Azure resource provider usage for Azure Virtual Machines protection

Commvault uses Azure resource providers to perform data protection operations for Azure and Azure Stack VMs.

These resource providers are used only to access snapshots, disks, and VM configurations that are required for backing up VMs to storage media, for recovering VMs, and for deleting intermediate entities that are created by Commvault during those operations. When a user who has the required administrative privileges requests that a recovered VM overwrite the original VM, the resource providers are also used to remove the original VM, but only after confirmation from the user.

Commvault usage of Azure resource providers is controlled by the managed identity or the Azure application that gives Commvault access to your Azure resources.

For more information about Azure resource providers, see Azure resource providers and types on the Microsoft documentation website.

For information about roles and permissions for protecting Azure resources, see Role and Permission Requirements for Protecting Azure Resources.

Resource providers for all protection operations

The following table shows the Azure resource providers that are needed for all Commvault operations and describes how Commvault uses each resource provider.

Resource providers Backups Restores VM conversions Replication Usage
Microsoft.Compute/availabilitySets/Read Get the availability set details of the VM.
Microsoft.Compute/diskEncryptionSets/read List the disk encryption set options for the region.
Microsoft.Compute/disks/* Perform all disk actions.
Microsoft.Compute/locations/* List the available VM sizes for a location and track the status of asynchronous API operations.
Microsoft.Compute/proximityPlacementGroups/read Get the proximity placement group properties.
Microsoft.Compute/proximityPlacementGroups/write Create a new proximity placement group or updates an existing one.
Microsoft.Compute/restorePointCollections/* Perform all restorePointCollection activities.
Microsoft.ManagedIdentity/userAssignedIdentities/assign/action RBAC action for assigning an existing user-assigned identity to a resource.
Microsoft.Compute/snapshots/* Perform all snapshot activities.
Microsoft.Compute/virtualMachines/* Create VMs during restore operations.
Microsoft.KeyVault/checkNameAvailability/read Validate the name of a key vault.
Microsoft.KeyVault/vaults/accessPolicies/write Add, merge, or replace an access policy in a key vault.
Microsoft.KeyVault/vaults/deploy/action Access secrets in a key vault when you deploy Azure resources.
Microsoft.KeyVault/vaults/keys/* Access key vault when configured with RBAC. Used only for encrypted VMs.
Microsoft.KeyVault/vaults/read Get the key vault properties.
Microsoft.KeyVault/vaults/secrets/* Access key vault when configured with RBAC. Used only for encrypted VMs.
Microsoft.KeyVault/vaults/write Create or update a key vault for an encrypted VM.
Microsoft.Network/applicationSecurityGroups/joinIpConfiguration/action Joins an IP Configuration to application security groups. Not alertable.
Microsoft.Network/applicationSecurityGroups/read Gets an application security group ID.
Microsoft.Network/loadBalancers/read Get a load balancer definition.
Microsoft.Network/locations/* Track the status of asynchronous API operations.
Microsoft.Network/networkInterfaces/* Perform all network interface actions to create or attach existing network interfaces.
Microsoft.Network/networkSecurityGroups/join/action Join a network security group.
Microsoft.Network/networkSecurityGroups/read Get a network security group definition.
Microsoft.Network/publicIPAddresses/delete Deletes the public IP address.
Microsoft.Network/publicIPAddresses/join/action Join a public IP address.
Microsoft.Network/publicIPAddresses/read Get a public IP address.
Microsoft.Network/publicIPAddresses/write Create or update an existing IP address.
Microsoft.Network/virtualNetworks/read Get virtualNetworks information.
Microsoft.Network/virtualNetworks/subnets/join/action Join a subnet.
Microsoft.Network/virtualNetworks/subnets/read Get virtualNetworks information about a subnet.
Microsoft.ResourceHealth/availabilityStatuses/read Get the availability statuses for the resources in a specified scope.
Microsoft.Resources/deployments/* Create and manage a deployment.
Microsoft.Resources/subscriptions/resourceGroups/read Get a list of resource groups.
Microsoft.Storage/storageAccounts/* Create and manage a storage account on Blob.
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/add/action Access unmanaged VM blob.
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete Access unmanaged VM blob.
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/move/action Access unmanaged VM blob.
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read Access unmanaged VM blob.
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/write Access unmanaged VM blob.
Microsoft.Network/publicIPPrefixes/join/action Create a public IP address from a prefix.
Microsoft.Network/routeTables/join/action Associate a route table to a subnet.
Microsoft.ElasticSan/elasticSans/* Perform all Elastic SAN resource actions (create, update, delete, and read SAN properties).
Microsoft.ElasticSan/elasticSans/volumeGroups/* Perform all volume group actions (create, update, delete, and read volume group properties).
Microsoft.ElasticSan/elasticSans/volumeGroups/volumes/* Perform all volume actions (create, update, delete, and read volumes within a volume group).
Microsoft.ElasticSan/elasticSans/volumeGroups/snapshots/* Perform all snapshot actions (create, delete, read snapshots, and initiate snapshot access for backup and restore).
Microsoft.ElasticSan/skus/read List available Elastic SAN SKUs to validate provisioning options in a region.

Resource providers for auto-scaling Azure VM access nodes

The following table shows the Azure resource providers that are needed for auto-scaling Azure VM access nodes and describes how Commvault uses each resource provider.

Resource providers Backups Restores VM conversions Replication Usage
Microsoft.MarketplaceOrdering/offertypes/publishers/offers/plans/agreements/read
Get an agreement for a given marketplace VM item
Microsoft.MarketplaceOrdering/offertypes/publishers/offers/plans/agreements/write
Sign or cancel an agreement for a given marketplace VM item
×

Loading...