Azure Storage built-in role

Backup Reader

Views Azure Backup vaults, policies, protected items, backup instances, jobs, recovery points, alerts, usage, and operation status without changing protection or restoring data. The role has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: a795c7a0-d4a2-40c1-ae25-d81f01202912

Control-plane actions (64)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy. Assign it at a Recovery Services vault or Backup vault for focused monitoring; a resource-group, subscription, or management-group assignment is inherited and exposes backup metadata for every child vault.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Backup Reader on the specific Recovery Services vault or Backup vault for monitoring and audit work. Escalate to Backup Operator only for an approved backup or restore action and to Backup Contributor only for policy or destructive protection administration.

Related roles (2)

Common questions

When should I assign the Backup Reader Azure role?

Assign Backup Reader when you need to: Monitor backup health, jobs, alerts, policies, recovery points, and protected items.; and Support audit, compliance, or incident-triage workflows that need backup configuration visibility but no backup or restore changes.. Practical scope: The role is assignable throughout the Azure hierarchy. Assign it at a Recovery Services vault or Backup vault for focused monitoring; a resource-group, subscription, or management-group assignment is inherited and exposes backup metadata for every child vault.

What permissions does the Backup Reader Azure role grant?

The role definition grants 64 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.RecoveryServices/locations/allocatedStamp/read; Microsoft.RecoveryServices/Vaults/backupFabrics/operationResults/read; Microsoft.RecoveryServices/Vaults/backupFabrics/operationsStatus/read; Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/operationResults/read; and Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationResults/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Backup Reader Azure role?

Key considerations when assigning Backup Reader: Backup metadata can reveal protected asset names, policies, schedules, recovery points, alerts, and environment topology.; The role cannot initiate restores or alter protection and has no workload DataActions.; and Broad inherited scope can disclose backup posture across multiple applications or business units.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (4)

Official Microsoft Learn documentation →