Azure Storage built-in role
Backup MUA Admin
Creates, updates, and deletes Azure Backup Resource Guards and manages their protected-operation configuration and vault proxies. This is the security-administration side of Azure Backup multi-user authorization, separate from ordinary vault backup administration.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: c2a970b4-16a7-4a51-8c84-8a8ea6ee0bb8
Control-plane actions (26)
Microsoft.DataProtection/*/readMicrosoft.DataProtection/*/resourceGuards/writeMicrosoft.DataProtection/subscriptions/resourceGroups/providers/resourceGuards/writeMicrosoft.DataProtection/subscriptions/resourceGroups/providers/resourceGuards/deleteMicrosoft.DataProtection/subscriptions/resourceGroups/providers/resourceGuards/readMicrosoft.DataProtection/locations/operationResults/readMicrosoft.DataProtection/locations/operationStatus/readMicrosoft.DataProtection/locations/getBackupStatus/actionMicrosoft.DataProtection/locations/checkFeatureSupport/actionMicrosoft.DataProtection/subscriptions/resourceGroups/providers/locations/operationStatus/readMicrosoft.Authorization/*/readMicrosoft.Features/features/readMicrosoft.Features/providers/features/readMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/operations/readMicrosoft.Resources/subscriptions/operationresults/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/*Microsoft.DataProtection/backupVaults/backupResourceGuardProxies/readMicrosoft.DataProtection/backupVaults/backupResourceGuardProxies/writeMicrosoft.DataProtection/backupVaults/backupResourceGuardProxies/deleteMicrosoft.DataProtection/backupVaults/backupResourceGuardProxies/unlockDelete/actionMicrosoft.DataProtection/subscriptions/providers/resourceGuards/readMicrosoft.DataProtection/subscriptions/resourceGroups/providers/resourceGuards/{operationName}/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The role is assignable throughout the Azure hierarchy, but MUA guidance places it on the Resource Guard or its isolated containing scope. Microsoft recommends a Resource Guard in another subscription or tenant, in the same region as the protected vault, so the backup administrator cannot control both sides of authorization.
Common use cases (2)
- Create and maintain Resource Guards that protect critical Recovery Services vault or Backup vault operations.
- Define protected operations and manage Resource Guard proxies while keeping approval authority outside the backup operations team.
Prerequisites (3)
- Register the Microsoft.RecoveryServices and Microsoft.DataProtection resource providers as required by the vault scenario.
- Place the Resource Guard in the same region as the vault and preferably in a different subscription or tenant.
- Ensure the backup administrator does not hold Contributor, Backup MUA Admin, or Backup MUA Operator on the Resource Guard scope.
Best practices (3)
- Assign this role to a security administrator who is organizationally separate from the backup administrator.
- Keep the Resource Guard in a different subscription or tenant for stronger isolation and document how operators request protected-operation access.
- Use PIM and approval for Backup MUA Operator activation rather than granting the backup administrator permanent Resource Guard authority.
Security considerations (3)
- An MUA administrator can change or delete the Resource Guard and its protection configuration, weakening the second-person control if compromised.
- Combining this role with backup-vault administration defeats the intended separation of duties.
- The role has no DataActions, but it controls the security boundary around destructive backup operations.
Assignment guidance
Assign Backup MUA Admin to the separate security team at the Resource Guard scope. Do not assign it to vault backup administrators, keep the Resource Guard isolated, and use Backup MUA Operator as eligible just-in-time access for approved protected operations.
Related roles (2)
- Backup MUA Operator: Operator authorizes protected operations on the Resource Guard; Admin creates and maintains the guard itself.
- Backup Contributor: Vault-side backup administrator that Microsoft explicitly keeps separate from Resource Guard administration.
Editorial sources (4)
- Azure built-in roles for Storage →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Eligible and time-bound role assignments in Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Configure multi-user authorization using Resource Guard →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.