Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup™ Snapshot Manager for Data Center Administrator's Guide
  3. Storage array plug-ins for Snapshot Manager for Data Center
  4. Azure Files plug-in
  5. Roles and privileges on Azure Files
NetBackup™ Snapshot Manager for Data Center Administrator's Guide

Roles and privileges on Azure Files

To enable Snapshot Manager for Data Center to perform snapshot management operations, ensure that the credentials used for configuring the plug-in have the required roles and privileges assigned within Azure:

Table: Roles and privileges on Azure Files

Feature

Required permissions

Task/Operation

Discovery of Azure Files

Microsoft.Resources/subscriptions/resourceGroups/read

To retrieve a list of Resource Groups in a Subscription to search for Storage Accounts.

Microsoft.Storage/storageAccounts/read

To list Storage Accounts in a resource group.

Microsoft.Storage/storageAccounts/listkeys/action

To retrieve the connection Key for the Storage Account to read its contents to look for Azure file shares.

Microsoft.Storage/storageAccounts/fileServices/shares/read

To read Azure files in a storage account.

Plug-in configuration for Azure Files

Microsoft.Compute/virtualMachines/read

Required for identity-based authentication method used in plug-in configuration, when the Snapshot Manager for Data Center is deployed on a VM.

Microsoft.Compute/virtualMachineScaleSets/read

Required for identity-based authentication method used in plug-in configuration, when the Snapshot Manager for Data Center is deployed on a Virtual Machine Scale Set.

Feedback

Was this page helpful?
Previous

Azure Files plug-in configuration parameters

Next

Supported Snapshot Manager for Data Center Operation on Azure Files

Feedback

Was this page helpful?