Running Azure VMs that are not protected by Azure Backup
What does ZopNight detect here?
ZopNight flags a running or successfully provisioned Azure VM that does not appear among Azure Backup's protected items. With no Recovery Services vault backup, there is no restore point for the VM's disks after accidental deletion, corruption or ransomware. The finding is rated high and carries a fixed estimate of $0 per month.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-267 |
| Category | compliance |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | not in Azure Backup protected items |
| Source | ZopNight |
| Permissions used | Microsoft.Compute/virtualMachines/read · Microsoft.RecoveryServices/Vaults/backupProtectedItems/read |
Where it applies
What a VM backup gives you that disks alone do not
Azure VM backup takes a snapshot of the VM on a schedule and transfers the data to a Recovery Services vault, where recovery points are kept separate from the VM and managed for you. For running Windows VMs, Azure Backup coordinates with the Volume Shadow Copy Service for an app-consistent snapshot; Linux VMs get file-consistent backups unless you add pre and post scripts.
Without it, the VM’s only copy of its data is the live disks. A deleted VM, a bad patch that corrupts the OS or a ransomware run has nothing to roll back to.
Checking whether a VM is protected
az backup protection check-vm --resource-group my-rg --vm my-vmThe command returns the vault ID when the VM is protected and nothing when it is not. To see
all protected VMs in a vault, use az backup item list against that vault.
Two conditions for the finding
- The VM’s provisioning state is succeeded, or the VM is running.
- Azure Backup’s list of protected items was retrieved and the VM is not in it.
The protection state comes from Azure Backup itself, not from tags. No metric or window is involved; the VM is checked on every scan.
When a VM is not flagged
VMs in any other state, such as those being created or deleted, are skipped. If ZopNight could not retrieve the protected-items list, it has no evidence either way and raises nothing. A tag saying a VM is backed up neither triggers nor clears the finding.
Recovery risk, with a backup bill to fix it
The saving is a fixed $0 per month: this is a compliance finding. Protection adds cost, a per-instance fee plus vault storage, described on the Azure Backup pricing page.
Enabling Azure Backup for the VM
- Create a Recovery Services vault in the VM’s region, or pick an existing one.
- Choose or create a backup policy; a daily schedule is the common starting point.
- Enable protection:
az backup protection enable-for-vm --resource-group my-rg \ --vault-name my-vault --vm my-vm --policy-name DefaultPolicy- Trigger the first backup and wait for it to finish. Microsoft notes total backup time is under 24 hours for daily policies; snapshot transfer to the vault can take hours at peak times.
- Test a restore, ideally to a separate VM.
For protecting a single data disk rather than the whole machine, see Azure Managed Disk Without Backup.