Azure Management and governance built-in role
Site Recovery Contributor
Manages Azure Site Recovery operations in a Recovery Services vault, including replication and recovery configuration, but cannot create or delete the vault or assign access. It has broad control-plane permissions across recovery, compute, network, storage, automation, and supporting resources and no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 6670b86e-a3f7-4917-ac9b-5d6ab1be4567
Control-plane actions (29)
Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Network/virtualNetworks/readMicrosoft.RecoveryServices/locations/allocatedStamp/readMicrosoft.RecoveryServices/locations/allocateStamp/actionMicrosoft.RecoveryServices/Vaults/certificates/writeMicrosoft.RecoveryServices/Vaults/extendedInformation/*Microsoft.RecoveryServices/Vaults/readMicrosoft.RecoveryServices/Vaults/refreshContainers/readMicrosoft.RecoveryServices/Vaults/registeredIdentities/*Microsoft.RecoveryServices/vaults/replicationAlertSettings/*Microsoft.RecoveryServices/vaults/replicationEvents/readMicrosoft.RecoveryServices/vaults/replicationFabrics/*Microsoft.RecoveryServices/vaults/replicationJobs/*Microsoft.RecoveryServices/vaults/replicationPolicies/*Microsoft.RecoveryServices/vaults/replicationRecoveryPlans/*Microsoft.RecoveryServices/vaults/replicationVaultSettings/*Microsoft.RecoveryServices/Vaults/storageConfig/*Microsoft.RecoveryServices/Vaults/tokenInfo/readMicrosoft.RecoveryServices/Vaults/usages/readMicrosoft.RecoveryServices/Vaults/vaultTokens/readMicrosoft.RecoveryServices/Vaults/monitoringAlerts/*Microsoft.RecoveryServices/Vaults/monitoringConfigurations/notificationConfiguration/readMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Storage/storageAccounts/readMicrosoft.RecoveryServices/vaults/replicationOperationStatus/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at the Recovery Services vault for Site Recovery administration. Enabling replication and recovery can also require permissions on source, target compute, network, storage, resource groups, and automation resources; those scopes are separate from the vault role assignment.
Common use cases (2)
- Enable and manage disaster recovery for applications or an approved fleet.
- Configure replication, recovery plans, failover, reprotection, and failback without Azure RBAC delegation.
Prerequisites (2)
- Prepare the Recovery Services vault, source and target regions or sites, networks, storage, capacity, recovery objectives, and workload-specific replication prerequisites.
- Grant the separately documented permissions on source and target resources needed to enable replication and recovery.
Best practices (2)
- Assign at the vault, use Operator for instructed failover and failback duties, and test recovery plans regularly.
- Separate disaster-recovery administration from application ownership and protect destructive or cross-region operations with change control.
Security considerations (2)
- The role can change protection, replication, recovery plans, failover, reprotection, and failback, affecting workload availability and recovered data placement.
- Its broad supporting control-plane permissions and additional target-resource assignments can create a large effective blast radius despite no DataActions.
Assignment guidance
Assign to disaster-recovery administrators at the vault. Grant source and target permissions separately and only as documented, use Operator for runbook-style failover duties, and use Reader for monitoring.
Related roles (2)
- Site Recovery Operator: Runs and manages failover and failback without general replication administration.
- Site Recovery Reader: Read-only protection and recovery status role.
Editorial sources (5)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Manage Site Recovery access with Azure role-based access control →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.