备份到URL的SAS Token权限要求及Azure备份操作疑问
Great question—let’s break this down clearly, since SQL Server backups to Azure Storage can have some non-obvious permission requirements.
一、备份到Azure存储所需的SAS Token权限
For SQL Server backups to Azure Blob Storage, the SAS Token needs permissions that cover both the write operation and any pre-backup validation steps. The key permissions you’ll typically need are:
- Write (
w): Required to actually upload the backup data to the target blob - Read (
r): Often needed for pre-backup checks (like verifying the target container/blob exists, or validating media set info) - List (
l): Useful if you need to list existing blobs in the container (e.g., when usingWITH INITto overwrite backups, SQL might check existing blobs first)
二、为什么仅w权限失败,rw却成功?
Your scenario with BACKUP X TO URL = <目标URL> WITH INIT, FORMAT explains exactly why w alone isn’t enough:
- The
WITH INIToption tells SQL Server to overwrite any existing backup on the target blob. To do this safely, SQL first needs to check if the blob exists and validate its current state—this requires therpermission. Without read access, SQL can’t confirm the blob’s location or whether it’s a valid backup target, so the operation fails. - The
FORMAToption creates a new media set. This process also involves some validation checks against the storage account/container, which again rely on read permissions to confirm accessibility.
In short: w lets you write data, but SQL needs r to do the necessary pre-flight checks before starting the backup.
三、你的操作步骤是否有误?
From what you’ve described, your workflow is totally correct:
- Create a credential using the SAS Token
- Run the
BACKUP ... TO URL WITH INIT, FORMATcommand
There’s no mistake in your steps here— the issue is purely a permission gap. If you want to test this further, try running the backup without WITH INIT (i.e., creating a new blob instead of overwriting) with just w permissions. It might work, but since INIT is a common requirement for managing backups, sticking with rw (or rwl if you need list access) is the safe bet.
内容的提问来源于stack exchange,提问作者OZ1903

