description given Backup Operator
Microsoft.RecoveryServices/Vaults/backupOperations/readReturns Backup Operation Status for Recovery Services Vault. Backup Operator, Backup Reader
Microsoft.RecoveryServices/Vaults/backupPolicies/*no description given none
Microsoft.RecoveryServices/Vaults/backupProtectableItems/*no description given Backup Operator
Microsoft.RecoveryServices/Vaults/backupProtectedItems/*no description given none
Microsoft.RecoveryServices/Vaults/backupProtectionContainers/*no description given none
Microsoft.RecoveryServices/Vaults/backupProtectionIntents/readList all backup Protection Intents Backup Operator, Backup Reader
Microsoft.RecoveryServices/Vaults/backupSecurityPIN/*no description given none
Microsoft.RecoveryServices/Vaults/backupstorageconfig/*no description given Backup Operator
Microsoft.RecoveryServices/Vaults/backupUsageSummaries/readReturns summaries for Protected Items and Protected Servers for a Recovery Services . Backup Operator, Backup Reader
Microsoft.RecoveryServices/Vaults/backupValidateOperation/actionValidate Operation on Protected Item Backup Operator
Microsoft.RecoveryServices/Vaults/certificates/*no description given none
Microsoft.RecoveryServices/Vaults/extendedInformation/*no description given Site Recovery Contributor
Microsoft.RecoveryServices/Vaults/monitoringAlerts/readGets the alerts for the Recovery services vault. Backup Operator, Backup Reader, Site Recovery Reader
Microsoft.RecoveryServices/Vaults/monitoringAlerts/writeResolves the alert. Backup Operator, Backup Reader
Microsoft.RecoveryServices/Vaults/monitoringConfigurations/*no description given Backup Operator, Backup Reader
Microsoft.RecoveryServices/Vaults/readThe Get Vault operation gets an object representing the Azure resource of type 'vault' Backup Operator, Backup Reader, Site Recovery Contributor , Site Recovery Operator, Site Recovery Reader, Virtual Machine Contributor
Microsoft.RecoveryServices/Vaults/registeredIdentities/*no description given Site Recovery Contributor
Microsoft.RecoveryServices/Vaults/usages/*no description given none
Microsoft.RecoveryServices/Vaults/writeCreate Vault operation creates an Azure resource of type 'vault' Virtual Machine Contributor
Microsoft.Resources/deployments/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Kubernetes Service Contributor Role, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Operator, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Collaborative Data Contributor, Cosmos DB Operator, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Log Analytics Contributor, Logic App Contributor, Managed Application Contributor Role, Managed Applications Reader, Managed Identity Contributor, Managed Identity Operator, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Services Hub Operator, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups. API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Avere Operator, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Operator, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, Experimentation Administrator, Experimentation Contributor, HDInsight Cluster Operator, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Monitoring Metrics Publisher, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Reservation Purchaser, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Backup Contributor Role, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Storage/storageAccounts/readReturns the list of storage accounts or gets the properties for the specified storage account. Backup Operator, Logic App Contributor, Reader and Data Access , Site Recovery Contributor, Site Recovery Operator, Storage Account Backup Contributor Role, Virtual Machine Contributor
Microsoft.Support/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Operator, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Log Analytics Contributor, Log Analytics Reader, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Monitoring Contributor, Monitoring Metrics Publisher, Monitoring Reader, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Resource Policy Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), SignalR AccessKey Reader, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, User Access Administrator, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in Policy
Policy DisplayName Policy Id Category State
[Preview]: Configure backup on VMs with a given tag to a new recovery services vault with a default policy 83644c87-93dd-49fe-bf9f-6aff8fd0834e Backup Preview
[Preview]: Configure backup on VMs with a given tag to an existing recovery services vault in the same location 345fa903-145c-4fe1-8bcd-93ec2adccde8 Backup Preview
[Preview]: Configure backup on VMs without a given tag to a new recovery services vault with a default policy 98d0b9f8-fd90-49c9-88e2-d3baf3b0dd86 Backup Preview
Configure backup on VMs without a given tag to an existing recovery services vault in the same location 09ce66bc-1220-4153-8104-e3f51c936913 Backup GA
Json
{
  "Name": "Backup Contributor",
  "Id": "5e467623-bb1f-42f4-a55d-6e525e11384b",
  "IsCustom": false,
  "Description": "Lets you manage backup service,but can't create vaults and give access to others",
  "Actions": [
    "Microsoft.Authorization/*/read",
    "Microsoft.Network/virtualNetworks/read",
    "Microsoft.RecoveryServices/locations/*",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/operationResults/*",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/*",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/refreshContainers/action",
    "Microsoft.RecoveryServices/Vaults/backupJobs/*",
    "Microsoft.RecoveryServices/Vaults/backupJobsExport/action",
    "Microsoft.RecoveryServices/Vaults/backupOperationResults/*",
    "Microsoft.RecoveryServices/Vaults/backupPolicies/*",
    "Microsoft.RecoveryServices/Vaults/backupProtectableItems/*",
    "Microsoft.RecoveryServices/Vaults/backupProtectedItems/*",
    "Microsoft.RecoveryServices/Vaults/backupProtectionContainers/*",
    "Microsoft.RecoveryServices/Vaults/backupSecurityPIN/*",
    "Microsoft.RecoveryServices/Vaults/backupUsageSummaries/read",
    "Microsoft.RecoveryServices/Vaults/certificates/*",
    "Microsoft.RecoveryServices/Vaults/extendedInformation/*",
    "Microsoft.RecoveryServices/Vaults/monitoringAlerts/read",
    "Microsoft.RecoveryServices/Vaults/monitoringConfigurations/*",
    "Microsoft.RecoveryServices/Vaults/read",
    "Microsoft.RecoveryServices/Vaults/registeredIdentities/*",
    "Microsoft.RecoveryServices/Vaults/usages/*",
    "Microsoft.Resources/deployments/*",
    "Microsoft.Resources/subscriptions/resourceGroups/read",
    "Microsoft.Storage/storageAccounts/read",
    "Microsoft.RecoveryServices/Vaults/backupstorageconfig/*",
    "Microsoft.RecoveryServices/Vaults/backupconfig/*",
    "Microsoft.RecoveryServices/Vaults/backupValidateOperation/action",
    "Microsoft.RecoveryServices/Vaults/write",
    "Microsoft.RecoveryServices/Vaults/backupOperations/read",
    "Microsoft.RecoveryServices/Vaults/backupEngines/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/*",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectableContainers/read",
    "Microsoft.RecoveryServices/locations/backupStatus/action",
    "Microsoft.RecoveryServices/locations/backupPreValidateProtection/action",
    "Microsoft.RecoveryServices/locations/backupValidateFeatures/action",
    "Microsoft.RecoveryServices/Vaults/monitoringAlerts/write",
    "Microsoft.RecoveryServices/operations/read",
    "Microsoft.RecoveryServices/locations/operationStatus/read",
    "Microsoft.RecoveryServices/Vaults/backupProtectionIntents/read",
    "Microsoft.Support/*"
  ],
  "NotActions": [
    
  ],
  "DataActions": [
    
  ],
  "NotDataActions": [
    
  ],
  "AssignableScopes": [
    "/"
  ]
}