Keeps, in a resource of its own, the permissions demanded by multi-user authorisation before sensitive backup vault operations can go ahead; putting it in another subscription or tenant is recommended.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Resource Guard in context, with comparison tables and the common traps.
Terms in this definition
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- Authorisation
Working out which actions and data a signed-in user or application is permitted, typically via role assignments. It comes after authentication.
- Backup vault
Vault type in Azure Backup aimed at newer workloads, for instance managed disks, Azure Blobs, AKS and Azure Database for PostgreSQL. Protecting Azure VMs, Azure Files or MARS backups requires a Recovery Services vault instead.
- subscription
Entitlement bought for a product under VCF 9.0 licensing, carrying a set capacity. Where active ones share the same site, unit and product, their capacity is combined into licences, which are then allocated to vCenters.
- Tenant
A trusted, dedicated Microsoft Entra ID instance that stores the users, groups and app registrations of one organisation. A subscription trusts only a single tenant, although a tenant can be trusted by several subscriptions.
Related terms
- Backup MUA Operator
To perform a backup operation that multi-user authorisation (MUA) protects, a user needs this role assigned on the relevant Resource Guard.
- Multi-user authorization
Safeguard in Azure Backup whereby critical backup operations only proceed once a role on a Resource Guard has been obtained; that guard is best kept in a different tenant.