★ First page of Microsoft's 100,000-partner directory, sorted by responsiveness✓ Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation, Data & AI● Microsoft partner since 2006◆ 1,100+ organizations under management

Azure Backup and Azure Site Recovery for a Small Business: Disaster Recovery Without a Second Site

2026-09-27·IT Partner·Security guidesNewAzureBackupDisaster RecoverySecurity

A second site used to be the price of disaster recovery: a rack, a second set of servers and someone to drive there. For a small business with three or four servers, Azure replaces the rack with two services that are easy to confuse. Azure Backup keeps copies you can restore from; Azure Site Recovery keeps a replica you can fail over to. This article explains the difference, which server needs which, immutable vaults against ransomware, test failovers and the runbook, what drives the bill, and why Microsoft 365 data is separate.

Backup and replication answer different questions

Two numbers define a recovery plan: the recovery point objective (RPO), how much work you can afford to lose, and the recovery time objective (RTO), how long you can be down.

Azure Backup, in Microsoft's words (September 2026), "is a native Azure service that helps you protect your data and restore it when required." A backup is a point-in-time copy in a vault. Restoring means building or repairing a server and copying data back, so the RPO is your backup interval and the RTO is hours to days.

Azure Site Recovery (September 2026) "replicates workloads running on physical and virtual machines (VMs) from a primary site to a secondary location," and Microsoft's pitch is the point of this article: "replication to Azure eliminates the cost and complexity of maintaining a secondary datacenter." A replica is a continuously updated copy of the whole VM in Azure that can be started. The RPO is minutes, and the RTO is the time to fail over and confirm.

A small business needs backup for everything and replication for the servers whose downtime costs more than the replica does.

What to protect: the three servers

The typical estate is the trio from moving the last on-premises servers to Azure: a file server, an application server (often with SQL Server) and a domain controller. Each gets a different treatment.

The file server: back up daily at minimum, with retention that covers a slowly discovered ransomware event (we use 30 daily, 12 monthly and 3 yearly points). Replicate it only if a day without shared files stops the business.

The application server and SQL: this is the replication candidate. Back it up as well, with application-consistent SQL backups, because replication copies corruption as faithfully as it copies data.

The domain controller: back up the system state, and do not rely on replicating it. Our practice is a small second domain controller running in Azure permanently, so that identity is already there when the application server fails over.

Azure Backup for on-premises servers: MARS and MABS

Two agents cover on-premises servers. The Microsoft Azure Recovery Services agent, MARS, backs up "files, folders, and the volume or system state from an on-premises computer to Azure" (January 2026), straight to a vault. It is the tool for the file server's data and the domain controller's system state.

Microsoft Azure Backup Server, MABS, is "a dedicated, single-purpose server" on Windows Server 2019 or 2022, on-premises or as an Azure VM, that protects "application workloads, such as Hyper-V VMs, VMware VMs, Azure Local VMs, Microsoft SQL Server, SharePoint Server, Microsoft Exchange, and Windows clients" (January 2026). It keeps "the first backup copy" on its own attached storage and sends the second to the vault. It is the tool for the application server and SQL.

For servers already in Azure, native VM backup with the enhanced policy runs "multiple times a day" (January 2026), with no agent to install. Vault storage can be locally, zone or geo redundant; pick geo redundant when the vault is the disaster copy.

Immutable vaults, soft delete and multi-user authorization against ransomware

Modern ransomware deletes backups before it encrypts. Azure Backup's answer is three settings, and our immutable vault hardening service turns all three on.

Soft delete keeps deleted backup data for a window before it is gone. Microsoft's enhanced soft delete documentation (November 2025) says it "is now enforced by default, and soft delete state can no longer be modified from the Azure portal," with retention "for 14 to 180 days."

