Skip to main content
compliance · azure

Running Azure VMs that are not protected by Azure Backup

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

ZopNight flags a running or successfully provisioned Azure VM that does not appear among Azure Backup's protected items. With no Recovery Services vault backup, there is no restore point for the VM's disks after accidental deletion, corruption or ransomware. The finding is rated high and carries a fixed estimate of $0 per month.

Signal and threshold

How ZopNight evaluates Running Azure VMs that are not protected by Azure Backup.
Field Value
Rule IDsRC-267
Categorycompliance
Severityhigh
Metricnone — pure configuration read
Thresholdnot in Azure Backup protected items
SourceZopNight
Permissions usedMicrosoft.Compute/virtualMachines/read · Microsoft.RecoveryServices/Vaults/backupProtectedItems/read

What a VM backup gives you that disks alone do not

Azure VM backup takes a snapshot of the VM on a schedule and transfers the data to a Recovery Services vault, where recovery points are kept separate from the VM and managed for you. For running Windows VMs, Azure Backup coordinates with the Volume Shadow Copy Service for an app-consistent snapshot; Linux VMs get file-consistent backups unless you add pre and post scripts.

Without it, the VM’s only copy of its data is the live disks. A deleted VM, a bad patch that corrupts the OS or a ransomware run has nothing to roll back to.

Checking whether a VM is protected

Terminal window
az backup protection check-vm --resource-group my-rg --vm my-vm

The command returns the vault ID when the VM is protected and nothing when it is not. To see all protected VMs in a vault, use az backup item list against that vault.

Two conditions for the finding

  1. The VM’s provisioning state is succeeded, or the VM is running.
  2. Azure Backup’s list of protected items was retrieved and the VM is not in it.

The protection state comes from Azure Backup itself, not from tags. No metric or window is involved; the VM is checked on every scan.

When a VM is not flagged

VMs in any other state, such as those being created or deleted, are skipped. If ZopNight could not retrieve the protected-items list, it has no evidence either way and raises nothing. A tag saying a VM is backed up neither triggers nor clears the finding.

Recovery risk, with a backup bill to fix it

The saving is a fixed $0 per month: this is a compliance finding. Protection adds cost, a per-instance fee plus vault storage, described on the Azure Backup pricing page.

Enabling Azure Backup for the VM

  1. Create a Recovery Services vault in the VM’s region, or pick an existing one.
  2. Choose or create a backup policy; a daily schedule is the common starting point.
  3. Enable protection:
Terminal window
az backup protection enable-for-vm --resource-group my-rg \
--vault-name my-vault --vm my-vm --policy-name DefaultPolicy
  1. Trigger the first backup and wait for it to finish. Microsoft notes total backup time is under 24 hours for daily policies; snapshot transfer to the vault can take hours at peak times.
  2. Test a restore, ideally to a separate VM.

For protecting a single data disk rather than the whole machine, see Azure Managed Disk Without Backup.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·