This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage identity, access, and governance (20–25%)
--> Implement governance to enforce security and regulatory compliance
--> Configure security controls for backup protection by using Azure Backup security features
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Overview
Backups are a critical security control because they provide a recovery option after data is accidentally deleted, corrupted, encrypted by ransomware, or intentionally destroyed.
However, backup data can also become a target. An attacker who compromises an administrator account may attempt to:
- Delete backup recovery points.
- Disable soft delete.
- Reduce backup retention.
- Stop backup protection.
- Modify backup policies.
- Delete a Recovery Services vault or Backup vault.
- Change encryption settings.
- Prevent administrators from restoring data.
Azure Backup includes several security features designed to protect backup data against accidental deletion, ransomware, and malicious or compromised administrators.
The most important features for the SC-500 exam are:
- Azure RBAC
- Soft delete
- Enhanced or always-on soft delete
- Immutable vaults
- Multi-user authorization (MUA)
- Resource Guard
- Encryption
- Private endpoints and network controls
- Backup security posture
- Azure Policy
- Monitoring, alerts, and reporting
These controls should be implemented together as part of a defense-in-depth strategy.
1. Understand the Azure Backup Security Model
Azure Backup protects supported workloads by storing backup data in Azure backup infrastructure.
Depending on the workload, backups may be stored in:
- Recovery Services vaults
- Backup vaults
- Azure-managed backup storage
- Snapshot-based storage used for certain workloads
A vault provides a management boundary for backup operations and an Azure RBAC boundary for controlling access to backup resources.
Examples of protected workloads include:
- Azure virtual machines
- Azure Files
- Azure SQL workloads
- SAP HANA databases
- SQL Server workloads
- Other supported Azure and hybrid workloads
Backup security must protect both:
- The backup data itself
- The administrative operations that control the backup data
For example, encrypting backup data is useful, but it does not prevent an administrator from deleting the recovery points. Similarly, RBAC limits who can manage backups, but it does not by itself make deleted backup data recoverable.
2. Use Azure RBAC to Control Backup Access
Azure RBAC controls who can perform management operations on backup resources.
Azure Backup provides built-in roles that help separate backup responsibilities.
Common roles include:
| Role | General purpose |
|---|---|
| Backup Reader | View backup-management information |
| Backup Operator | Perform many backup operations without managing backup policies or removing backups |
| Backup Contributor | Create and manage backups, but does not have unrestricted control over all vault-management operations |
| Contributor | Broad Azure resource management |
| Owner | Full resource access, including access management |
The exact permissions should be reviewed for the specific workload and operation.
Least-privilege guidance
Avoid assigning broad roles such as Owner or Contributor at subscription scope when a backup administrator only needs to manage one vault.
A better approach is to:
- Assign a backup-specific role.
- Assign it at the vault or resource-group scope when practical.
- Avoid granting unnecessary subscription-level permissions.
- Separate backup administration from security approval responsibilities.
For example:
A backup operator needs to configure and monitor backups in one Recovery Services vault.
The preferred approach is to assign an appropriate backup role at the vault scope rather than assigning Owner at the subscription scope.
Azure RBAC controls management-plane access. It should be combined with additional controls to protect critical backup operations.
3. Understand Soft Delete
What is soft delete?
Soft delete protects backup data after a backup item is deleted.
Instead of permanently deleting the backup immediately, Azure Backup retains the deleted backup data in a soft-deleted state for a configured retention period.
This allows the backup item to be recovered after:
- Accidental deletion
- Malicious deletion
- An administrator mistake
- A ransomware-related attack on the backup environment
The default soft-delete retention period is commonly 14 days, and the retention period can be extended to as much as 180 days depending on the applicable vault and configuration.
Example
An administrator accidentally deletes the backup item for a production virtual machine.
Without soft delete:
Delete backup item | vBackup data permanently deleted
With soft delete:
Delete backup item | vBackup enters soft-deleted state | vAdministrator can recover the backup
Important exam point
Soft delete does not prevent the initial deletion request.