Immutable vault blocks "any operations that could lead to loss of recovery points" (September 2026): stopping protection with data deletion, and shortening retention in a policy. It has two states. Enabled can be disabled again. Enabled and locked cannot: "immutability locking is irreversible." Lock it once retention is settled; an attacker with admin credentials cannot unlock it either.

Multi-user authorization puts a Resource Guard, "another Azure resource," in front of critical operations such as disabling soft delete, disabling immutability or changing policies, and requires a second authorization from someone with access to that guard (April 2026). Microsoft's advice, and ours, is to place the Resource Guard "in a subscription or tenant that's different from the one that contains the vaults."

Together they answer the immutable-backup line in the cyber insurance questionnaire with a screenshot.

Azure Site Recovery: replication, test failover and the runbook

For Hyper-V hosts without Virtual Machine Manager, Site Recovery needs an Azure subscription, a storage account and a virtual network, plus "the Azure Site Recovery Provider and Recovery Services agent on each standalone Hyper-V host" (February 2026). Microsoft's overview cites "replication frequency as low as 30 seconds for Hyper-V."

A recovery plan "gathers machines into recovery groups for the purpose of failover" and defines "the sequence in which they start after failover" (January 2025): domain controller first, SQL second, application server third, with Automation runbooks or manual pauses between groups, up to 100 protected instances per plan. That is the technical half of the runbook. The other half is people: who declares a disaster, who runs the failover, how DNS is repointed, who checks the application, and how you fail back to repaired hardware, which Microsoft supports as a planned failover from Azure to the on-premises site.

Test it. A test failover validates "your replication and disaster recovery strategy, without any data loss or downtime," and "doesn't impact ongoing replication, or your production environment" (October 2025). Run it into an isolated Azure network, then select Cleanup test failover to delete the test VMs. We run one at go-live and then twice a year, and write the timing down, because the measured time is your RTO and the auditor will ask for it.

What drives the monthly bill

We print no Azure rates; they change, and the Azure pricing calculator carries the current ones. The drivers are stable.

Azure Backup: a charge per protected instance, which Microsoft defines as "a computer, server (physical or virtual), or workload that backs up to Azure" (March 2026), plus the vault storage consumed at the replication tier you chose.

Azure Site Recovery: Microsoft's cost page (September 2026) lists a "Protected Instance License fee" per server, "Replica Storage" in the target region, a cache storage account, storage transactions, network egress when data leaves an Azure region, and snapshot storage. Microsoft does not charge the protected-instance fee for the first 31 days of each instance, but storage, transactions and any recovered VM's compute still accrue. Compute is the important one: you pay for the replica's disks every month, and for VM compute only while a failover (or a test failover) is running.

Reservations do not fit DR compute, which runs rarely; they fit the permanent second domain controller, as covered in Azure reservations and savings plans.

Microsoft 365 data is a separate question

Neither service touches Exchange Online, SharePoint or OneDrive. Those live in Microsoft's cloud with Microsoft's resilience, and whether you add Microsoft 365 Backup or a third-party product is a different decision, worked through in native Microsoft 365 backup vs third-party tools.

The document that ties the server plan, the Microsoft 365 answer, the people and the phone tree together is what our Business Continuity and Disaster Recovery Plan Development service produces, and it is the document insurers and clients ask to see.

Frequently asked questions

What is the difference between Azure Backup and Azure Site Recovery?

Azure Backup keeps point-in-time copies in a vault to restore from; the recovery point is your backup interval and recovery takes hours. Site Recovery keeps a running replica of the whole VM in Azure to fail over to; the recovery point is minutes and recovery is the failover time.

Do I need a second site for disaster recovery?

No. Azure is the second site. Site Recovery replicates on-premises Hyper-V, VMware and physical servers to an Azure region, and Microsoft describes it as eliminating the cost of a secondary datacenter.

How much does Azure Site Recovery cost for a small business?

A per-server protected-instance fee each month, replica disk storage, transactions and snapshot storage, with VM compute charged only while failed over. Microsoft waives the instance fee for each server's first 31 days.

