Skip to content

Commit c10d06a

Browse files
authored
Merge pull request #307996 from MicrosoftDocs/release-backup-security
release-backup-security -> main -- 11/09 - 21:30 PST (11/10 11:00 IST)
2 parents 7e98386 + 6794920 commit c10d06a

13 files changed

+221
-2
lines changed

articles/backup/index.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ metadata:
1010
ms.topic: landing-page
1111
author: AbhishekMallick-MS
1212
ms.author: v-mallicka
13-
ms.date: 09/22/2025
13+
ms.date: 11/01/2025
1414

1515
# linkListType: architecture | concept | deploy | download | get-started | how-to-guide | learn | overview | quickstart | reference | tutorial | video | whats-new
1616

@@ -65,6 +65,8 @@ landingContent:
6565
linkLists:
6666
- linkListType: whats-new
6767
links:
68+
- text: Threat Detection with Microsoft Defender for Cloud integration (preview)
69+
url: threat-detection-overview.md
6870
- text: Azure Files (Premium) vaulted backup
6971
url: azure-file-share-backup-overview.md
7072
- text: Azure Elastic SAN backup (preview)
92.1 KB
Loading
65.6 KB
Loading
52.8 KB
Loading
61.5 KB
Loading
76.9 KB
Loading
84.3 KB
Loading
61.9 KB
Loading
71.4 KB
Loading
Lines changed: 130 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,130 @@
1+
---
2+
title: Tutorial - Configure Threat Detection and manage health of Azure VM Backups
3+
description: Learn how to enable threat detection for Azure VM backups using Azure Backup. The feature is integrated with Microsoft Defender for Cloud, configure settings, and monitor backup restore point health.
4+
ms.service: azure-backup
5+
ms.date: 11/10/2025
6+
ms.topic: tutorial
7+
author: AbhishekMallick-MS
8+
ms.author: v-mallicka
9+
ms.reviewer: v-mallicka
10+
#customer intent: As an IT admin, I want to enable threat detection for Azure VM backups so that I can identify and mitigate ransomware threats in restore points.
11+
12+
---
13+
14+
# Tutorial: Configure Threat Detection and manage health of Azure VM Backups (preview)
15+
16+
This tutorial describes how to enable threat detection for Azure Virtual Machine (VM) backups and manage them using Azure Backup. This feature is integrated with Microsoft Defender for Cloud, configure settings, and monitor backup restore point health.
17+
18+
Azure Backup now uses Microsoft Defender for Cloud (MDC) to provide threat detection for Azure VM backups. By integrating security signals and malware scans from Defender for Servers, Azure Backup automatically assesses the health of restore points during backup creation. This feature helps you quickly identify and respond to suspicious or ransomware-infected backups, ensuring safer recovery options for your VMs.
19+
20+
[Learn about Azure Backup threat detection feature and supported scenarios](threat-detection-overview.md).
21+
22+
## Prerequisites
23+
24+
Before you enable and manage threat detection for Azure VM backups, ensure the following prerequisites are met:
25+
26+
- Enable Microsoft Defender for Servers Plan 1 or Plan 2 on your Azure subscription. For Plan 1, enable Microsoft Defender for Endpoint (MDE) on virtual machines and verify correct configuration on the source VM; otherwise, backups might be incorrectly tagged. For Plan 2, ensure that you enable agentless malware scan. [Learn more about Defender for Server plans](/azure/defender-for-cloud/defender-for-servers-overview).
27+
- Enable bi-directional alert synchronization in Microsoft Sentinel to accurately identify backup recovery points (RPs). [Learn how to Ingest Microsoft Defender for Cloud alerts to Microsoft Sentinel](/azure/sentinel/connect-defender-for-cloud).
28+
- Mark alerts as resolved in Microsoft Defender for Cloud when using any third-party incident management solution alongside Defender.
29+
30+
31+
## Enable threat detection for Azure VM backups
32+
33+
You can configure source-scan at-scale at the vault level, which allows Azure Backup to perform Malware scans using Microsoft Defender at the source virtual machine. This capability allows Azure Backup to assess the health of recovery points when snapshots are taken.
34+
35+
You can enable threat detection for Azure VM backups with one of the methods - Azure Business Continuity Center or Vault properties. After the threat detection scan is configured on the vaults, the vault applies scan status to all new restore points created for VM backups.
36+
37+
38+
>[!Important]
39+
>- With the required Microsoft Defender for Cloud (MDC) plans, you can enable source-scan integration. Once enabled, this security feature can't be turned off.
40+
>- You can configure Source scan only when the selected subscription has the required Microsoft Defender for Servers plan.
41+
42+
### Option 1: Configure threat detection using Azure Business Continuity Center
43+
44+
45+
To enable threat detection for Azure VM backups using Azure Business Continuity Center, follow these steps:
46+
47+
1. In the [Azure portal](https://portal.azure.com/), go to **Business Continuity Center**.
48+
49+
1. On the **overview** pane, select the **Threat detection (Preview)** tile.
50+
51+
:::image type="content" source="./media/threat-detection-configure-monitor-tutorial/threat-detection-tile.png" alt-text="Screenshot shows the Threat detection tile in Azure Business Continuity Center." lightbox="./media/threat-detection-configure-monitor-tutorial/threat-detection-tile.png":::
52+
53+
1. On the **Threat detection (Preview)** pane, select **+ Configure scan** to start configuring source-scan integration.
54+
55+
:::image type="content" source="./media/threat-detection-configure-monitor-tutorial/configure-threat-detection.png" alt-text="Screenshot shows how to initiate threat detection scan configuration." lightbox="./media/threat-detection-configure-monitor-tutorial/configure-threat-detection.png":::
56+
57+
1. On the **Configure source-scan integration (preview)** pane, click **+ Select Vaults**.
