Azure Compute built-in role

Disk Restore Operator

Allows an Azure Backup vault managed identity to read and create managed disks and to begin or end disk access during an Azure Disk Backup restore. It is a restore service role for a target resource group, not a human Backup Operator role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b50d9833-a0cb-478e-945f-707fcc997c13

Control-plane actions (6)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign the role to the Backup vault managed identity on the target resource group where restored disks will be created. The assignment is inherited by disks in that group. Its permissions are control-plane Actions only and include disk access-URI operations; it has no DataActions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Disk Restore Operator to the Backup vault managed identity on the target resource group immediately before validation or restore. Keep Backup Operator on the human or automation initiating the vault workflow, and remove the service assignment after successful restore when it is no longer needed.

Related roles (1)

Editorial sources (7)

Official Microsoft Learn documentation →