Azure Storage built-in role
Backup Reader
Views Azure Backup vaults, policies, protected items, backup instances, jobs, recovery points, alerts, usage, and operation status without changing protection or restoring data. The role has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: a795c7a0-d4a2-40c1-ae25-d81f01202912
Control-plane actions (64)
Microsoft.Authorization/*/readMicrosoft.RecoveryServices/locations/allocatedStamp/readMicrosoft.RecoveryServices/Vaults/backupFabrics/operationResults/readMicrosoft.RecoveryServices/Vaults/backupFabrics/operationsStatus/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/operationResults/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationResults/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/operationsStatus/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/protectedItems/recoveryPoints/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/readMicrosoft.RecoveryServices/Vaults/backupJobs/operationResults/readMicrosoft.RecoveryServices/Vaults/backupJobs/readMicrosoft.RecoveryServices/Vaults/backupJobsExport/actionMicrosoft.RecoveryServices/Vaults/backupOperationResults/readMicrosoft.RecoveryServices/Vaults/backupPolicies/operationResults/readMicrosoft.RecoveryServices/Vaults/backupPolicies/readMicrosoft.RecoveryServices/Vaults/backupProtectedItems/readMicrosoft.RecoveryServices/Vaults/backupProtectionContainers/readMicrosoft.RecoveryServices/Vaults/backupUsageSummaries/readMicrosoft.RecoveryServices/Vaults/extendedInformation/readMicrosoft.RecoveryServices/Vaults/monitoringAlerts/readMicrosoft.RecoveryServices/Vaults/readMicrosoft.RecoveryServices/Vaults/registeredIdentities/operationResults/readMicrosoft.RecoveryServices/Vaults/registeredIdentities/readMicrosoft.RecoveryServices/Vaults/backupstorageconfig/readMicrosoft.RecoveryServices/Vaults/backupconfig/readMicrosoft.RecoveryServices/Vaults/backupOperations/readMicrosoft.RecoveryServices/Vaults/backupPolicies/operations/readMicrosoft.RecoveryServices/Vaults/backupEngines/readMicrosoft.RecoveryServices/Vaults/backupFabrics/backupProtectionIntent/readMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/items/readMicrosoft.RecoveryServices/locations/backupStatus/actionMicrosoft.RecoveryServices/Vaults/monitoringConfigurations/*Microsoft.RecoveryServices/Vaults/monitoringAlerts/writeMicrosoft.RecoveryServices/operations/readMicrosoft.RecoveryServices/locations/operationStatus/readMicrosoft.RecoveryServices/Vaults/backupProtectionIntents/readMicrosoft.RecoveryServices/Vaults/usages/readMicrosoft.RecoveryServices/locations/backupValidateFeatures/actionMicrosoft.RecoveryServices/locations/backupCrrJobs/actionMicrosoft.RecoveryServices/locations/backupCrrJob/actionMicrosoft.RecoveryServices/locations/backupCrrOperationResults/readMicrosoft.RecoveryServices/locations/backupCrrOperationsStatus/readMicrosoft.DataProtection/locations/getBackupStatus/actionMicrosoft.DataProtection/backupVaults/backupInstances/readMicrosoft.DataProtection/backupVaults/deletedBackupInstances/readMicrosoft.DataProtection/backupVaults/backupPolicies/readMicrosoft.DataProtection/backupVaults/backupPolicies/readMicrosoft.DataProtection/backupVaults/backupInstances/recoveryPoints/readMicrosoft.DataProtection/backupVaults/backupInstances/recoveryPoints/readMicrosoft.DataProtection/backupVaults/backupInstances/operationResults/readMicrosoft.DataProtection/backupVaults/backupInstances/findRestorableTimeRanges/actionMicrosoft.DataProtection/backupVaults/readMicrosoft.DataProtection/backupVaults/operationResults/readMicrosoft.DataProtection/backupVaults/operationStatus/readMicrosoft.DataProtection/backupVaults/readMicrosoft.DataProtection/backupVaults/readMicrosoft.DataProtection/locations/operationStatus/readMicrosoft.DataProtection/locations/operationResults/readMicrosoft.DataProtection/operations/readMicrosoft.DataProtection/subscriptions/resourceGroups/providers/locations/fetchCrossRegionRestoreJobs/actionMicrosoft.DataProtection/subscriptions/resourceGroups/providers/locations/fetchCrossRegionRestoreJob/actionMicrosoft.DataProtection/subscriptions/resourceGroups/providers/locations/fetchSecondaryRecoveryPoints/actionMicrosoft.DataProtection/locations/checkFeatureSupport/action
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The role is assignable throughout the Azure hierarchy. Assign it at a Recovery Services vault or Backup vault for focused monitoring; a resource-group, subscription, or management-group assignment is inherited and exposes backup metadata for every child vault.
Common use cases (2)
- Monitor backup health, jobs, alerts, policies, recovery points, and protected items.
- Support audit, compliance, or incident-triage workflows that need backup configuration visibility but no backup or restore changes.
Prerequisites (2)
- Identify the vaults whose backup metadata the principal must inspect.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at that scope.
Best practices (3)
- Use Backup Reader for monitoring teams instead of Backup Operator or Backup Contributor.
- Assign at individual vault scope when cross-vault visibility is unnecessary.
- Grant source-resource or restored-data access separately only when the investigation explicitly requires it.
Security considerations (3)
- Backup metadata can reveal protected asset names, policies, schedules, recovery points, alerts, and environment topology.
- The role cannot initiate restores or alter protection and has no workload DataActions.
- Broad inherited scope can disclose backup posture across multiple applications or business units.
Assignment guidance
Assign Backup Reader on the specific Recovery Services vault or Backup vault for monitoring and audit work. Escalate to Backup Operator only for an approved backup or restore action and to Backup Contributor only for policy or destructive protection administration.
Related roles (2)
- Backup Operator: Adds operational backup and restore capabilities.
- Backup Contributor: Adds policy and destructive backup administration.
Editorial sources (4)
- Azure built-in roles for Storage →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Manage backups with Azure role-based access control →
Supports: Description, Practical scope, Common use cases, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.