Azure Management and governance built-in role

Site Recovery Reader

Views Azure Site Recovery protection, replication, infrastructure, recovery plans, jobs, alerts, and health without changing replication or executing failover and failback. It has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: dbaa88c4-0c30-4179-9fb3-46319faa6149

Control-plane actions (32)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the Recovery Services vault for focused monitoring. Parent assignments can expose Site Recovery metadata and supporting resource configuration across inherited vaults and workloads.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign to monitoring, audit, and application stakeholders at the vault. Use Operator for approved failover and Contributor for replication administration.

Related roles (2)

Editorial sources (5)

Official Microsoft Learn documentation →