Why Backup Matters
Even the most resilient system can suffer from accidental deletions, corruption, or ransomware attacks. Backup is your last line of defense to restore critical data. In Azure, Azure Backup provides a cloud-native, secure, and cost-efficient solution.
As a Solution Architect, you must design backup strategies that meet business RPO and retention requirements without overspending.
Azure Backup Overview
Definition:
A fully managed service that automates backup and recovery of data across Azure and on-premises workloads.
Key Features:
-
Supports VMs, Azure Files, SQL Database, SAP HANA, on-prem servers.
-
Application-consistent backups (not just crash-consistent).
-
Long-term retention (days to years).
-
Backup data stored in Recovery Services Vaults or Backup Vaults.
-
Geo-redundant and zone-redundant storage options.
Backup Scenarios
-
Azure VMs
-
Agentless backups.
-
Restore whole VM or individual files.
-
Databases
-
SQL Server and SAP HANA backups with log-level granularity.
-
Point-in-time restores supported.
-
Azure Files
-
Protect file shares with snapshot-based backup.
-
On-Premises Servers
-
Azure Backup Agent or MARS agent for file/folder backup.
-
Azure Backup Server (MABS) for app-level workloads.
Backup Design Considerations
-
Retention Policies
-
Short-term: daily/weekly backups.
-
Long-term: monthly/yearly retention for compliance.
-
Storage Redundancy
-
LRS (Locally Redundant Storage): cheapest, single datacenter.
-
GRS (Geo-Redundant Storage): replicates to paired region.
-
ZRS (Zone-Redundant Storage): across zones in region.
-
Security
-
Soft delete (default 14 days, can be extended).
-
Multi-user authentication for delete operations.
-
Encryption at rest with Azure-managed or customer-managed keys.
-
Cost Management
-
Optimize by separating daily vs archival backups.
-
Use GRS only when compliance requires geo-redundancy.
Example Enterprise Scenario
A hospital requires:
-
Daily VM backups with 90-day retention.
-
7-year retention for patient records.
-
Protection against accidental deletion by admins.
Correct design:
-
Use Azure Backup with Recovery Services Vault.
-
Configure daily VM backups with 90-day retention.
-
Enable long-term archival policy for 7 years.
-
Use Soft Delete + Multi-User Authentication for deletion protection.
Confusion Buster
-
Backup vs Replication
-
Backup = point-in-time recovery (historical snapshots).
-
Replication = real-time availability, not historical.
-
-
Recovery Services Vault vs Backup Vault
-
Recovery Services Vault = traditional, supports VMs, SQL, SAP.
-
Backup Vault = newer model, optimized for scale & RBAC.
-
-
Soft Delete vs Hard Delete
-
Soft Delete = protects deleted backups for 14+ days.
-
Hard Delete = permanent removal.
-
Exam Tips
-
“Which Azure service provides long-term retention of backups?” → Azure Backup.
-
“Which storage redundancy for cheapest backup?” → LRS.
-
“Which feature prevents accidental deletion of backup data?” → Soft Delete.
-
“Hospital requires 7-year retention.” → Configure long-term backup policy.
What to Expect in the Exam
-
Direct Q: “Which service to back up Azure VMs and SQL with long-term retention?” → Azure Backup.
-
Scenario Q: “Company requires compliance-grade retention for 7 years.” → Long-term backup with Recovery Services Vault.
-
Scenario Q: “Which option protects backups from accidental deletion?” → Soft Delete.
-
Trick Q: “Replication and backup provide the same protection.” → False.