Azure Recovery Services Vault
Does ZopNight manage Azure Recovery Services Vault?
Recovery Services vaults bill per protected instance plus the backup storage consumed, multiplied by the vault's replication choice. ZopNight discovers vaults with protected-item and policy context, recommends trimming default-policy retention beyond 30 days on vaults costing $50 a month or more, and flags stale or redundant protection.
Rules that fire on Azure Recovery Services Vault
At a glance
| Field | Value |
|---|---|
| Scheduling notes | discovery and cost visibility only. |
Recovery Services vaults hold backup data and site-recovery configuration for VMs and workloads, billed per protected instance plus storage consumed. Stale protection for deleted or unimportant resources keeps billing indefinitely.
Two charges per protected item, one multiplier on top
Backup cost has a fixed and a variable half. Every protected instance carries a flat monthly protection charge that depends on the workload and its size band, and the recovery points themselves consume vault storage billed per GB. The vault’s storage replication setting then multiplies that second half: geo-redundant vault storage costs roughly double locally redundant, and it is the default. Retention is the compounding factor: every extra day of retention is more recovery points held, so a generous policy quietly converts a modest per-instance fee into a substantial storage line.
Policy signals ZopNight extracts from each vault
Discovery runs via Azure Resource Graph with protected-item context, and Cost Management billing attributes backup spend. A dedicated enricher then reads the vault’s backup-policy configuration: the default policy’s retention days, the soft-delete window, the storage replication type (locally redundant, zone-redundant, geo-redundant, or read-access geo-zone-redundant), and whether cross-region restore is on. On vaults billing at least $50 a month, default-policy retention beyond 30 days triggers the retention-tune recommendation (RC-1382). Soft-delete windows beyond the free 14 days are checked as well (RC-1385), but that recommendation stays silent until soft-deleted volume can be measured, and other recommendations flag redundant or stale protection. Smart Tags can derive an environment tag for each vault from your tagging policies, held as pending until you accept it. Vaults are not schedulable; savings come from policy trims, replication downgrades, and retiring dead protection.
Backup spend that outlives its reason
Recurring offenders: protected items pointing at VMs deleted long ago, whose retained recovery points bill until someone stops protection and clears the data; production-grade geo-redundant vault storage guarding development machines; and default retention policies applied fleet-wide when a fraction of the fleet needs them.
Tracing vault charges in the portal
Azure portal → Recovery Services vaults → select a vault → Backup items shows everything protected and by which policy; Properties → Backup Configuration shows the replication type. Cross-checking backup items against live resources finds the stale protection fastest.