Azure Storage built-in role

Backup Contributor

Administers Azure Backup management operations for Recovery Services vaults and Backup vaults, including policies, protected items, backup instances, backup and restore operations, and destructive protection changes. It cannot delegate Azure RBAC access and does not grant workload data-plane access through DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 5e467623-bb1f-42f4-a55d-6e525e11384b

Control-plane actions (89)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy. Microsoft maps most policy and destructive backup operations to the Recovery Services vault or Backup vault, while creating a vault uses the containing resource group and some cross-region operations use the subscription. Separate roles can be required on protected or restore-target resources.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Reserve Backup Contributor for backup administrators who need policy or destructive protection management. Scope it to the vault or resource group documented for the workload, grant target-resource permissions separately, and protect critical operations with MUA so a Backup Contributor alone cannot authorize them.

Related roles (3)

Editorial sources (7)

Official Microsoft Learn documentation →