Azure Storage built-in role

Backup Contributor

Administers Azure Backup management operations for Recovery Services vaults and Backup vaults, including policies, protected items, backup instances, backup and restore operations, and destructive protection changes. It cannot delegate Azure RBAC access and does not grant workload data-plane access through DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 5e467623-bb1f-42f4-a55d-6e525e11384b

Control-plane actions (89)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy. Microsoft maps most policy and destructive backup operations to the Recovery Services vault or Backup vault, while creating a vault uses the containing resource group and some cross-region operations use the subscription. Separate roles can be required on protected or restore-target resources.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Reserve Backup Contributor for backup administrators who need policy or destructive protection management. Scope it to the vault or resource group documented for the workload, grant target-resource permissions separately, and protect critical operations with MUA so a Backup Contributor alone cannot authorize them.

Related roles (3)

Common questions

When should I assign the Backup Contributor Azure role?

Assign Backup Contributor when you need to: Create and manage backup policies, protection configuration, backup instances, recovery points, and restores for supported Azure Backup workloads.; and Stop protection, delete backup data or registrations where supported, and administer vault backup configuration without granting access to others.. Practical scope: The role is assignable throughout the Azure hierarchy. Microsoft maps most policy and destructive backup operations to the Recovery Services vault or Backup vault, while creating a vault uses the containing resource group and some cross-region operations use the subscription. Separate roles can be required on protected or restore-target resources.

What permissions does the Backup Contributor Azure role grant?

The role definition grants 89 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Network/virtualNetworks/read; Microsoft.RecoveryServices/locations/*; Microsoft.RecoveryServices/Vaults/backupFabrics/operationResults/*; Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/*; and Microsoft.RecoveryServices/Vaults/backupFabrics/refreshContainers/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Backup Contributor Azure role?

Key considerations when assigning Backup Contributor: The role can stop protection, delete backup instances or policies, undelete soft-deleted instances, restore data, and disable vault immutability where the operation is supported.; Backup and restore workflows can require additional roles over source and target resources, increasing the effective blast radius beyond the vault.; and It has no DataActions, but control of recovery points and destructive backup settings is highly privileged.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →