This article explains how permissions and consents work in Quest On Demand Recovery (ODR) when connecting to an Azure AD tenant.
To use On Demand Recovery, a Global Admin role must be used to grant tenant-wide admin consent to the ODR application. This will register an Enterprise Application and create an ODR service principals in the tenant, which will be used for all backup and restore related actions.
Once consents are granted, the Global Admin role can be removed from the account used, as long as the required permissions from the user guide are assigned: ODR Required Permissions
© 2025 Quest Software Inc. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center