Skip to main content
rightsizing · azure

Recovery Services vaults for non-production workloads still storing backups geo-redundantly

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags a Recovery Services vault whose storage replication type is `GeoRedundant` or `ReadAccessGeoZoneRedundant` when the vault is affirmatively non-production and shows no production signal. It needs usable geo-redundant and locally redundant storage rates for the region, which are not yet available to it, so no finding is raised today.

Signal and threshold

How ZopNight evaluates Recovery Services vaults for non-production workloads still storing backups geo-redundantly.
Field Value
Rule IDsRC-1393
Categoryrightsizing
Severitylow
Metricnone — pure configuration read
ThresholdGRS or RA-GZRS replication on a non-production vault
SourceZopNight
Permissions usedMicrosoft.RecoveryServices/Vaults/read · Microsoft.RecoveryServices/Vaults/backupstorageconfig/read

Why a second-region backup copy costs more than it is worth for dev

Recovery Services vaults default to geo-redundant storage (GRS), which keeps a copy of backup data in the paired region. The vault creation guide lets you pick geo-redundant, locally redundant or zone-redundant, and notes that Cross Region Restore, the feature that uses the paired copy, works only on GRS vaults and carries its own charges.

For a vault that protects development or test machines, a regional disaster copy is rarely a real requirement. Locally redundant storage keeps the backups in one region at a lower storage rate, and the vaults that protect production can stay on GRS.

Checking the replication type of each vault

Terminal window
az backup vault list --query "[].{name:name, rg:resourceGroup}" -o table
az backup vault backup-properties show --resource-group my-rg --name my-dev-vault

The second command returns the vault’s backup properties, including its storage redundancy and whether Cross Region Restore is on.

Non-production evidence the rule insists on

  1. The vault’s replication type is read from its backup storage configuration and is GeoRedundant or ReadAccessGeoZoneRedundant. If Azure does not return an authoritative value, the vault is not judged.
  2. There is an affirmative non-production signal: a dev or test pattern in the vault name, or a subscription flagged as non-production.
  3. There is no production signal. A production name pattern or a production environment tag overrides everything else.

The two signals are asymmetric on purpose. Name patterns can mislead either way, so the rule needs positive proof of non-production and the absence of any sign of production.

Vaults that are never proposed for LRS

Vaults already on locally or zone-redundant storage are skipped, as are vaults without a clear non-production signal. Without both a geo-redundant and a locally redundant storage rate for the region it raises no finding, and at present those per-GB rates cannot yet be used by the check, so it stays silent on every vault. When Cross Region Restore is enabled, the recommendation adds disabling it as a first step.

Where the saving comes from

Only the backup storage component of a vault bill depends on redundancy. The fee charged for each protected instance stays the same whichever replication type you pick, so any real saving is the stored backup volume priced at the GRS rate minus the same volume at the LRS rate. ZopNight does not show a figure for this recommendation until it can price that storage component on its own, rather than apply a rate ratio to a bill that is mostly instance fees.

Moving a dev vault to locally redundant storage

  1. Confirm the vault protects only non-production workloads and that no one needs a second-region copy.
  2. Open the vault, then Properties, then Backup Configuration.
  3. Check Cross Region Restore first. Microsoft notes that a vault with it enabled cannot be reverted to GRS or LRS after protection starts for the first time.
  4. Change Storage replication type to Locally-redundant and save, for example with az backup vault backup-properties set --resource-group my-rg --name my-dev-vault --backup-storage-redundancy LocallyRedundant.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·