← All Roles

Entra Backup Administrator

Enabled
Versionv6
Last Updated2026-07-27
Categoryidentity
Assignment Modeallowed
Built-inYes
Template IDb6a27b2b-f905-4b2e-81b5-0d90e0ef1fdb

Description

Manage all aspects of Microsoft Entra Backup, such as create recovery jobs and manage backup snapshots.

Details

Assign the Entra Backup Administrator role to users who need to do the following tasks:

  • List all the snapshots in a tenant
  • Create a difference report (preview job) of a backup in the past and optionally include scoping filters
  • Compare states of changed directory objects that are in backup and recovery scope
  • Filter directory objects with supported scoping filters
  • Read status of a job
  • List all the jobs including preview and recovery jobs
  • Trigger recovery jobs and optionally include scoping filters
  • Enable or disable hard deletion protection on users, groups, applications, and service principals

Directory Actions5

  • microsoft.directory/backup/preview/cancel
  • microsoft.directory/backup/preview/create
  • microsoft.directory/backup/recovery/cancel
  • microsoft.directory/backup/recovery/create
  • microsoft.directory/backup/standard/read

Graph API Permissions4

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • BackupRestore-Monitor.Read.All
  • EntraBackup.Read.All
  • EntraBackup.ReadWrite.Preview
  • EntraBackup.ReadWrite.Recovery