Skip to main content
rightsizing · azure

Recovery Services vaults whose default backup policy keeps daily points longer than 30 days

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags an Azure Recovery Services vault billing at least $50 a month whose default backup policy keeps daily recovery points for more than 30 days. The estimate applies the retention cut to an assumed 70% storage share of the vault bill, leaving the fixed per-protected-instance fee out, and the recommendation says plainly that the share is assumed.

Signal and threshold

How ZopNight evaluates Recovery Services vaults whose default backup policy keeps daily points longer than 30 days.
Field Value
Rule IDsRC-1382
Categoryrightsizing
Severitymedium
Metricnone — pure configuration read
Thresholddefault policy retention > 30 days, vault cost >= $50/month
SourceZopNight
Permissions usedMicrosoft.RecoveryServices/Vaults/read · Microsoft.RecoveryServices/Vaults/backupPolicies/read · Microsoft.CostManagement/query/read

How backup policy retention drives the vault’s storage bill

An Azure Backup policy decides how often a recovery point is taken and how long each one is kept. Every retained point occupies backup storage in the vault, so a policy that keeps daily points for 90 days holds roughly three times the history of one that keeps them for 30. The vault charge has two parts: a fee for each protected instance, which retention does not touch, and the storage those recovery points use, which grows with it.

Default policies are easy to over-provision. A long daily retention chosen once for a critical server tends to become the default for everything added to the vault afterwards.

Reading policy retention for a vault

Terminal window
az backup policy list --resource-group my-rg --vault-name my-vault \
--query "[].{policy:name, daily:properties.retentionPolicy.dailySchedule.retentionDuration.count, items:properties.protectedItemsCount}" \
-o table

The retentionPolicy block of the backup policy definition also holds weekly, monthly and yearly schedules, which this rule does not change.

What the vault must show before it is flagged

  1. The vault has a monthly cost taken from actual billing, not an estimate, and it is at least $50. Smaller vaults are not worth a policy review.
  2. The retention of the vault’s default policy is known.
  3. That retention is longer than 30 days, the baseline this rule measures against.

The recommendation also carries context when ZopNight has it: the vault’s storage replication type, because retention and replication together set the storage bill, and the number of protected items.

Vaults left alone, and the estimate’s limits

Vaults under $50 a month, vaults without actual billing data, and vaults whose default policy keeps 30 days or less produce nothing. The saving is an estimate, and the recommendation says so: ZopNight assumes 70% of the vault bill is retention-scaled storage. That is a conservative industry-typical split, not a measured value for this vault, and a vault dominated by instance fees will save less. For vaults where nothing is being protected any more, see Azure Recovery Vault Orphan.

Estimating the retention saving

Terminal window
monthly saving = vault monthly cost x 0.70 x (1 - 30 / current retention days)

A $400-a-month vault retaining 90 days would show $186.67: 0.70 of the bill, with two thirds of that history removed.

Shortening the default policy

  1. Confirm the recovery point objective each protected workload really needs with its owner.
  2. Open the vault, then Backup policies, and edit the default policy’s daily retention to 30 days or to the agreed value.
  3. Apply it with az backup policy set --resource-group my-rg --vault-name my-vault --policy @policy.json after editing the exported JSON.
  4. Move items that need long history to a separate policy instead of keeping everyone on it.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·