question

BastiaanMolsbeckInfoland avatar image
0 Votes"
BastiaanMolsbeckInfoland asked WojnarPeter-4160 commented

Azure SQL Database: are backups stored on immutable storage?

There is a lot of documentation on docs.microsoft.com about automated backups and long-term backup retention for Azure SQL Databases.
But I can't seem to find any article which confirms that these backups are stored on immutable storage.
I would like to know whether these backups are tamper proof and are not susceptible to ransomware attacks.
Or do I need to take additional measures to achieve that?

azure-sql-database
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Wanted to add a few follow on questions to this existing question.

  1. Do the two answers given previously apply to backups for both Azure SQL Database and Azure SQL Managed Instance?

  2. The two answers provided seem to imply, although they don't specifically say, that Azure SQL backup storage is not immutable, however, the location and security infrastructure around backups is such that tampering and ransomware attacks are not possible. Is that a correct interpretation?

  3. Azure has immutable blob storage. Would it be desirable or even possible for a customer to move Azure SQL backups to this storage to achieve even greater protection against ransomware types of attacks. or, would this not provide any greater level of protection assuming it were even possible.

Sorry if I sound a bit paranoid with these questions but given recent and ongoing events heard almost daily now in the news this has become an even more important issue than ever.

Thank you

0 Votes 0 ·
NavtejSaini-MSFT avatar image
0 Votes"
NavtejSaini-MSFT answered NavtejSaini-MSFT commented

@BastiaanMolsbeckInfoland

Azure SQL Backups are redundant and are replicated across the regions for protection. Here are the more details for the same.

Also Azure Cloud is a Trusted Cloud with capabilities of in built security, privacy and compliance. Please go through these documents for more information regarding the same.

Hope this helps.

Thanks
Navtej S


· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@BastiaanMolsbeckInfoland

Please let us know if you need any further help regarding this.

Thanks
Navtej S

0 Votes 0 ·
DavidBrowne-msft avatar image
0 Votes"
DavidBrowne-msft answered

I would like to know whether these backups are tamper proof and are not susceptible to ransomware attacks.

Customers have no direct access to the storage for these backups, protecting against both tampering and ransomware from compromised customer accounts.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.