Azure Storage built-in role
Storage Account Backup Contributor
Provides the storage-account control-plane permissions Azure Backup needs for blob and file-share backup and restore workflows. It can manage backup-owned locks, object replication policies, blob service and container configuration, and point-in-time restore operations, but has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: e5e2a7ff-d759-4cd2-bb51-3152d37e2eb1
Control-plane actions (18)
Microsoft.Authorization/*/readMicrosoft.Authorization/locks/readMicrosoft.Authorization/locks/writeMicrosoft.Authorization/locks/deleteMicrosoft.Features/features/readMicrosoft.Features/providers/features/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Storage/operations/readMicrosoft.Storage/storageAccounts/objectReplicationPolicies/deleteMicrosoft.Storage/storageAccounts/objectReplicationPolicies/readMicrosoft.Storage/storageAccounts/objectReplicationPolicies/writeMicrosoft.Storage/storageAccounts/objectReplicationPolicies/restorePointMarkers/writeMicrosoft.Storage/storageAccounts/blobServices/containers/readMicrosoft.Storage/storageAccounts/blobServices/containers/writeMicrosoft.Storage/storageAccounts/blobServices/readMicrosoft.Storage/storageAccounts/blobServices/writeMicrosoft.Storage/storageAccounts/readMicrosoft.Storage/storageAccounts/restoreBlobRanges/action
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The role is assignable throughout the Azure hierarchy. Microsoft documents assigning it to the Backup vault managed identity on each protected or restore-target storage account, or at a containing resource group when the same vault protects multiple approved accounts. A parent assignment reaches every inheriting storage account.
Common use cases (2)
- Grant a Backup vault managed identity the minimum consolidated storage-account permissions required to configure operational or vaulted blob backup.
- Allow Azure Backup to restore blobs or file shares where Microsoft's workload role matrix requires this role on the source and target accounts.
Prerequisites (3)
- Create or select the Backup vault and enable its managed identity before assignment.
- Identify every protected source and restore-target storage account and verify the selected backup mode and workload support matrix.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at the storage-account or approved containing scope.
Best practices (3)
- Assign to the Backup vault managed identity, not routinely to human backup operators.
- Use individual storage-account scope unless a single vault is explicitly approved to protect every account in a resource group.
- Review the delete lock, object replication, versioning, change feed, and retention changes that Azure Backup applies to protected accounts.
Security considerations (3)
- The role can create and delete resource locks, alter object replication policies, change blob service or container configuration, and trigger blob-range restore.
- A resource-group assignment gives the Backup vault control-plane authority over every storage account inherited into that group.
- It has no DataActions, but the service uses the management permissions to configure protection and restore behavior for account data.
Assignment guidance
Assign Storage Account Backup Contributor to the selected Backup vault managed identity on each protected or restore-target storage account. Use broader resource-group scope only for a deliberately grouped backup estate, and remove the assignment when protection is permanently retired.
Related roles (1)
- Backup Operator: Microsoft's backup role matrix pairs vault-side Backup Operator permissions with this storage-account role for supported blob and file-share operations.
Editorial sources (6)
- Azure built-in roles for Storage →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-16.
- Manage backups with Azure role-based access control →
Supports: Practical scope, Common use cases, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Configure and manage backup for Azure Blobs using Azure Backup →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.