Can ransomware delete my Azure backups?

Not if soft delete (14 to 180 days, on by default), a locked immutable vault and multi-user authorization with a Resource Guard in a separate tenant are all in place. Locking is irreversible by design, so an attacker with admin credentials cannot undo it.

Sources

  • Microsoft Learn source files on GitHub (MicrosoftDocs/azure-docs), opened 2026-09-27: "What is the Azure Backup service?", ms.date 09/16/2026; "About the MARS agent", 01/16/2026; "Install and upgrade Azure Backup Server", 01/21/2026; "About Azure VM backup", 01/08/2026; "Azure Backup FAQ", 03/17/2026; "Immutable vault for Azure Backup", 09/09/2026; "Multi-user authorization using Resource Guard", 04/28/2026; "Configure and manage enhanced soft delete", 11/11/2025; "About Site Recovery", 09/23/2026; "Hyper-V to Azure disaster recovery architecture", 02/27/2026; "Azure to Azure common questions", 09/11/2026; "Site Recovery cost", 09/11/2026; "Run a test failover to Azure", 10/31/2025; "About recovery plans", 01/22/2025
  • IT Partner blog articles and service pages linked above; IT Partner engineering notes from Azure Backup and Site Recovery deployments, September 2026
  • No Azure Backup or Site Recovery rates are printed; the Azure pricing calculator carries current pricing.
Server Backup Replication RPO target RTO target What to test
File server MARS daily; 30 daily, 12 monthly, 3 yearly; geo-redundant vault Only if a day without files stops the business 24 hours Same business day Restore a folder to an Azure VM and time it
Application server with SQL MABS with application-consistent SQL backups Yes, Site Recovery with a recovery plan Minutes by replication; 1 hour by SQL backup 1 to 2 hours after declaration Test failover into an isolated network twice a year
Domain controller System state with MARS No; run a second DC in Azure permanently 24 hours Already running Confirm replication and sign-in from Azure
Microsoft 365 Separate decision: native or third-party Not applicable Per that decision Per that decision One mailbox and one site restore
Vault settings for all of the above Soft delete 14 to 180 days, locked immutable vault, MUA with a Resource Guard in a separate tenant Same vault Screenshot for the insurer

Key takeaways

  • Backup restores with an RPO of your backup interval and an RTO of hours; replication fails over with an RPO of minutes and a monthly fee. Back up every server; replicate one or two.
  • MARS covers files, folders and system state straight to a vault; MABS covers Hyper-V, VMware, SQL, Exchange and SharePoint with a local first copy; Azure VMs use the native enhanced policy.
  • Soft delete enforced by default for 14 to 180 days, a locked immutable vault and multi-user authorization with a Resource Guard in a separate tenant are the ransomware answer, and locking is irreversible on purpose.
  • Site Recovery needs a provider and agent on each Hyper-V host, a recovery plan that sequences the domain controller, SQL and the application, and a test failover at go-live and twice a year with the time recorded.
  • Backup bills per protected instance plus storage; Site Recovery bills an instance fee plus replica storage, with compute only while failed over. Microsoft 365 data needs its own decision.

Back up your Physical or Virtual Servers using Azure Backup is $90 per server plus a $500 tenant fee, 2 days, fixed price and paid after approval. Azure Backup Immutable Vault and Ransomware Hardening ($2,950 per project, 2 weeks) turns on soft delete, locked immutability and multi-user authorization. Azure Site Recovery Disaster Recovery Implementation is $150 per server plus a $2,500 tenant fee over 2 weeks, and Business Continuity and Disaster Recovery Plan Development ($3,950 per project, 2 weeks) writes the runbook around it. Ongoing restore testing is Managed Backup and Backup-Restore at $200 per month. Azure consumption is billed to your subscription at Microsoft's rates. Book a call with your server list and we will size the vault.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.