last sync: 2021-Sep-16 15:24:53 UTC

Azure RBAC Role definition

Backup Reader

NameBackup Reader
Microsoft docs
Ida795c7a0-d4a2-40c1-ae25-d81f01202912
DescriptionCan view backup services, but can't make changes
CreatedOn2017-01-03 13:18:41 UTC
UpdatedOn2021-06-10 06:11:04 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2021-06-10 15:19:34 change: Actions Actions: 'add Microsoft.DataProtection/locations/getBackupStatus/action; add Microsoft.DataProtection/backupVaults/backupInstances/write; add Microsoft.DataProtection/backupVaults/backupInstances/read; add Microsoft.DataProtection/backupVaults/backupInstances/read; add Microsoft.DataProtection/backupVaults/backupInstances/backup/action; add Microsoft.DataProtection/backupVaults/backupInstances/validateRestore/action; add Microsoft.DataProtection/backupVaults/backupInstances/restore/action; add Microsoft.DataProtection/backupVaults/backupPolicies/read; add Microsoft.DataProtection/backupVaults/backupPolicies/read; add Microsoft.DataProtection/backupVaults/backupInstances/recoveryPoints/read; add Microsoft.DataProtection/backupVaults/backupInstances/recoveryPoints/read; add Microsoft.DataProtection/backupVaults/backupInstances/findRestorableTimeRanges/action; add Microsoft.DataProtection/backupVaults/read; add Microsoft.DataProtection/backupVaults/operationResults/read; add Microsoft.DataProtection/backupVaults/read; add Microsoft.DataProtection/backupVaults/read; add Microsoft.DataProtection/locations/operationStatus/read; add Microsoft.DataProtection/locations/operationResults/read; add Microsoft.DataProtection/backupVaults/validateForBackup/action; add Microsoft.DataProtection/providers/operations/read'
2021-05-25 14:52:54 change: Actions Actions: 'add Microsoft.RecoveryServices/locations/backupCrrJobs/action; add Microsoft.RecoveryServices/locations/backupCrrJob/action; add Microsoft.RecoveryServices/locations/backupCrrOperationResults/read; add Microsoft.RecoveryServices/locations/backupCrrOperationsStatus/read'
Actions
Operation Description Used in other Roles
Microsoft.Authorization/*/readno description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Autonomous Development Platform Data Contributor (Preview), Autonomous Development Platform Data Owner (Preview), Autonomous Development Platform Data Reader (Preview), Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Automation Contributor, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Azure VM Managed identities restore Contributor, Backup Contributor, Backup Operator, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, CodeSigning Certificate Profile Signer, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, Cosmos DB Account Reader Role, Cosmos DB Operator, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Application Group Reader, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Host Pool Reader, Desktop Virtualization Reader, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Workspace Contributor, Desktop Virtualization Workspace Reader, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, Disk Backup Reader, Disk Pool Operator, Disk Restore Operator, Disk Snapshot Contributor, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid Contributor, EventGrid Data Sender, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Kubernetes Extension Contributor, Lab Creator, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Backup Contributor Role, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.DataProtection/backupVaults/backupInstances/backup/actionPerforms Backup on the Backup Instance Backup Contributor
Microsoft.DataProtection/backupVaults/backupInstances/findRestorableTimeRanges/actionFinds Restorable Time Ranges Backup Contributor, Backup Operator
Microsoft.DataProtection/backupVaults/backupInstances/readReturns all Backup Instances Backup Contributor, Backup Operator
Microsoft.DataProtection/backupVaults/backupInstances/readReturns all Backup Instances Backup Contributor, Backup Operator