Instead, it provides a recovery window after deletion.
Therefore:
Soft delete protects against permanent deletion, but it is not the same as preventing deletion.
4. Enhanced or Always-On Soft Delete
Azure Backup has enhanced soft-delete capabilities intended to strengthen protection against malicious attempts to disable the feature.
Traditional soft delete may allow certain administrative changes depending on the vault configuration and permissions.
Enhanced or always-on soft delete provides stronger protection by enforcing soft-delete behavior and reducing the ability to turn the protection off.
For newly created vaults, soft delete is enabled by default in supported configurations. Organizations should verify the current behavior and configuration for existing vaults.
The security objective is to ensure that deleted backup data remains recoverable for the configured protection period.
Exam distinction
If a question asks:
“Which feature allows recovery after a backup is deleted?”
The answer is:
Soft delete
If the question asks:
“Which feature helps prevent administrators from disabling soft delete?”
The answer may involve:
Enhanced or always-on soft delete and Multi-user authorization, depending on the scenario.
5. Understand Immutable Vaults
What is immutability?
An immutable vault protects backup data from operations that could cause the loss of recovery points.
Immutability is based on a write-once, read-many approach:
- Backup data can be written.
- Backup data can be read or restored.
- Backup data cannot be modified or deleted before the applicable retention period expires.
Immutability helps protect against:
- Ransomware
- Malicious administrators
- Accidental deletion
- Unauthorized retention reduction
- Destructive backup-policy changes
Azure Backup supports two important immutability states:
- Enabled
- Locked
6. Enabled Versus Locked Immutability
Enabled state
When immutability is enabled but not locked, the organization may retain some administrative flexibility.
Depending on the current service behavior and configuration, authorized administrators may be able to disable immutability or make certain policy changes.
This state can be useful while:
- Backup policies are still being finalized.
- Retention requirements are being validated.
- The organization is testing the configuration.
- Operational flexibility is still required.
Locked state
When immutability is locked, the protection becomes irreversible.
A locked immutable vault prevents destructive operations such as:
- Deleting backup data before retention expires.
- Reducing retention periods.
- Disabling immutability.
- Performing other operations that would undermine the protection of recovery points.
Before locking immutability, review:
- All protected items.
- Backup policies.
- Retention periods.
- Compliance requirements.
- Recovery requirements.
- Operational procedures.
After immutability is locked, retention settings cannot be freely reduced to remove protected backup data.
Exam decision rule
| Requirement | Appropriate approach |
|---|---|
| Need flexibility while configuring backup policies | Enable immutability but do not lock it yet |
| Need irreversible protection against deletion and retention reduction | Lock immutability |
| Need protection against a compromised administrator | Locked immutability, preferably combined with MUA |
Immutability is a strong data-protection control, but it should be planned carefully because it can restrict legitimate administrative operations.
7. Understand Multi-User Authorization
What is MUA?
Multi-user authorization (MUA) adds an additional approval layer for critical Azure Backup operations.
It is designed to prevent one compromised or malicious administrator from performing destructive operations alone.
MUA uses an Azure resource called Resource Guard.
A typical model is:
Backup administrator | | Requests protected operation vSecurity administrator | | Approves access or operation vProtected backup operation proceeds
MUA can protect operations such as:
- Disabling soft delete.
- Disabling immutability.
- Changing critical backup settings.
- Modifying backup policies.
- Performing protected restore operations.
- Changing encryption-related settings.
- Deleting or modifying protected backup resources.
The exact protected operations depend on the vault type and current service capabilities.
8. Understand Resource Guard
Resource Guard is the Azure resource used to provide an additional security boundary for MUA.
The purpose is to separate normal backup administration from approval of high-impact operations.
For stronger isolation, Microsoft recommends placing Resource Guard in a different Microsoft Entra tenant from the tenant hosting the production backup vault.
