Azure Storage built-in role

Backup MUA Admin

Creates, updates, and deletes Azure Backup Resource Guards and manages their protected-operation configuration and vault proxies. This is the security-administration side of Azure Backup multi-user authorization, separate from ordinary vault backup administration.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: c2a970b4-16a7-4a51-8c84-8a8ea6ee0bb8

Control-plane actions (26)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy, but MUA guidance places it on the Resource Guard or its isolated containing scope. Microsoft recommends a Resource Guard in another subscription or tenant, in the same region as the protected vault, so the backup administrator cannot control both sides of authorization.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Backup MUA Admin to the separate security team at the Resource Guard scope. Do not assign it to vault backup administrators, keep the Resource Guard isolated, and use Backup MUA Operator as eligible just-in-time access for approved protected operations.

Related roles (2)

Editorial sources (4)

Official Microsoft Learn documentation →