Microsoft.DataProtection/backupVaults/backupInstances/recoveryPoints/readReturns all Recovery Points Backup Contributor, Backup Operator
Microsoft.DataProtection/backupVaults/backupInstances/recoveryPoints/readReturns all Recovery Points Backup Contributor, Backup Operator
Microsoft.DataProtection/backupVaults/backupInstances/restore/actionTriggers restore on the Backup Instance Backup Contributor
Microsoft.DataProtection/backupVaults/backupInstances/validateRestore/actionValidates for Restore of the Backup Instance Backup Contributor
Microsoft.DataProtection/backupVaults/backupInstances/writeCreates a Backup Instance Backup Contributor
Microsoft.DataProtection/backupVaults/backupPolicies/readReturns all Backup Policies Backup Contributor, Backup Operator
Microsoft.DataProtection/backupVaults/backupPolicies/readReturns all Backup Policies Backup Contributor, Backup Operator
Microsoft.DataProtection/backupVaults/operationResults/readGets Operation Result of a Patch Operation for a Backup Vault Backup Contributor, Backup Operator
Microsoft.DataProtection/backupVaults/readGets list of Backup Vaults in a Subscription Backup Contributor, Backup Operator
Microsoft.DataProtection/backupVaults/readGets list of Backup Vaults in a Subscription Backup Contributor, Backup Operator
Microsoft.DataProtection/backupVaults/readGets list of Backup Vaults in a Subscription Backup Contributor, Backup Operator
Microsoft.DataProtection/backupVaults/validateForBackup/actionValidates for backup of Backup Instance Backup Contributor
Microsoft.DataProtection/locations/getBackupStatus/actionCheck Backup Status for Recovery Services Vaults Backup Contributor
Microsoft.DataProtection/locations/operationResults/readReturns Backup Operation Result for Backup Vault. Backup Contributor, Backup Operator
Microsoft.DataProtection/locations/operationStatus/readReturns Backup Operation Status for Backup Vault. Backup Contributor, Backup Operator
Microsoft.DataProtection/providers/operations/readOperation returns the list of Operations for a Resource Provider Backup Contributor, Backup Operator
Microsoft.RecoveryServices/locations/allocatedStamp/readGetAllocatedStamp is internal operation used by service Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader
Microsoft.RecoveryServices/locations/backupCrrJob/actionGet Cross Region Restore Job Details in the secondary region for Recovery Services Vault. Backup Operator
Microsoft.RecoveryServices/locations/backupCrrJobs/actionList Cross Region Restore Jobs in the secondary region for Recovery Services Vault. Backup Operator
Microsoft.RecoveryServices/locations/backupCrrOperationResults/readReturns CRR Operation Result for Recovery Services Vault. Backup Operator
Microsoft.RecoveryServices/locations/backupCrrOperationsStatus/readReturns CRR Operation Status for Recovery Services Vault. Backup Operator
Microsoft.RecoveryServices/locations/backupStatus/actionCheck Backup Status for Recovery Services Vaults Backup Contributor, Backup Operator
Microsoft.RecoveryServices/locations/backupValidateFeatures/actionValidate Features Backup Contributor, Backup Operator
Microsoft.RecoveryServices/locations/operationStatus/readGets Operation Status for a given Operation Backup Contributor, Backup Operator
Microsoft.RecoveryServices/operations/readOperation returns the list of Operations for a Resource Provider Backup Contributor, Backup Operator
Microsoft.RecoveryServices/Vaults/backupconfig/readReturns Configuration for Recovery Services Vault. none
Microsoft.RecoveryServices/Vaults/backupEngines/readReturns all the backup management servers registered with vault. Backup Contributor, Backup Operator
Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/readGet a backup Protection Intent Backup Operator
Microsoft.RecoveryServices/Vaults/backupFabrics/operationResults/readReturns status of the operation Backup Operator
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/items/readGet all items in a container Backup Operator
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/operationResults/readGets result of Operation performed on Protection Container. Backup Operator
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationResults/readGets Result of Operation Performed on Protected Items. Backup Operator
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationsStatus/readReturns the status of Operation performed on Protected Items. Backup Operator
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/readReturns object details of the Protected Item Backup Operator, Virtual Machine Contributor
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/readGet Recovery Points for Protected Items. Backup Operator
Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/readReturns all registered containers Backup Operator
Microsoft.RecoveryServices/Vaults/backupJobs/operationResults/readReturns the Result of Job Operation. none
Microsoft.RecoveryServices/Vaults/backupJobs/readReturns all Job Objects none
Microsoft.RecoveryServices/Vaults/backupJobsExport/actionExport Jobs Backup Contributor, Backup Operator
Microsoft.RecoveryServices/Vaults/backupOperationResults/readReturns Backup Operation Result for Recovery Services Vault. none
Microsoft.RecoveryServices/Vaults/backupOperations/readReturns Backup Operation Status for Recovery Services Vault. Backup Contributor, Backup Operator
Microsoft.RecoveryServices/Vaults/backupPolicies/operationResults/readGet Results of Policy Operation. Backup Operator
Microsoft.RecoveryServices/Vaults/backupPolicies/operations/readGet Status of Policy Operation. Backup Operator
Microsoft.RecoveryServices/Vaults/backupPolicies/readReturns all Protection Policies Backup Operator, Virtual Machine Contributor
Microsoft.RecoveryServices/Vaults/backupProtectedItems/readReturns the list of all Protected Items. Backup Operator
Microsoft.RecoveryServices/Vaults/backupProtectionContainers/readReturns all containers belonging to the subscription Backup Operator
Microsoft.RecoveryServices/Vaults/backupProtectionIntents/readList all backup Protection Intents Backup Contributor, Backup Operator
Microsoft.RecoveryServices/Vaults/backupstorageconfig/readReturns Storage Configuration for Recovery Services Vault. none
Microsoft.RecoveryServices/Vaults/backupUsageSummaries/readReturns summaries for Protected Items and Protected Servers for a Recovery Services . Backup Contributor, Backup Operator
Microsoft.RecoveryServices/Vaults/extendedInformation/readThe Get Extended Info operation gets an object's Extended Info representing the Azure resource of type ?vault? Backup Operator, Site Recovery Operator, Site Recovery Reader
Microsoft.RecoveryServices/Vaults/monitoringAlerts/readGets the alerts for the Recovery services vault. Backup Contributor, Backup Operator, Site Recovery Reader
Microsoft.RecoveryServices/Vaults/monitoringAlerts/writeResolves the alert. Backup Contributor, Backup Operator
Microsoft.RecoveryServices/Vaults/monitoringConfigurations/*no description given Backup Contributor, Backup Operator
Microsoft.RecoveryServices/Vaults/readThe Get Vault operation gets an object representing the Azure resource of type 'vault' Backup Contributor, Backup Operator, Site Recovery Contributor , Site Recovery Operator, Site Recovery Reader, Virtual Machine Contributor
Microsoft.RecoveryServices/Vaults/registeredIdentities/operationResults/readThe Get Operation Results operation can be used get the operation status and result for the asynchronously submitted operation Backup Operator, Site Recovery Operator, Site Recovery Reader
Microsoft.RecoveryServices/Vaults/registeredIdentities/readThe Get Containers operation can be used get the containers registered for a resource. Backup Operator, Site Recovery Operator, Site Recovery Reader
Microsoft.RecoveryServices/Vaults/usages/readRead any Vault Usages Backup Operator, Site Recovery Contributor, Site Recovery Operator , Site Recovery Reader, Virtual Machine Contributor
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in Policy none
JSON
{
  "Name": "Backup Reader",
  "Id": "a795c7a0-d4a2-40c1-ae25-d81f01202912",
  "IsCustom": false,
  "Description": "Can view backup services, but can't make changes",