This helps reduce the risk that a compromise of the primary tenant will automatically provide access to both:
- The backup environment
- The security approval mechanism
Example
Without MUA:
Compromised backup administrator | vDisable soft delete | vDelete backup data
With MUA:
Compromised backup administrator | vRequests protected operation | vSecurity administrator approval required | vOperation proceeds only if approved
This provides separation of duties and reduces the risk of a single compromised identity destroying the recovery environment.
9. Use PIM With Resource Guard
Microsoft Entra Privileged Identity Management can be used to provide temporary access to Resource Guard.
For example:
- A backup administrator needs to perform a protected operation.
- The administrator requests temporary access.
- A security administrator approves the request.
- The administrator receives the required Resource Guard role for a limited period.
- The administrator performs the approved operation.
- The temporary access expires or is removed.
The Backup MUA Operator role is intended for performing protected backup operations after the necessary approval.
This approach supports:
- Just-in-time access
- Time-limited permissions
- Approval workflows
- Separation of duties
- Reduced standing privilege
Exam point
If a question states that:
“A backup administrator must not be able to disable critical protections without approval from another administrator.”
Think:
MUA + Resource Guard
If it also states that access should be temporary:
MUA + Resource Guard + PIM
10. Use Encryption to Protect Backup Data
Azure Backup encrypts backup data at rest by using Azure encryption capabilities.
Backup data in transit is protected using secure communication protocols such as HTTPS and TLS.
Organizations may also use customer-managed keys (CMKs) when they require greater control over encryption keys and key lifecycle management.
CMK-related considerations include:
- Key rotation
- Key expiration
- Key access
- Managed identities
- Key Vault permissions
- Recovery procedures
- Protection of encryption settings
MUA can help protect critical changes to encryption configuration by requiring additional approval.
Important distinction
Encryption protects the confidentiality of backup data.
It does not, by itself, prevent:
- Backup deletion
- Retention reduction
- Disabling backup protection
- Unauthorized restore operations
Therefore, encryption should be combined with RBAC, soft delete, immutability, and MUA.
11. Use Network Security Controls
Depending on the vault and workload, Azure Backup can use network security controls such as:
- Private endpoints
- Private Link
- Restrictions on public network access
- Private DNS configuration
- Network access rules
These controls help reduce exposure of backup-management and data-transfer paths.
For example, an organization may require backup traffic to use private connectivity rather than public network access.
Network controls can help protect against:
- Unintended public exposure
- Unauthorized network access
- Data exfiltration paths
- Misconfigured backup connectivity
However, network controls do not replace identity-based authorization.
A private endpoint does not automatically determine which administrator can delete a backup. That remains an RBAC and backup-security concern.
12. Understand Backup Security Posture
Azure Backup provides a security posture view that helps organizations evaluate the protection level of their backup environment.
Security posture considers controls such as:
- Immutability
- Soft delete
- Multi-user authorization
- Other backup-protection settings
Security levels include:
| Level | General meaning |
|---|---|
| Excellent | Strong protection against accidental deletion and ransomware, with MUA enabled |
| Good | Strong protection against accidental deletion through irreversible immutability or soft delete |
| Fair | Critical operations receive additional protection through MUA |
| Poor | Advanced protection is absent or only reversible protections are configured |
A production environment should generally aim for Good or Excellent protection, depending on business and regulatory requirements.
The highest security posture generally requires:
- Irreversible or always-on deletion protection
- MUA enabled
- Appropriate backup policies
- Proper access control
Exam point
If the scenario asks how to improve the security posture of backup data, consider:
- Enable soft delete.
- Enable and lock immutability where appropriate.
- Enable MUA.
- Apply least-privilege RBAC.
- Monitor backup security configuration.
- Use Azure Policy to evaluate compliance.
13. Use Azure Policy to Govern Backup Security
Azure Policy can be used to audit or enforce backup-security requirements across an environment.
