Azure managed disks with no Azure Backup protection
What does ZopNight detect here?
ZopNight flags an Azure managed disk when no Azure Disk Backup instance in a Backup vault (`Microsoft.DataProtection/backupVaults`) protects it. Azure Disk Backup takes scheduled incremental snapshots and charges no protected-instance fee, so leaving a data disk unprotected saves little and leaves no restore point after deletion or corruption. No saving is claimed.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1327 |
| Category | compliance |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | backup protection = false |
| Source | ZopNight |
| Permissions used | Microsoft.Compute/disks/read · Microsoft.ResourceGraph/resources/read |
Where it applies
A disk without backup has one copy
A managed disk is replicated inside Azure for durability, but replication copies mistakes too. A deleted disk, an overwritten table or an encrypted-by-ransomware volume is gone in every replica at once. Recovery needs a point-in-time copy kept separately.
Azure Disk Backup provides that for individual disks. It is agentless and crash-consistent, uses incremental snapshots billed only for changed data, and stores them on standard storage in a resource group you choose. Because the snapshots are not copied to the vault, Azure Backup charges no protected instance fee and no backup storage cost; you pay snapshot storage.
Finding disks with no backup instance
List the disks that are already protected, then compare with the disks in your subscription:
az dataprotection backup-instance list-from-resourcegraph --datasource-type AzureDiskaz disk list --query "[].{name:name, rg:resourceGroup, state:diskState}" -o tableAny disk in the second list with no backup instance in the first has no Disk Backup protection.
What ZopNight needs before it fires
The rule uses the disk’s standalone Azure Disk Backup state, taken from the Backup vault backup instances ZopNight records during inventory. It fires only when that state says the disk is not protected. No metric or window is involved, and tags on the disk are not read: a tag saying “backed up” proves nothing, so it neither triggers nor clears the finding.
Disks that stay out of the report
When ZopNight has no backup state for a disk, it raises nothing rather than assuming the disk is exposed. Disks with an active backup instance are clear. If a disk is attached as a Kubernetes persistent volume, Microsoft recommends Azure Backup for AKS instead, which protects the volume together with the application; consider that before adding standalone disk backup.
One known gap: ZopNight does not yet cross-check VM-level backup in a Recovery Services vault. A disk protected only because its VM is backed up can therefore be flagged; dismiss those findings with that reason, or check the VM with the Azure VM backup rule instead.
Data-loss risk; the fix costs snapshot storage
There is no saving on this finding. Protection adds snapshot storage cost proportional to how much data changes between backups.
Protecting a disk with Azure Disk Backup
- Create a Backup vault in the disk’s region, or reuse one.
- Create a disk backup policy with the schedule and retention you need. A disk can hold at most 500 snapshots; scheduled backups may use 450 of them, with 50 kept for on-demand backups.
- Grant the vault’s managed identity the Disk Backup Reader role on the disk and the Disk Snapshot Contributor role on the snapshot resource group.
- Configure backup for the disk from the vault by assigning the policy to it.
- Run an on-demand backup and a test restore to a new disk to prove it works.
If the whole VM should be protected rather than one disk, see Azure VM Backup Not Enabled.