Symptom

When a user attempts Full System Recovery (FSR) of an account to Azure, the following error presents:
 
Error: The client "TenantAccount" with object id 'ID' does not have authorization to perform action 
'Microsoft.Storage/storageAccounts/listKeys/action' over scope
'/subscriptions/ID/resourceGroups/RSG-CORE-DR/providers/Microsoft.Storage/storageAccounts/redstorbackup'
or the scope is invalid. If access was recently granted, please refresh your credentials.


Cause

Only certain roles have rights to initiate FSR to Azure.

 

Solution

Assign one of the following roles to the relevant tenant account in the subscription:
  • Azure Resource Manager Owner
  • Azure Resource Manager Contributor
  • Storage Account Contributor