Examples of policy objectives include:
- Require soft delete.
- Require immutability.
- Require MUA.
- Require private endpoints.
- Restrict public network access.
- Require customer-managed keys where appropriate.
- Audit backup vault configurations.
Azure Policy is especially useful when an organization wants consistent security requirements across many subscriptions or resource groups.
Azure Policy versus Azure RBAC
| Capability | Azure RBAC | Azure Policy |
|---|---|---|
| Controls who can perform operations | Yes | No |
| Grants permissions | Yes | No |
| Enforces resource configuration standards | Limited | Yes |
| Audits backup security settings | No | Yes |
| Prevents noncompliant resource configurations | No | Yes, depending on policy effect |
For example:
Require all Recovery Services vaults to use private endpoints.
This is an Azure Policy requirement.
Allow only designated backup administrators to manage the vault.
This is an Azure RBAC requirement.
14. Monitor Backup Security
Backup security must be monitored continuously.
Useful monitoring capabilities include:
- Azure Backup alerts
- Azure Monitor
- Log Analytics
- Workbooks
- Backup reports
- Activity logs
- Security posture information
- Microsoft Defender for Cloud recommendations
Security alerts can help identify suspicious events such as:
- Backup deletion
- Changes to retention
- Changes to protection settings
- Other potentially destructive backup operations
Action groups can be used to notify administrators through supported notification channels.
Example monitoring scenario
An organization wants to be notified whenever a backup item is deleted or a critical backup setting changes.
A suitable solution is to use:
- Azure Backup security alerts
- Azure Monitor action groups
- Activity and diagnostic logs
- Centralized monitoring through Log Analytics or Microsoft Sentinel when required
Monitoring does not prevent every destructive action, but it helps the organization detect and respond quickly.
15. Understand the Difference Between the Main Security Features
| Feature | Primary purpose |
|---|---|
| Azure RBAC | Control who can manage backup resources |
| Soft delete | Recover backup data after deletion |
| Enhanced or always-on soft delete | Strengthen deletion protection and reduce the ability to disable it |
| Immutable vault | Prevent modification or deletion before retention expires |
| Locked immutability | Make immutability irreversible |
| MUA | Require additional approval for critical operations |
| Resource Guard | Provides the approval boundary used by MUA |
| PIM | Provide temporary, controlled privileged access |
| Encryption | Protect confidentiality of backup data |
| Private endpoints | Reduce public network exposure |
| Azure Policy | Audit or enforce backup-security configuration |
| Azure Monitor and alerts | Detect suspicious or important backup events |
16. Recommended Defense-in-Depth Configuration
A strong backup-security design may include the following:
Identity and access
- Use least-privilege Azure RBAC.
- Separate backup administration from security approval.
- Avoid unnecessary Owner assignments.
- Use groups where appropriate.
- Use PIM for privileged access.
- Review role assignments regularly.
Backup data protection
- Enable soft delete.
- Use enhanced or always-on soft delete where supported.
- Enable immutability.
- Lock immutability after policies and retention requirements are validated.
- Use appropriate backup retention.
- Consider geo-redundant storage for resilience.
Critical-operation protection
- Enable MUA.
- Use Resource Guard.
- Place Resource Guard in a separate tenant when stronger isolation is required.
- Require approval for destructive or high-impact operations.
Encryption and networking
- Use encryption at rest and in transit.
- Use customer-managed keys when required.
- Protect Key Vault and encryption configuration.
- Use private endpoints and restrict public network access where appropriate.
Governance and monitoring
- Use Azure Policy to audit backup-security settings.
- Monitor backup alerts and activity logs.
- Review backup security posture.
- Integrate important events with centralized security monitoring.
17. Common Exam Traps
Trap 1: Soft delete prevents deletion
Not exactly.
Soft delete allows recovery after deletion. It does not necessarily prevent the deletion request itself.
Trap 2: Encryption prevents ransomware from deleting backups
Incorrect.
