Concerns about security issues, like malware, ransomware, and intrusion, are increasing. These security issues can be costly, in terms of both money and data. To guard against such attacks, Azure Backup now provides security features to help protect hybrid backups. This article covers how to enable and leverage these features to protect on-premises workloads using Microsoft Azure Backup Server (MABS), Data Protection Manager (DPM), and Microsoft Azure Recovery Services (MARS) agent. These features include:
Note
Enable Multi-user authorization (MUA) on your recovery services vault to add an additional layer of protection to the critical operation of disabling security features. Learn more.
Minimum version requirementsEnable the security features only if you're using:
Note
Ensure that you donât enable the security features if you're using infrastructure as a service (IaaS) VM backup. Currently, these features aren't available for IaaS VM backup and thus, enabling them won't have an impact.
Enable security featuresIf you're creating a Recovery Services vault, you can use all the security features. If you're working with an existing vault, enable security features by following these steps:
Sign in to the Azure portal by using your Azure credentials.
Select Browse, and type Recovery Services.
The list of Recovery Services vaults appears. From this list, select a vault. The selected vault dashboard opens.
From the list of items that appears under the vault, under Settings, select Properties.
Under Security Settings, select Update.
The update link opens the Security Settings pane, which provides a summary of the features and lets you enable them.
Enable the security features and select Save.
If security features setting is enabled, Azure Backup retains deleted backup data for an additional 14 days, and doesn't delete it immediately if the Stop backup with delete backup data operation is performed. To restore this data in the 14-day period, take the following steps, depending on what you're using:
For Azure Recovery Services agent users:
For Azure Backup Server users:
For Data Protection Manager users:
Checks have been added to make sure only valid users can perform various operations. These include adding an extra layer of authentication, and maintaining a minimum retention range for recovery purposes.
Authentication to perform critical operationsAs part of adding an extra layer of authentication for critical operations, you're prompted to enter a security PIN when you perform Stop Protection with Delete data and Change Passphrase operations for DPM, MABS, and MARS.
Additionally, with MARS version 2.0.9262.0 and later, the operations to remove a volume from MARS file/folder backup, add a new exclusion setting for an existing volume, reduce retention duration, and move to a less-frequent backup schedule are also protected with a security pin for additional security.
Note
Currently, for the following DPM and MABS versions, security PIN is supported for Stop Protection with Delete data to online storage:
To receive this PIN:
To ensure that there are always a valid number of recovery points available, the following checks have been added:
Typically, when a critical operation is performed, the subscription admin is sent an email notification with details about the operation. You can configure additional email recipients for these notifications by using the Azure portal.
The security features mentioned in this article provide defense mechanisms against targeted attacks. More importantly, if an attack happens, these features give you the ability to recover your data.
Troubleshoot errors Operation Error details Resolution Policy change The backup policy couldn't be modified. Error: The current operation failed due to an internal service error [0x29834]. Please retry the operation after sometime. If the issue persists, please contact Microsoft support. Cause:When immutability for your Recovery Services vault is enabled, operations that reduce the cloud backup retention or remove cloud backup for on-premises data sources are blocked.
Immutability support for DPM and MABSThis feature is supported with MARS agent version 2.0.9250.0 and higher from DPM 2022 UR1 and MABS v4.
The following table lists the disallowed operations on DPM connected to an immutable Recovery:
Operation on Immutable vault Result with DPM 2022 UR1, MABS v4, and latest MARS agent.With DPM 2022 UR2 or MABS v4 UR1, you can select the option to retain online recovery points by policy when stopping protection or removing a data source from a protection group from the console.
Result with older DPM/MABS and or MARS agent Remove Data Source from protection group configured for online backup 81001: The backup item(s) can't be deleted because it has active recovery points, and the selected vault is an immutable vault. 130001: Microsoft Azure Backup encountered an internal error. Stop protection with delete data 81001: The backup item(s) can't be deleted because it has active recovery points, and the selected vault is an immutable vault.With DPM 2022 UR2 or MABS v4 UR1, you can select the option to retain online recovery points by policy when stopping protection or removing a data source from a protection group from the console.
130001: Microsoft Azure Backup encountered an internal error. Reduce online retention period 810002: Reduction in retention during Policy/Protection modification isn't allowed because the selected vault is immutable. 130001: Microsoft Azure Backup encountered an internal error. Remove-DPMChildDatasource command 81001: The backup item(s) can't be deleted because it has active recovery points, and the selected vault is an immutable vault.Use new option -EnableOnlineRPsPruning with -KeepOnlineData to retain data only up to policy duration.
With DPM 2022 UR2 or MABS v4 UR1, you can select the option to retain online recovery points by policy when stopping protection or removing a data source from a protection group from the console.
130001: Microsoft Azure Backup encountered an internal error.Use the -KeepOnlineData flag to retain data.
Immutability support for MARSThe following table lists the disallowed operations for MARS when immutability is enabled on the Recovery Services vault. Other operations, such as increasing retention and excluding a file/folder from backup are allowed.
Disallowed operation Result with latest MARS agent Result with old MARS agent Stop protection with delete data for system state Error 810001User trying to delete backup item or stop protection with delete data where backup item has valid (unexpired) recovery point.
Error 130001Microsoft Azure Backup encountered an internal error.
Stop protection with delete data Error 810001User trying to delete backup item or stop protection with delete data where backup item has valid (unexpired) recovery point.
Error 130001Microsoft Azure Backup encountered an internal error.
MARS 2.0.9262.0 and later provide the option of stopping protection and retaining recovery points according to the policy in the console.
Reduce online retention period User trying to modify policy or protection with reduction of retention. 130001Microsoft Azure Backup encountered an internal error.
Remove-OBPolicy with -DeleteBackup flag 810001User trying to delete backup item or stop protection with delete data where backup item has valid (unexpired) recovery point.
Use âEnablePruning flag to retain backups up to their retention period.
130001Microsoft Azure Backup encountered an internal error.
Don't use the -DeleteBackup flag.
MARS 2.0.9262.0 and later provide the option of stopping protection and retaining recovery points according to the policy in the console.
Next stepsRetroSearch is an open source project built by @garambo | Open a GitHub Issue
Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo
HTML:
3.2
| Encoding:
UTF-8
| Version:
0.7.4