Howdy Of us!
You probably have ever inherited a sprawling Azure atmosphere and quietly puzzled whether or not each VM, database, AKS cluster, and storage account in it’s truly being backed up the way in which the enterprise thinks it’s, you might be in good firm.
In session this session of the Microsoft Azure Infra Summit 2026, Bhavya Tadikonda and Shobhit Garg from the Azure Resiliency product workforce walked us by means of how Azure Backup is evolving right into a unified, application-centric service that protects IaaS, PaaS, AKS, PostgreSQL, and unstructured storage from a single pane of glass.
Backup is a type of matters no person talks about till the day it actually issues. Then it’s the solely matter. The session framed Azure Resiliency round three pillars (infrastructure resiliency, knowledge resiliency, and cyber restoration), and Azure Backup sits squarely in the midst of the final two. The rationale this session lands arduous for ops groups is that the floor space we’re anticipated to guard retains rising: VMs, SQL on Azure VMs, SAP HANA, Sybase, AKS, PostgreSQL versatile servers, Azure Information, blobs, ADLS, and on it goes.
Right here is why this could matter to you:
- One vault mannequin now protects IaaS, PaaS, AKS, PostgreSQL versatile server, and storage workloads, with constant insurance policies and reporting.
- Cyber resiliency is constructed into the vault layer with immutability, delicate delete, and multi-user authorization, so backups themselves can survive a ransomware occasion.
- A brand new risk detection preview (powered by Microsoft Defender for Cloud) scans restore factors and tags them wholesome or suspicious earlier than you get better.
- Azure Backup for AKS protects cluster assets and chronic volumes with granular restores and immutable restoration factors.
- You may configure backups from VS Code by means of the Azure MCP server utilizing pure language prompts, which is genuinely helpful if you end up defending dozens of assets.
Briefly, fewer level instruments, fewer scripts, and a significantly better probability of truly assembly your RPO and RTO targets when the day comes.
The session opened with a fast reminder that resiliency in Azure stands on three pillars working collectively. Infrastructure resiliency retains the underlying VMs, zones, and networks alive. Information resiliency retains your knowledge intact, out there, and recoverable. Cyber restoration assumes the worst (a ransomware assault or insider occasion) and provides you air-gapped, immutable backups plus remoted restoration to revive safely.
Azure Backup is the connective tissue throughout knowledge resiliency and cyber restoration. On the knowledge layer, it presents snapshot tier backups for immediate operational restoration (with as much as a four-hour RPO), vault tier backups for long-term retention, and an archive tier for chilly compliance storage. For databases, you get database-aware safety for SQL Server in Azure VMs, SAP HANA, and SAP ASE (Sybase), with point-in-time restore and log backups as frequent as each quarter-hour. That will get you to an RPO as little as quarter-hour for SQL, which is a quantity most IT professionals will recognise as adequate for the overwhelming majority of enterprise apps.
On the vault layer, three safety primitives stack collectively: delicate delete (deleted backups are stored for an extra retention window), immutability (no operation can shorten retention or destroy restoration factors earlier than expiry), and multi-user authorization (crucial operations want approval from a second admin through a Useful resource Guard). These usually are not bolt-ons. They’re baked into Restoration Companies vaults and Backup vaults.
The session adopted a Contoso situation the place John, a cloud architect, configures backup for an utility VM and a database VM. He picks a Restoration Companies vault, creates a backup coverage, and defines frequency and retention primarily based on his RTO and RPO necessities. For the Linux utility tier, John permits the brand new agentless, crash-consistent backup, which is non-invasive and protects performance-sensitive workloads with out an in-guest agent.
For the database tier, John permits Azure Backup for SQL in Azure VMs. The service auto-discovers all databases contained in the VM, removes the handbook config dance, and lets him layer log backups, differential backups, and archival retention. For SQL At all times On, HANA HSR, and Sybase HA clusters, snapshot-based acceleration offers him quicker backups and on the spot restores.
Then John turns to cyber resiliency. From vault properties he evaluations delicate delete, immutability, and multi-user authorization, then permits the brand new risk detection preview. This integration with Microsoft Defender for Cloud scans restore factors for malware so you’ll be able to affirm a restoration level is clear earlier than you roll again. Contained in the protected objects view, every restore level is marked wholesome or suspicious, which is precisely the sign you need throughout an incident response.
For PaaS and cloud-native, Shobhit took over and walked by means of Azure Backup for AKS and Azure Backup for PostgreSQL versatile server. AKS safety covers the cluster assets, the persistent volumes, and the namespaces, with automated scheduled backups, granular restores, immutable restoration factors, and versatile retention. PostgreSQL versatile server will get vaulted backups with long-term retention plus a unified view for monitoring and alerts.
The piece that made the room sit up was the demo of configuring backup from VS Code utilizing the Azure MCP server. John installs the Azure MCP extension, validates mcp.json, opens the chat window, and begins the MCP server. He prompts it to record unprotected AKS clusters in his subscription, then asks it to configure backup for a selected cluster. The MCP server reuses an current vault and coverage, creates the protected merchandise, and applies the enterprise safety defaults. That’s the form of conversational ops expertise that scales properly when you might have lots of of assets.
For unstructured knowledge, Azure Backup brings file shares, ADLS knowledge, utility artifacts, and huge object shops into the identical vault-based mannequin, with off-site safety, long-term retention, immutability, delicate delete, and MUA utilized persistently.
So the place does the ROI present up? A couple of trustworthy eventualities:
- Ransomware assault on manufacturing VMs. With immutability and MUA, even a compromised admin account can’t destroy your restoration factors. With risk detection, you keep away from restoring an contaminated snapshot.
- Unintentional deletion of an AKS namespace. Granular AKS backup will get you a managed, application-aware restore with out redeploying the entire cluster.
- Compliance audit on a regulated workload. Vault tier plus archive tier offers you the retention you want with out inflating scorching storage prices.
- A cloud architect onboarding 30 new VMs and 10 PostgreSQL servers. Utilizing Azure MCP from VS Code, they will configure backup conversationally as a substitute of click-clicking by means of portal blades.
- A BCDR drill. The resiliency agent (powered by Azure Copilot) can advocate enabling Azure Website Restoration on high of Azure Backup for stricter RTO and RPO, then information you thru enabling it.
Sincere tradeoff: risk detection is in preview, agentless crash-consistent backup is newer than the in-guest variant, and multi-user authorization requires a Useful resource Guard that lives in a separate subscription (ideally a separate tenant). That’s further setup work, however it’s the proper design for separation of duties.
Concrete first steps you’ll be able to take this week:
- Open Backup Middle (or the brand new Resiliency in Azure expertise) and stock what’s already protected versus uncovered.
- Choose one Restoration Companies vault and activate enhanced delicate delete with a significant retention interval, then make it AlwaysOn for manufacturing.
- Rise up a Useful resource Guard in a separate subscription or tenant and wire up MUA in your most crucial vault.
- For a non-production AKS cluster, set up the Backup extension and shield a namespace finish to finish, together with a check restore.
- Attempt the Azure MCP server from VS Code to record unprotected assets and configure backup with a immediate.
- If you happen to run SQL on Azure VMs, allow log backups each quarter-hour on one database and validate a point-in-time restore.
Catch the total Microsoft Azure Infra Summit 2026 session playlist right here
Cheers!
Pierre