Encryption protects data confidentiality. It does not prevent an authorized or compromised administrator from deleting backup data.
Use soft delete, immutability, and MUA for deletion and destructive-operation protection.
Trap 3: MUA is the same as RBAC
Incorrect.
RBAC determines who has permissions.
MUA adds an approval requirement for selected critical operations.
Trap 4: Resource Guard stores the backup data
Not its primary purpose.
Resource Guard provides the authorization boundary used to protect critical operations through MUA.
Trap 5: Locked immutability can be disabled later
Incorrect.
Locked immutability is intended to be irreversible.
Trap 6: PIM alone protects backup data
Not necessarily.
PIM reduces standing privilege, but the underlying role and scope must still be appropriate. PIM is especially useful with MUA and Resource Guard.
Trap 7: Azure Policy grants backup permissions
Incorrect.
Azure Policy governs resource configuration and compliance. Azure RBAC grants permissions.
Trap 8: A private endpoint prevents an administrator from deleting backups
Incorrect.
Private endpoints control network access. RBAC, immutability, soft delete, and MUA address administrative and data-protection risks.
18. Scenario-Based Decision Guide
| Scenario | Best control |
|---|---|
| Recover a backup deleted accidentally | Soft delete |
| Prevent recovery points from being deleted before retention expires | Immutable vault |
| Make deletion protection irreversible | Lock immutability |
| Require approval before disabling critical protections | MUA with Resource Guard |
| Provide temporary access to Resource Guard | PIM |
| Restrict backup administration to specific identities | Azure RBAC |
| Require private connectivity to a vault | Private endpoint and network controls |
| Require backup-security settings across subscriptions | Azure Policy |
| Detect suspicious backup deletion | Azure Backup alerts and Azure Monitor |
| Protect backup data confidentiality | Encryption |
| Improve resilience against regional failure | Appropriate storage redundancy |
Practice Exam Questions
Question 1
An administrator accidentally deletes the backup item for a production virtual machine. The organization wants to recover the backup item without restoring from another backup source.
Which Azure Backup feature should be used?
A. Resource Guard
B. Azure Policy
C. Private endpoint
D. Soft delete
Answer: D
Explanation
Soft delete retains deleted backup data for a configured period, allowing the backup item to be recovered after accidental or malicious deletion.
Azure Policy governs configuration, private endpoints control network access, and Resource Guard supports MUA-protected operations.
Question 2
A company wants to ensure that backup recovery points cannot be deleted or have their retention reduced before the configured retention period expires.
Which feature is MOST appropriate?
A. Azure RBAC Reader
B. Azure Monitor
C. Immutable vault with locked immutability
D. Private Link
Answer: C
Explanation
An immutable vault protects backup data from destructive operations. Locking immutability makes the protection irreversible and prevents retention from being reduced to remove protected recovery points prematurely.
Question 3
A backup administrator must occasionally disable a critical backup protection setting. Company policy requires approval from a separate security administrator before the operation can proceed.
Which solution should be implemented?
A. Azure Policy with the Audit effect
B. Multi-user authorization with Resource Guard
C. Storage account firewall rules
D. Azure Backup Reader
Answer: B
Explanation
MUA requires an additional approval layer for protected backup operations. Resource Guard provides the authorization boundary used by MUA.
Question 4
An organization wants backup administrators to receive temporary access to perform MUA-protected operations. The access should expire automatically after the approved maintenance period.
Which solution is MOST appropriate?
A. Assign Owner permanently
B. Use a resource lock
C. Assign Contributor at subscription scope
D. Use Microsoft Entra PIM with the appropriate Resource Guard role
Answer: D
Explanation
PIM can provide eligible, time-limited access to the required Resource Guard role. This reduces standing privilege and supports approval-based administration.
Question 5
A security engineer wants to require all Recovery Services vaults in the organization to have soft delete and private network access configured.
Which service should be used to evaluate and govern these configuration requirements at scale?
