Here is the list of permissions required for Active Directory Backup and Restore actions.
Action | Required Permissions |
For Granular Backup |
|
For Granular Restore |
|
For System State Backup |
|
For System State Restore - Forest Recovery |
|
Restore Deleted Objects (Recycle Bin Access) | To restore deleted objects, read and list access to the Recycle Bin (Deleted Objects container) is required. Since this container is protected, ownership must be taken before assigning permissions.
|
Generic example commands:
Action | Command |
Take ownership of the Deleted Objects container |
|
Grant read and list permissions to the service account |
|
