Stay organized with collections
Save and categorize content based on your preferences.
This page explains how to assign and modify a Backup and DR role to a user.
To access Backup and DR Service, each user needs a Google Account that has been
added to a Google Cloud project, folder, or organization as a principal with
an Identity and Access Management role that allows access to the management console.
Click a Select a project drop-down menu at the top of the page.
Click Grant Access.
In the Add Principals section, enter the principal's email address, domain, or other identifier.
Select the project you want to view users in.
Find the principal's email address, domain, or other identifier in Principals and select Edit principal.
The Assign roles drop-down menu displays all the roles–including any custom roles–that you can grant to the principal on this resource. Search for predefined roles.
Click Save.
Modify a users assigned roles
Use the following instructions to modify an existing role to a user.
Click a Select a project drop-down menu at the top of the page.
Select the user you want to modify the role of and click Edit principal.
The Select a role drop-down menu displays all the roles–including any custom roles–that you can grant to the principal on this resource. Search for predefined roles.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-29 UTC."],[[["\u003cp\u003eUsers require a Google Account added to a Google Cloud project, folder, or organization with an Identity and Access Management (IAM) role to access Backup and DR Service.\u003c/p\u003e\n"],["\u003cp\u003eIAM roles can be assigned to users via the Google Cloud console's IAM page by adding a principal and selecting the appropriate role from the "Assign roles" dropdown menu.\u003c/p\u003e\n"],["\u003cp\u003eExisting roles assigned to users can be modified by selecting the user in the IAM page and then utilizing the "Select a role" dropdown menu to change their assigned role.\u003c/p\u003e\n"],["\u003cp\u003ePredefined and custom roles for Backup and DR service can be found and granted within the IAM roles interface.\u003c/p\u003e\n"]]],[],null,["# Manage IAM roles\n\nThis page explains how to assign and modify a Backup and DR role to a user.\n\nTo access Backup and DR Service, each user needs a Google Account that has been\nadded to a Google Cloud project, folder, or organization as a principal with\nan Identity and Access Management role that allows access to the management console.\n\nFor a complete list of permissions associated with each role, see\n[IAM roles and permissions for Backup and DR Service](/backup-disaster-recovery/docs/access-control#roles).\nYou can also [create custom roles](/iam/docs/creating-custom-roles)\nthat contain subsets of permissions that map directly to your needs.\n\nAssign IAM roles to a user\n--------------------------\n\nUse the following instructions to assign a role to a user.\n\n1. In the Google Cloud console, go to the **IAM** page.\n\n [Go\n to IAM](https://console.cloud.google.com/projectselector/iam-admin/iam?supportedpurview=project,folder,organizationId)\n2. Click a **Select a project** drop-down menu at the top of the page.\n\n3. Click **Grant Access**.\n\n4. In the **Add Principals** section, enter the principal's email address, domain, or other identifier.\n\n5. Select the project you want to view users in.\n\n6. Find the principal's email address, domain, or other identifier in **Principals** and select **Edit principal**.\n\n7. The **Assign roles** drop-down menu displays all the roles--including any custom roles--that you can grant to the principal on this resource. Search for [predefined roles](/backup-disaster-recovery/docs/access-control#roles).\n\n8. Click **Save**.\n\nModify a users assigned roles\n-----------------------------\n\nUse the following instructions to modify an existing role to a user.\n\n1. In the Google Cloud console, go to the **IAM** page.\n\n [Go\n to IAM](https://console.cloud.google.com/projectselector/iam-admin/iam?supportedpurview=project,folder,organizationId)\n2. Click a **Select a project** drop-down menu at the top of the page.\n\n3. Select the user you want to modify the role of and click **Edit principal.**\n\n4. The **Select a role** drop-down menu displays all the roles--including any custom roles--that you can grant to the principal on this resource. Search for [predefined roles](/backup-disaster-recovery/docs/access-control#roles).\n\n5. Click **Save**."]]