  "Actions": [
    "Microsoft.Authorization/*/read",
    "Microsoft.RecoveryServices/locations/allocatedStamp/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/operationResults/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/operationResults/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationResults/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationsStatus/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/read",
    "Microsoft.RecoveryServices/Vaults/backupJobs/operationResults/read",
    "Microsoft.RecoveryServices/Vaults/backupJobs/read",
    "Microsoft.RecoveryServices/Vaults/backupJobsExport/action",
    "Microsoft.RecoveryServices/Vaults/backupOperationResults/read",
    "Microsoft.RecoveryServices/Vaults/backupPolicies/operationResults/read",
    "Microsoft.RecoveryServices/Vaults/backupPolicies/read",
    "Microsoft.RecoveryServices/Vaults/backupProtectedItems/read",
    "Microsoft.RecoveryServices/Vaults/backupProtectionContainers/read",
    "Microsoft.RecoveryServices/Vaults/backupUsageSummaries/read",
    "Microsoft.RecoveryServices/Vaults/extendedInformation/read",
    "Microsoft.RecoveryServices/Vaults/monitoringAlerts/read",
    "Microsoft.RecoveryServices/Vaults/read",
    "Microsoft.RecoveryServices/Vaults/registeredIdentities/operationResults/read",
    "Microsoft.RecoveryServices/Vaults/registeredIdentities/read",
    "Microsoft.RecoveryServices/Vaults/backupstorageconfig/read",
    "Microsoft.RecoveryServices/Vaults/backupconfig/read",
    "Microsoft.RecoveryServices/Vaults/backupOperations/read",
    "Microsoft.RecoveryServices/Vaults/backupPolicies/operations/read",
    "Microsoft.RecoveryServices/Vaults/backupEngines/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/read",
    "Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/items/read",
    "Microsoft.RecoveryServices/locations/backupStatus/action",
    "Microsoft.RecoveryServices/Vaults/monitoringConfigurations/*",
    "Microsoft.RecoveryServices/Vaults/monitoringAlerts/write",
    "Microsoft.RecoveryServices/operations/read",
    "Microsoft.RecoveryServices/locations/operationStatus/read",
    "Microsoft.RecoveryServices/Vaults/backupProtectionIntents/read",
    "Microsoft.RecoveryServices/Vaults/usages/read",
    "Microsoft.RecoveryServices/locations/backupValidateFeatures/action",
    "Microsoft.RecoveryServices/locations/backupCrrJobs/action",
    "Microsoft.RecoveryServices/locations/backupCrrJob/action",
    "Microsoft.RecoveryServices/locations/backupCrrOperationResults/read",
    "Microsoft.RecoveryServices/locations/backupCrrOperationsStatus/read",
    "Microsoft.DataProtection/locations/getBackupStatus/action",
    "Microsoft.DataProtection/backupVaults/backupInstances/write",
    "Microsoft.DataProtection/backupVaults/backupInstances/read",
    "Microsoft.DataProtection/backupVaults/backupInstances/read",
    "Microsoft.DataProtection/backupVaults/backupInstances/backup/action",
    "Microsoft.DataProtection/backupVaults/backupInstances/validateRestore/action",
    "Microsoft.DataProtection/backupVaults/backupInstances/restore/action",
    "Microsoft.DataProtection/backupVaults/backupPolicies/read",
    "Microsoft.DataProtection/backupVaults/backupPolicies/read",
    "Microsoft.DataProtection/backupVaults/backupInstances/recoveryPoints/read",
    "Microsoft.DataProtection/backupVaults/backupInstances/recoveryPoints/read",
    "Microsoft.DataProtection/backupVaults/backupInstances/findRestorableTimeRanges/action",
    "Microsoft.DataProtection/backupVaults/read",
    "Microsoft.DataProtection/backupVaults/operationResults/read",
    "Microsoft.DataProtection/backupVaults/read",
    "Microsoft.DataProtection/backupVaults/read",
    "Microsoft.DataProtection/locations/operationStatus/read",
    "Microsoft.DataProtection/locations/operationResults/read",
    "Microsoft.DataProtection/backupVaults/validateForBackup/action",
    "Microsoft.DataProtection/providers/operations/read"
  ],
  "NotActions": [],
  "DataActions": [],
  "NotDataActions": [],
  "AssignableScopes": [
    "/"
  ]
}