Azure Management and governance built-in role

Site Recovery Reader

Views Azure Site Recovery protection, replication, infrastructure, recovery plans, jobs, alerts, and health without changing replication or executing failover and failback. It has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: dbaa88c4-0c30-4179-9fb3-46319faa6149

Control-plane actions (32)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the Recovery Services vault for focused monitoring. Parent assignments can expose Site Recovery metadata and supporting resource configuration across inherited vaults and workloads.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign to monitoring, audit, and application stakeholders at the vault. Use Operator for approved failover and Contributor for replication administration.

Related roles (2)

Common questions

When should I assign the Site Recovery Reader Azure role?

Assign Site Recovery Reader when you need to: Monitor current protection health, replication status, recovery plans, jobs, and alerts.; and Support audit, operations-center, or application-owner visibility without recovery execution authority.. Practical scope: Assign at the Recovery Services vault for focused monitoring. Parent assignments can expose Site Recovery metadata and supporting resource configuration across inherited vaults and workloads.

What permissions does the Site Recovery Reader Azure role grant?

The role definition grants 32 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.RecoveryServices/locations/allocatedStamp/read; Microsoft.RecoveryServices/Vaults/extendedInformation/read; Microsoft.RecoveryServices/Vaults/monitoringAlerts/read; Microsoft.RecoveryServices/Vaults/monitoringConfigurations/notificationConfiguration/read; and Microsoft.RecoveryServices/Vaults/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Site Recovery Reader Azure role?

Key considerations when assigning Site Recovery Reader: Protection metadata can reveal source and target topology, recovery plans, workload names, health, and recovery readiness.; and The role cannot execute recovery or change protection and has no DataActions.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →