Azure Storage built-in role
Backup Contributor
Administers Azure Backup management operations for Recovery Services vaults and Backup vaults, including policies, protected items, backup instances, backup and restore operations, and destructive protection changes. It cannot delegate Azure RBAC access and does not grant workload data-plane access through DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 5e467623-bb1f-42f4-a55d-6e525e11384b
Control-plane actions (89)
Microsoft.Authorization/*/readMicrosoft.Network/virtualNetworks/readMicrosoft.RecoveryServices/locations/*Microsoft.RecoveryServices/Vaults/backupFabrics/operationResults/*Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/*Microsoft.RecoveryServices/Vaults/backupFabrics/refreshContainers/actionMicrosoft.RecoveryServices/Vaults/backupJobs/*Microsoft.RecoveryServices/Vaults/backupJobsExport/actionMicrosoft.RecoveryServices/Vaults/backupOperationResults/*Microsoft.RecoveryServices/Vaults/backupPolicies/*Microsoft.RecoveryServices/Vaults/backupProtectableItems/*Microsoft.RecoveryServices/Vaults/backupProtectedItems/*Microsoft.RecoveryServices/Vaults/backupProtectionContainers/*Microsoft.RecoveryServices/Vaults/backupSecurityPIN/*Microsoft.RecoveryServices/Vaults/backupUsageSummaries/readMicrosoft.RecoveryServices/Vaults/certificates/*Microsoft.RecoveryServices/Vaults/extendedInformation/*Microsoft.RecoveryServices/Vaults/monitoringAlerts/readMicrosoft.RecoveryServices/Vaults/monitoringConfigurations/*Microsoft.RecoveryServices/Vaults/readMicrosoft.RecoveryServices/Vaults/registeredIdentities/*Microsoft.RecoveryServices/Vaults/usages/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Storage/storageAccounts/readMicrosoft.RecoveryServices/Vaults/backupstorageconfig/*Microsoft.RecoveryServices/Vaults/backupconfig/*Microsoft.RecoveryServices/Vaults/backupValidateOperation/actionMicrosoft.RecoveryServices/Vaults/writeMicrosoft.RecoveryServices/Vaults/backupOperations/readMicrosoft.RecoveryServices/Vaults/backupEngines/readMicrosoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/*Microsoft.RecoveryServices/Vaults/backupFabrics/protectableContainers/readMicrosoft.RecoveryServices/vaults/operationStatus/readMicrosoft.RecoveryServices/vaults/operationResults/readMicrosoft.RecoveryServices/locations/backupStatus/actionMicrosoft.RecoveryServices/locations/backupPreValidateProtection/actionMicrosoft.RecoveryServices/locations/backupValidateFeatures/actionMicrosoft.RecoveryServices/Vaults/monitoringAlerts/writeMicrosoft.RecoveryServices/operations/readMicrosoft.RecoveryServices/locations/operationStatus/readMicrosoft.RecoveryServices/Vaults/backupProtectionIntents/readMicrosoft.Support/*Microsoft.DataProtection/locations/getBackupStatus/actionMicrosoft.DataProtection/backupVaults/backupInstances/writeMicrosoft.DataProtection/backupVaults/backupInstances/deleteMicrosoft.DataProtection/backupVaults/backupInstances/readMicrosoft.DataProtection/backupVaults/backupInstances/readMicrosoft.DataProtection/backupVaults/deletedBackupInstances/readMicrosoft.DataProtection/backupVaults/deletedBackupInstances/undelete/actionMicrosoft.DataProtection/backupVaults/backupInstances/backup/actionMicrosoft.DataProtection/backupVaults/backupInstances/validateRestore/actionMicrosoft.DataProtection/backupVaults/backupInstances/restore/actionMicrosoft.DataProtection/subscriptions/resourceGroups/providers/locations/crossRegionRestore/actionMicrosoft.DataProtection/subscriptions/resourceGroups/providers/locations/validateCrossRegionRestore/actionMicrosoft.DataProtection/subscriptions/resourceGroups/providers/locations/fetchCrossRegionRestoreJobs/actionMicrosoft.DataProtection/subscriptions/resourceGroups/providers/locations/fetchCrossRegionRestoreJob/actionMicrosoft.DataProtection/subscriptions/resourceGroups/providers/locations/fetchSecondaryRecoveryPoints/actionMicrosoft.DataProtection/backupVaults/backupPolicies/writeMicrosoft.DataProtection/backupVaults/backupPolicies/deleteMicrosoft.DataProtection/backupVaults/backupPolicies/readMicrosoft.DataProtection/backupVaults/backupPolicies/readMicrosoft.DataProtection/backupVaults/backupInstances/recoveryPoints/readMicrosoft.DataProtection/backupVaults/backupInstances/recoveryPoints/readMicrosoft.DataProtection/backupVaults/backupInstances/findRestorableTimeRanges/actionMicrosoft.DataProtection/backupVaults/backupInstances/operationResults/readMicrosoft.DataProtection/backupVaults/writeMicrosoft.DataProtection/backupVaults/readMicrosoft.DataProtection/backupVaults/operationResults/readMicrosoft.DataProtection/backupVaults/operationStatus/readMicrosoft.DataProtection/locations/checkNameAvailability/actionMicrosoft.DataProtection/locations/checkFeatureSupport/actionMicrosoft.DataProtection/backupVaults/readMicrosoft.DataProtection/backupVaults/readMicrosoft.DataProtection/locations/operationStatus/readMicrosoft.DataProtection/locations/operationResults/readMicrosoft.DataProtection/backupVaults/validateForBackup/actionMicrosoft.DataProtection/operations/readMicrosoft.RecoveryServices/Vaults/backupResourceGuardProxies/deleteMicrosoft.RecoveryServices/Vaults/backupResourceGuardProxies/readMicrosoft.RecoveryServices/Vaults/backupResourceGuardProxies/unlockDelete/actionMicrosoft.RecoveryServices/Vaults/backupResourceGuardProxies/writeMicrosoft.DataProtection/backupVaults/backupResourceGuardProxies/readMicrosoft.DataProtection/backupVaults/backupResourceGuardProxies/writeMicrosoft.DataProtection/backupVaults/backupResourceGuardProxies/deleteMicrosoft.DataProtection/backupVaults/backupResourceGuardProxies/unlockDelete/actionMicrosoft.DataProtection/backupVaults/backupInstances/validateForModifyBackup/actionMicrosoft.DataProtection/backupVaults/backupInstances/SuspendBackups/actionMicrosoft.DataProtection/backupVaults/backupInstances/resumeProtection/action
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The role is assignable throughout the Azure hierarchy. Microsoft maps most policy and destructive backup operations to the Recovery Services vault or Backup vault, while creating a vault uses the containing resource group and some cross-region operations use the subscription. Separate roles can be required on protected or restore-target resources.
Common use cases (2)
- Create and manage backup policies, protection configuration, backup instances, recovery points, and restores for supported Azure Backup workloads.
- Stop protection, delete backup data or registrations where supported, and administer vault backup configuration without granting access to others.
Prerequisites (3)
- Identify the vault type, protected workload, source resource, restore target, and the exact scopes in Microsoft's workload-specific role matrix.
- Grant any separately documented VM, database, disk, storage-account, or target-resource roles required by the operation.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at each target scope.
Best practices (3)
- Use Backup Operator for routine backup and restore work that does not require policy management or destructive protection changes.
- Enable multi-user authorization with a separately administered Resource Guard for protected critical operations.
- Assign at the vault or documented workload scope and use eligible, time-bound access for human backup administrators where available.
Security considerations (3)
- The role can stop protection, delete backup instances or policies, undelete soft-deleted instances, restore data, and disable vault immutability where the operation is supported.
- Backup and restore workflows can require additional roles over source and target resources, increasing the effective blast radius beyond the vault.
- It has no DataActions, but control of recovery points and destructive backup settings is highly privileged.
Assignment guidance
Reserve Backup Contributor for backup administrators who need policy or destructive protection management. Scope it to the vault or resource group documented for the workload, grant target-resource permissions separately, and protect critical operations with MUA so a Backup Contributor alone cannot authorize them.
Related roles (3)
- Backup Operator: Microsoft documents Operator for routine backup and restore while Contributor adds policy management and destructive operations.
- Backup Reader: Monitoring-only backup role.
- Backup MUA Operator: Separate Resource Guard role required to authorize operations protected by multi-user authorization.
Editorial sources (7)
- Azure built-in roles for Storage →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-16.
- Eligible and time-bound role assignments in Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Manage backups with Azure role-based access control →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Configure multi-user authorization using Resource Guard →
Supports: Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.