A. Azure Policy
B. Azure RBAC
C. Microsoft Entra authentication methods
D. Azure Backup Reader
Answer: A
Explanation
Azure Policy can audit or enforce resource configuration requirements across subscriptions and resource groups.
Azure RBAC controls who can perform operations; it does not enforce that vaults have particular security settings.
Question 6
A company wants to reduce the risk that a compromised administrator in the production tenant can both manage backup vaults and approve destructive backup operations.
Which design provides the STRONGEST separation?
A. Assign Contributor to the administrator at subscription scope
B. Place Resource Guard in a separate Microsoft Entra tenant and use MUA
C. Disable soft delete
D. Use only Azure Monitor alerts
Answer: B
Explanation
Placing Resource Guard in a separate tenant provides stronger isolation between backup administration and approval of critical operations.
MUA then requires the appropriate approval before protected operations can proceed.
Question 7
A company has enabled encryption for its Azure Backup data. A security engineer states that encryption prevents an administrator from deleting backup recovery points.
Is the statement correct?
A. Yes. Encryption prevents all administrative deletion operations.
B. Yes, but only when the backup is stored in locally redundant storage.
C. No. Encryption protects data confidentiality but does not prevent deletion.
D. No. Encryption is not supported for Azure Backup.
Answer: C
Explanation
Encryption protects backup data at rest and in transit. It does not prevent authorized or compromised administrators from deleting backup data.
Deletion protection requires features such as soft delete, immutability, and MUA.
Question 8
A backup administrator only needs to manage backups in one Recovery Services vault. The administrator currently has Owner access at the subscription level.
What is the BEST remediation?
A. Keep Owner because backup operations are highly important.
B. Replace Owner with Reader at the management-group scope.
C. Remove all access to the subscription and disable the vault.
D. Assign an appropriate backup-specific role at the narrowest required scope.
Answer: D
Explanation
The administrator should receive only the permissions needed to manage backups and only at the required scope.
A backup-specific role at the vault scope is more consistent with least privilege than Owner at subscription scope.
Question 9
An organization is preparing to lock immutability on a production backup vault.
Which action should be performed FIRST?
A. Delete all existing backup items.
B. Review protected items, backup policies, retention periods, and recovery requirements.
C. Disable soft delete.
D. Assign Owner to all backup administrators.
Answer: B
Explanation
Locked immutability is intended to be irreversible. The organization should validate all protected items, retention requirements, and operational procedures before locking it.
Question 10
A security team wants to detect suspicious deletion of backup items and notify the security operations team automatically.
Which solution is MOST appropriate?
A. Configure Azure Backup security alerts with Azure Monitor action groups.
B. Assign the Backup Reader role to all users.
C. Enable a resource lock on every virtual machine.
D. Replace soft delete with encryption.
Answer: A
Explanation
Azure Backup security alerts and Azure Monitor action groups can provide notification when important or suspicious backup events occur.
RBAC controls access, resource locks protect Azure resources from certain management operations, and encryption protects confidentiality. None of those alone provides the required monitoring and notification capability.
Final Exam Takeaways
Remember the purpose of each major Azure Backup security feature:
- Soft delete provides a recovery window after backup deletion.
- Enhanced or always-on soft delete strengthens deletion protection.
- Immutable vaults protect recovery points from modification and deletion.
- Locked immutability makes the protection irreversible.
- MUA requires additional approval for critical backup operations.
- Resource Guard provides the approval boundary for MUA.
- PIM provides temporary, controlled privileged access.
- Azure RBAC controls who can manage backup resources.
- Encryption protects backup-data confidentiality.
- Private endpoints reduce public network exposure.
- Azure Policy audits or enforces backup-security configuration.
- Azure Monitor and alerts detect important or suspicious backup events.
An important security principle is:
Protect the backup data, protect the operations that control the backup data, and separate backup administration from approval of destructive operations.
Go to the SC-500 Exam Prep Hub main page
