Azure Storage built-in role
Backup Operator
Performs routine Azure Backup protection, on-demand backup, restore, registration, and job operations without the Backup Contributor permissions used for policy management and destructive removal of backup data. It cannot create vaults or delegate Azure RBAC access.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 00c29273-979b-4161-815c-10b084fb9324
Control-plane actions (103)
Microsoft.Authorization/*/readMicrosoft.Network/virtualNetworks/readMicrosoft.RecoveryServices/Vaults/backupFabrics/operationResults/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/operationResults/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/backup/actionMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationResults/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationsStatus/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/provisionInstantItemRecovery/actionMicrosoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/accessToken/actionMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/restore/actionMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/revokeInstantItemRecovery/actionMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/writeMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/readMicrosoft.RecoveryServices/Vaults/backupFabrics/refreshContainers/actionMicrosoft.RecoveryServices/Vaults/backupJobs/*Microsoft.RecoveryServices/Vaults/backupJobsExport/actionMicrosoft.RecoveryServices/Vaults/backupOperationResults/*Microsoft.RecoveryServices/Vaults/backupPolicies/operationResults/readMicrosoft.RecoveryServices/Vaults/backupPolicies/readMicrosoft.RecoveryServices/Vaults/backupProtectableItems/*Microsoft.RecoveryServices/Vaults/backupProtectedItems/readMicrosoft.RecoveryServices/Vaults/backupProtectionContainers/readMicrosoft.RecoveryServices/Vaults/backupUsageSummaries/readMicrosoft.RecoveryServices/Vaults/certificates/writeMicrosoft.RecoveryServices/Vaults/extendedInformation/readMicrosoft.RecoveryServices/Vaults/extendedInformation/writeMicrosoft.RecoveryServices/Vaults/monitoringAlerts/readMicrosoft.RecoveryServices/Vaults/monitoringConfigurations/*Microsoft.RecoveryServices/Vaults/readMicrosoft.RecoveryServices/Vaults/registeredIdentities/operationResults/readMicrosoft.RecoveryServices/Vaults/registeredIdentities/readMicrosoft.RecoveryServices/Vaults/registeredIdentities/writeMicrosoft.RecoveryServices/Vaults/usages/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Storage/storageAccounts/readMicrosoft.RecoveryServices/Vaults/backupstorageconfig/*Microsoft.RecoveryServices/Vaults/backupValidateOperation/actionMicrosoft.RecoveryServices/Vaults/backupTriggerValidateOperation/actionMicrosoft.RecoveryServices/Vaults/backupValidateOperationResults/readMicrosoft.RecoveryServices/Vaults/backupValidateOperationsStatuses/readMicrosoft.RecoveryServices/Vaults/backupOperations/readMicrosoft.RecoveryServices/Vaults/backupPolicies/operations/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/writeMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/inquire/actionMicrosoft.RecoveryServices/Vaults/backupEngines/readMicrosoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/writeMicrosoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectableContainers/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/items/readMicrosoft.RecoveryServices/locations/backupStatus/actionMicrosoft.RecoveryServices/locations/backupPreValidateProtection/actionMicrosoft.RecoveryServices/locations/backupValidateFeatures/actionMicrosoft.RecoveryServices/locations/backupAadProperties/readMicrosoft.RecoveryServices/locations/backupCrrJobs/actionMicrosoft.RecoveryServices/locations/backupCrrJob/actionMicrosoft.RecoveryServices/locations/backupCrossRegionRestore/actionMicrosoft.RecoveryServices/locations/backupCrrOperationResults/readMicrosoft.RecoveryServices/locations/backupCrrOperationsStatus/readMicrosoft.RecoveryServices/Vaults/monitoringAlerts/writeMicrosoft.RecoveryServices/operations/readMicrosoft.RecoveryServices/locations/operationStatus/readMicrosoft.RecoveryServices/Vaults/backupProtectionIntents/readMicrosoft.Support/*Microsoft.DataProtection/backupVaults/backupInstances/readMicrosoft.DataProtection/backupVaults/backupInstances/readMicrosoft.DataProtection/backupVaults/backupInstances/operationResults/readMicrosoft.DataProtection/backupVaults/backupInstances/writeMicrosoft.DataProtection/backupVaults/deletedBackupInstances/readMicrosoft.DataProtection/backupVaults/backupPolicies/readMicrosoft.DataProtection/backupVaults/backupPolicies/readMicrosoft.DataProtection/backupVaults/backupInstances/recoveryPoints/readMicrosoft.DataProtection/backupVaults/backupInstances/recoveryPoints/readMicrosoft.DataProtection/backupVaults/backupInstances/findRestorableTimeRanges/actionMicrosoft.DataProtection/backupVaults/readMicrosoft.DataProtection/backupVaults/operationResults/readMicrosoft.DataProtection/backupVaults/operationStatus/readMicrosoft.DataProtection/backupVaults/readMicrosoft.DataProtection/backupVaults/readMicrosoft.DataProtection/locations/operationStatus/readMicrosoft.DataProtection/locations/operationResults/readMicrosoft.DataProtection/operations/readMicrosoft.DataProtection/backupVaults/validateForBackup/actionMicrosoft.DataProtection/backupVaults/backupInstances/backup/actionMicrosoft.DataProtection/backupVaults/backupInstances/validateRestore/actionMicrosoft.DataProtection/backupVaults/backupInstances/restore/actionMicrosoft.DataProtection/subscriptions/resourceGroups/providers/locations/crossRegionRestore/actionMicrosoft.DataProtection/subscriptions/resourceGroups/providers/locations/validateCrossRegionRestore/actionMicrosoft.DataProtection/subscriptions/resourceGroups/providers/locations/fetchCrossRegionRestoreJobs/actionMicrosoft.DataProtection/subscriptions/resourceGroups/providers/locations/fetchCrossRegionRestoreJob/actionMicrosoft.DataProtection/subscriptions/resourceGroups/providers/locations/fetchSecondaryRecoveryPoints/actionMicrosoft.DataProtection/locations/checkFeatureSupport/actionMicrosoft.RecoveryServices/Vaults/backupResourceGuardProxies/deleteMicrosoft.RecoveryServices/Vaults/backupResourceGuardProxies/readMicrosoft.RecoveryServices/Vaults/backupResourceGuardProxies/unlockDelete/actionMicrosoft.RecoveryServices/Vaults/backupResourceGuardProxies/writeMicrosoft.DataProtection/backupVaults/backupResourceGuardProxies/readMicrosoft.DataProtection/backupVaults/backupResourceGuardProxies/writeMicrosoft.DataProtection/backupVaults/backupResourceGuardProxies/deleteMicrosoft.DataProtection/backupVaults/backupResourceGuardProxies/unlockDelete/actionMicrosoft.DataProtection/backupVaults/backupInstances/validateForModifyBackup/action
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The role is assignable throughout the Azure hierarchy. Microsoft maps ordinary backup and restore operations primarily to the Recovery Services vault or Backup vault, with subscription scope required for some cross-region operations. Separate roles are often required on protected workloads, staging storage, and restore targets.
Common use cases (2)
- Enable supported backup workloads, run on-demand backups, monitor jobs, and restore recovery points.
- Register supported on-premises backup resources and perform operational recovery work without managing backup policies or deleting retained backup data.
Prerequisites (3)
- Use the workload-specific Azure Backup role matrix to identify every vault, source, staging, and restore-target scope.
- Grant separately required roles such as VM, disk, database, storage-account, or target-resource permissions.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at each target scope.
Best practices (3)
- Use Backup Operator for day-to-day backup and restore instead of Backup Contributor when policy and destructive operations are not required.
- Keep source and restore-target permissions separate and time-bound, especially for incident recovery.
- Protect critical operations with MUA and review cross-region or cross-subscription scope before assignment.
Security considerations (3)
- Restore permissions can expose protected data or write recovered resources into a target environment.
- The role can trigger backup and restore and modify protected instances, even though Microsoft excludes destructive backup removal and policy management.
- Additional workload roles can make the effective access much broader than the vault assignment alone.
Assignment guidance
Assign Backup Operator at the vault scope for routine operations, then add only the workload and restore-target roles explicitly required by Microsoft for the task. Use Backup Contributor for approved policy or destructive protection changes and Backup Reader for monitoring only.
Related roles (2)
- Backup Contributor: Adds policy management and destructive backup operations.
- Backup Reader: Monitoring-only alternative without backup or restore changes.
Editorial sources (6)
- Azure built-in roles for Storage →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Manage backups with Azure role-based access control →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Configure multi-user authorization using Resource Guard →
Supports: Best practices. Retrieved 2026-07-16.