Azure Management and governance built-in role
Site Recovery Reader
Views Azure Site Recovery protection, replication, infrastructure, recovery plans, jobs, alerts, and health without changing replication or executing failover and failback. It has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: dbaa88c4-0c30-4179-9fb3-46319faa6149
Control-plane actions (32)
Microsoft.Authorization/*/readMicrosoft.RecoveryServices/locations/allocatedStamp/readMicrosoft.RecoveryServices/Vaults/extendedInformation/readMicrosoft.RecoveryServices/Vaults/monitoringAlerts/readMicrosoft.RecoveryServices/Vaults/monitoringConfigurations/notificationConfiguration/readMicrosoft.RecoveryServices/Vaults/readMicrosoft.RecoveryServices/Vaults/refreshContainers/readMicrosoft.RecoveryServices/Vaults/registeredIdentities/operationResults/readMicrosoft.RecoveryServices/Vaults/registeredIdentities/readMicrosoft.RecoveryServices/vaults/replicationAlertSettings/readMicrosoft.RecoveryServices/vaults/replicationEvents/readMicrosoft.RecoveryServices/vaults/replicationFabrics/readMicrosoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/readMicrosoft.RecoveryServices/vaults/replicationFabrics/replicationNetworks/replicationNetworkMappings/readMicrosoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/readMicrosoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectableItems/readMicrosoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/readMicrosoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectedItems/recoveryPoints/readMicrosoft.RecoveryServices/vaults/replicationFabrics/replicationProtectionContainers/replicationProtectionContainerMappings/readMicrosoft.RecoveryServices/vaults/replicationFabrics/replicationRecoveryServicesProviders/readMicrosoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/readMicrosoft.RecoveryServices/vaults/replicationFabrics/replicationStorageClassifications/replicationStorageClassificationMappings/readMicrosoft.RecoveryServices/vaults/replicationFabrics/replicationvCenters/readMicrosoft.RecoveryServices/vaults/replicationJobs/readMicrosoft.RecoveryServices/vaults/replicationPolicies/readMicrosoft.RecoveryServices/vaults/replicationRecoveryPlans/readMicrosoft.RecoveryServices/vaults/replicationVaultSettings/readMicrosoft.RecoveryServices/Vaults/storageConfig/readMicrosoft.RecoveryServices/Vaults/tokenInfo/readMicrosoft.RecoveryServices/Vaults/usages/readMicrosoft.RecoveryServices/Vaults/vaultTokens/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at the Recovery Services vault for focused monitoring. Parent assignments can expose Site Recovery metadata and supporting resource configuration across inherited vaults and workloads.
Common use cases (2)
- Monitor current protection health, replication status, recovery plans, jobs, and alerts.
- Support audit, operations-center, or application-owner visibility without recovery execution authority.
Prerequisites (2)
- Site Recovery protection must already be configured in the vault.
- The principal must need monitoring only and not failover, reprotection, or configuration changes.
Best practices (2)
- Assign at the vault and route alerts to the responsible monitoring team.
- Escalate to Operator only for an approved drill or incident action.
Security considerations (2)
- Protection metadata can reveal source and target topology, recovery plans, workload names, health, and recovery readiness.
- The role cannot execute recovery or change protection and has no DataActions.
Assignment guidance
Assign to monitoring, audit, and application stakeholders at the vault. Use Operator for approved failover and Contributor for replication administration.
Related roles (2)
- Site Recovery Operator: Adds failover, reprotection, and failback execution.
- Site Recovery Contributor: Adds full Site Recovery administration except vault creation and role assignment.
Editorial sources (5)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Manage Site Recovery access with Azure role-based access control →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.