58+
1. On the **Select Vaults** pane, under **Select subscription**, choose the subscription under which you want to enable the source-scan integration.
59+
60+
1. To enable integration with Microsoft Defender for Cloud, select the vaults from the list that contain the protected datasources (VM backups), and then select **Add**.
61+
62+
:::image type="content" source="./media/threat-detection-configure-monitor-tutorial/select-vault.png" alt-text="Screenshot shows the vault selection for scan configuration." lightbox="./media/threat-detection-configure-monitor-tutorial/select-vault.png":::
63+
64+
1. On the **Configure source-scan integration (preview)** pane, select **Configure scan** to enable threat detection for the vaults in the supported regions.
65+
66+
All the new recovery points created for the VM backups in the vault start showing the scan status as **Configured**.
67+
68+
### Option 2: Configure threat detection from vault properties
69+
70+
To enable threat detection for Azure VM backups from the Recovery Services Vault properties, follow these steps:
71+
72+
1. Go to the **Recovery Services vault** that contains the VM backups requiring threat detection, and then select **Properties**.
73+
1. On the **Properties** pane, under **Security Settings** > **Threat detection (Preview)**, select **Update**.
74+
75+
:::image type="content" source="./media/threat-detection-configure-monitor-tutorial/enable-threat-detection-vault.png" alt-text="Screenshot shows the enable threat detection option in the vault properties." lightbox="./media/threat-detection-configure-monitor-tutorial/enable-threat-detection-vault.png":::
76+
77+
1. On the **Threat Detection (Preview)** pane, turn on **Enable source-scan integration**, accept the terms by selecting the checkbox.
78+
1. Select **Update**.
79+
80+
## Monitor the health of Azure VM recovery points
81+
82+
To monitor the health of Azure VM recovery points using Azure Business Continuity Center, follow these steps:
83+
84+
1. Go to **Business Continuity Center**, and select the **Threat detection (Preview)** tile and view the summary of the recovery point health.
85+
86+
1. On the **Threat detection (Preview)** pane, select the protected item with **Scan summary** status as **Suspicious RPs found**
87+
88+
You can view the **Scan status** and **Scan summary** of all protected items across subscriptions. Scan summary is aggregated value based on the scan status of the recovery points created in the last seven days.
89+
90+
:::image type="content" source="./media/threat-detection-configure-monitor-tutorial/threat-detection-status-protected-items.png" alt-text="Screenshot shows the threat detection status of the protected items." lightbox="./media/threat-detection-configure-monitor-tutorial/threat-detection-status-protected-items.png":::
91+
92+
1. On the selected protected item pane, select the associated item from the list.
93+
94+
1. On the associated item pane, from the list of recovery points, select the hyper link with **Recent scan status** as **Suspicious** and view the scan details.
95+
96+
:::image type="content" source="./media/threat-detection-configure-monitor-tutorial/suspicious-recovery-point.png" alt-text="Screenshot shows the suspicious recovery points." lightbox="./media/threat-detection-configure-monitor-tutorial/suspicious-recovery-point.png":::
97+
98+
5. You can see the alerts that led to tagging this RP as **Suspicious**. You can remediate and take actions by selecting the alert and navigating to MDC. You can stop backups or increase security level of backups by enabling immutability or Multi-user authorization.
99+
100+
:::image type="content" source="./media/threat-detection-configure-monitor-tutorial/scan-details.png" alt-text="Screenshot shows the scan details for the suspicious recovery point." lightbox="./media/threat-detection-configure-monitor-tutorial/scan-details.png":::
101+
102+
You can also view the scan status of each recovery point during Azure VM restore, which helps you to select the appropriate restore point for ransomware recovery.
103+
104+
:::image type="content" source="./media/threat-detection-configure-monitor-tutorial/view-restore-point-scan-status.png" alt-text="Screenshot shows the restore point scan status." lightbox="./media/threat-detection-configure-monitor-tutorial/view-restore-point-scan-status.png":::
105+
106+
## Resolve threats and ensure healthy backups
107+
108+
If a backup recovery point is flagged as **Suspicious**, all subsequent recovery points remain flagged until the related alerts are triaged and resolved.
109+
110+
To resolve the alerts, select the alert from the **Scan details** pane and go to the Defender portal and perform one of the following actions:
111+
112+
- Resolve the alert in the Defender for Cloud. Learn how to [Manage security alerts in Microsoft Defender for Cloud](/azure/defender-for-cloud/manage-respond-alerts).
113+
- [Resolve alerts in Microsoft Sentinel](/azure/sentinel/incident-navigate-triage).
114+
115+
Ensure that the alert status is synchronized back to Defender for Cloud. Learn how to [Ingest Microsoft Defender for Cloud alerts to Microsoft Sentinel](/azure/sentinel/connect-defender-for-cloud).
116+
117+
- For alerts managed through third-party incident management tools, resolve them in the Defender for Cloud portal.
118+
119+
After you resolve all alerts and mark them as *resolved* in Microsoft Defender for Cloud, protected items are marked as **No threats reported**.
120+
121+
## Related content
122+
123+
- [About security features for Azure Backup](security-overview.md).
124+
- [About Microsoft Defender for Servers](/azure/defender-for-cloud/defender-for-servers-overview).
125+
- [About Microsoft Sentinel](/azure/sentinel/sentinel-overview).
126+
127+
128+
129+
130+

0 commit comments

Comments
 (0)