Recovery Services vaults whose default backup policy keeps daily points longer than 30 days
What does ZopNight detect here?
ZopNight flags an Azure Recovery Services vault billing at least $50 a month whose default backup policy keeps daily recovery points for more than 30 days. The estimate applies the retention cut to an assumed 70% storage share of the vault bill, leaving the fixed per-protected-instance fee out, and the recommendation says plainly that the share is assumed.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1382 |
| Category | rightsizing |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | default policy retention > 30 days, vault cost >= $50/month |
| Source | ZopNight |
| Permissions used | Microsoft.RecoveryServices/Vaults/read · Microsoft.RecoveryServices/Vaults/backupPolicies/read · Microsoft.CostManagement/query/read |
Where it applies
How backup policy retention drives the vault’s storage bill
An Azure Backup policy decides how often a recovery point is taken and how long each one is kept. Every retained point occupies backup storage in the vault, so a policy that keeps daily points for 90 days holds roughly three times the history of one that keeps them for 30. The vault charge has two parts: a fee for each protected instance, which retention does not touch, and the storage those recovery points use, which grows with it.
Default policies are easy to over-provision. A long daily retention chosen once for a critical server tends to become the default for everything added to the vault afterwards.
Reading policy retention for a vault
az backup policy list --resource-group my-rg --vault-name my-vault \ --query "[].{policy:name, daily:properties.retentionPolicy.dailySchedule.retentionDuration.count, items:properties.protectedItemsCount}" \ -o tableThe retentionPolicy block of the
backup policy definition
also holds weekly, monthly and yearly schedules, which this rule does not change.
What the vault must show before it is flagged
- The vault has a monthly cost taken from actual billing, not an estimate, and it is at least $50. Smaller vaults are not worth a policy review.
- The retention of the vault’s default policy is known.
- That retention is longer than 30 days, the baseline this rule measures against.
The recommendation also carries context when ZopNight has it: the vault’s storage replication type, because retention and replication together set the storage bill, and the number of protected items.
Vaults left alone, and the estimate’s limits
Vaults under $50 a month, vaults without actual billing data, and vaults whose default policy keeps 30 days or less produce nothing. The saving is an estimate, and the recommendation says so: ZopNight assumes 70% of the vault bill is retention-scaled storage. That is a conservative industry-typical split, not a measured value for this vault, and a vault dominated by instance fees will save less. For vaults where nothing is being protected any more, see Azure Recovery Vault Orphan.
Estimating the retention saving
monthly saving = vault monthly cost x 0.70 x (1 - 30 / current retention days)A $400-a-month vault retaining 90 days would show $186.67: 0.70 of the bill, with two thirds of that history removed.
Shortening the default policy
- Confirm the recovery point objective each protected workload really needs with its owner.
- Open the vault, then Backup policies, and edit the default policy’s daily retention to 30 days or to the agreed value.
- Apply it with
az backup policy set --resource-group my-rg --vault-name my-vault --policy @policy.jsonafter editing the exported JSON. - Move items that need long history to a separate policy instead of keeping everyone on it.