Step 3. Specify Azure Account Settings
At the Account step of the wizard, select a Microsoft Azure compute account whose permissions will be used to deploy the new Veeam Backup for Microsoft Azure appliance.
For a Microsoft Azure compute account to be displayed in the Microsoft Azure compute account drop-down list, it must be added to the Cloud Credentials Manager. If you have not added the credentials to the Cloud Credentials Manager beforehand, you can do it without closing the wizard. To do that, click either the Manage cloud accounts link or the Add button, and complete the Microsoft Azure Compute Account wizard as described in the Veeam Backup & Replication User Guide, section Microsoft Azure Compute Accounts.
For each newly created account, Veeam Backup & Replication creates a new Azure AD application in your Microsoft Azure Active Directory. The application is automatically assigned the following built-in roles:
- Key Vault Crypto User role
- Owner role
For more information on Microsoft Azure built-in roles, see Microsoft Docs.
Note that the Owner role has a wide scope of permissions and capabilities. If you want the AD application to be assigned a limited list of permissions, create an AD application manually in Microsoft Azure. For more information on the required permissions that must be assigned to the AD application, see section Permissions. For more information on roles, see Microsoft Docs.
Consider the following: