VPS Snaps

How to back up Azure VMs with disk snapshots and Azure Backup

Azure has two ways to back up a VM. A managed disk snapshot is a read-only copy of one disk, full or incremental, that you take on demand and restore by creating a new disk. Azure Backup is the scheduled option: a policy snapshots the whole VM, copies the data to a Recovery Services vault and keeps recovery points as long as you say. Both stay inside your Azure subscription.

9 min readUpdated Checked against official documentation

Full vs incremental snapshots

A full snapshot copies the whole disk every time. An incremental snapshot's first copy is full; later ones store only changes since the previous snapshot of that disk, and each still restores to a complete disk. Use incremental unless you have a reason not to.

FullIncremental
Billed forUsed size of the diskChanged data since the last snapshot (the first bills the used size)
StorageStandard (default), standard zone-redundant or premiumStandard; zone-redundant automatically where the region supports it
Copy to another regionNoYes

Consistency

A snapshot records one disk as it is at that moment; data still in memory is missing. Microsoft's guidance: if you'll create a new VM from it, cleanly shut down the VM first. For a running database, write a dump to disk before the snapshot, or use Azure Backup (below).

Create a snapshot in the portal

  1. In the Azure portal, search for Disks and open the disk you want to back up.
  2. Choose Create snapshot from the menu at the top.
  3. Pick a resource group and enter a name.
  4. For Snapshot type, choose Incremental (or Full). For a full snapshot, keep Standard HDD storage unless you need zone-redundant or premium.
  5. Choose Review + create, then Create.

Create a snapshot with the Azure CLI

Get the OS disk's ID, then snapshot it. For a data disk, use az disk show -n DISK -g GROUP --query id -o tsv.

Terminal
osDiskId=$(az vm show \
    -g myResourceGroup \
    -n myVM \
    --query "storageProfile.osDisk.managedDisk.id" \
    -o tsv)
Terminal
az snapshot create \
    -g myResourceGroup \
    -n myVM-os-20261003 \
    --source "$osDiskId" \
    --incremental true
  • -g is the resource group the snapshot goes into; -n is its name.
  • --source takes a disk ID or name.
  • --incremental true makes it incremental; leave it out for a full snapshot.
  • --sku sets storage for full snapshots: Standard_LRS (default), Standard_ZRS or Premium_LRS. Microsoft recommends standard; premium costs more.
  • --location defaults to the resource group's region; --tags adds key=value tags.
Terminal
az snapshot list -g myResourceGroup -o table

Copy a snapshot to another region

Only incremental snapshots can be copied across regions. Azure performs the copy and, after the first, sends only changes. -l is the target region and --copy-start true starts the managed copy.

Terminal
sourceSnapshotId=$(az snapshot show -n myVM-os-20261003 -g myResourceGroup --query [id] -o tsv)
Terminal
az snapshot create \
    -g myResourceGroup \
    -n myVM-os-20261003-westus \
    -l westus \
    --source "$sourceSnapshotId" \
    --incremental true \
    --copy-start true
Terminal
az snapshot show -n myVM-os-20261003-westus -g myResourceGroup --query [completionPercent] -o tsv

Use the copy once it reports 100. Copy a disk's snapshots one at a time, oldest first, and keep the source until the copy finishes.

Restore from a snapshot

You restore by creating a managed disk from the snapshot, in the snapshot's region. --source takes the snapshot name or ID and --sku the disk type. Then attach the disk, swap it in, or build a VM on it.

Terminal
az disk create \
    -g myResourceGroup \
    -n myVM-os-restored \
    --source myVM-os-20261003 \
    --sku Premium_LRS

Recover files. Attach the disk to a VM as a data disk, mount it, and copy what you need.

Terminal
az vm disk attach -g myResourceGroup --vm-name myOtherVM --name myVM-os-restored

Roll back the OS disk. Swap the restored disk in with az vm update --os-disk, using its full resource ID. The replacement must match the current OS disk's size, use compatible encryption, and suit the VM size's storage type. Microsoft says you don't need to stop the VM, though you can.

Terminal
newDiskId=$(az disk show -g myResourceGroup -n myVM-os-restored --query id -o tsv)
Terminal
az vm update -g myResourceGroup -n myVM --os-disk "$newDiskId"

Build a new VM. --attach-os-disk uses the restored disk as the OS disk and --os-type says what's on it. The VM keeps the original computer name. In the portal, open the disk and choose Create VM.

Terminal
az vm create -g myResourceGroup -n myVM-restored --attach-os-disk myVM-os-restored --os-type linux

Schedule backups with Azure Backup

For scheduled protection, Microsoft's tool is Azure Backup. A policy snapshots every disk of the VM, keeps recent snapshots for instant restore, and sends changed data to a Recovery Services vault in the same region.

Standard policyEnhanced policy
FrequencyDaily or weeklyEvery 4, 6, 8, 12 or 24 hours, or daily or weekly
Instant restore snapshots1 to 5 days (default 2)1 to 30 days (default 7)
Default retentionDaily points for 30 daysDaily 180 days, weekly 12 weeks, monthly 60 months, yearly 10 years
NotesWeekly policies keep snapshots 5 daysNeeded for Premium SSD v2 and Ultra Disk; can't switch back to Standard
  1. Create a Recovery Services vault in the VM's region: search Resiliency, choose + Vault, Recovery Services vault, fill in the details, then Review + create.
  2. In Resiliency, choose + Configure protection, with datasource type Azure Virtual machines and solution Azure Backup, and pick the vault.
  3. Choose the policy subtype (Enhanced or Standard), then the default policy or Create New to set the schedule, instant restore days and retention.
  4. Under Virtual Machines, choose Add, select the VMs, then Enable backup.

The same with the CLI. DefaultPolicy backs up once a day and keeps recovery points 30 days. backup-now runs an on-demand backup, and --retain-until is its expiry date in dd-mm-yyyy. Vaults store data geo-redundantly by default.

Terminal
az backup vault create \
    --resource-group myResourceGroup \
    --name myVault \
    --location eastus
Terminal
az backup protection enable-for-vm \
    --resource-group myResourceGroup \
    --vault-name myVault \
    --vm myVM \
    --policy-name DefaultPolicy
Terminal
az backup protection backup-now \
    --resource-group myResourceGroup \
    --vault-name myVault \
    --container-name myVM \
    --item-name myVM \
    --backup-management-type AzureIaaSVM \
    --retain-until 31-12-2026

Consistency: Windows VMs get application-consistent backups through VSS. Linux VMs get file-system-consistent backups unless you add your own pre and post scripts. A VM that is shut down gets a crash-consistent backup.

Restore from Azure Backup

  • Create a new VM from a recovery point, in the same region as the source.
  • Restore disk copies the disks to a resource group you choose, with a template for building a VM.
  • Replace existing swaps the disks on the current VM; Azure Backup snapshots the VM first. It works for unencrypted managed VMs.
  • Cross Region restores in the paired region, from the vault tier only, if you enabled it on the vault.
Terminal
az backup recoverypoint list \
    --resource-group myResourceGroup \
    --vault-name myVault \
    --backup-management-type AzureIaasVM \
    --container-name myVM \
    --item-name myVM \
    --query [0].name \
    --output tsv
Terminal
az backup restore restore-disks \
    --resource-group myResourceGroup \
    --vault-name myVault \
    --container-name myVM \
    --item-name myVM \
    --storage-account mystorageaccount \
    --rp-name myRecoveryPointName \
    --target-resource-group targetRG

--rp-name is the recovery point from the list, --storage-account holds the VM configuration and deployment template, and --target-resource-group receives the restored managed disks.

What snapshots and backups cost

Microsoft lists rates per region on its pricing pages and calculator. The model, as of October 2026:

  • Full snapshots bill per GB-month on the disk's used size: a 64 GiB disk holding 10 GiB bills 10 GiB. Premium snapshot storage costs more than standard.
  • Incremental snapshots bill on data changed since the last snapshot (the first bills the used size), at one rate for LRS and ZRS.
  • Cross-region copies add bandwidth and read transactions on the source.
  • Azure Backup charges a monthly fee per protected VM that steps up with its used data (up to 50 GB, 50 to 500 GB, then each extra 500 GB), plus vault storage and instant restore snapshots. Billing continues while backup data remains, even after you stop protection.

For file and database backups in Azure rather than disk snapshots, see how to use Azure Blob Storage for server backups.

Limits worth knowing

  • 500 incremental snapshots per disk at any one time; up to 7 per disk every 5 minutes.
  • Incremental snapshots can't be moved to another subscription or resource group, only copied to another resource group or region.
  • Only incremental snapshots copy across regions; 100 parallel copies per subscription per region.
  • Azure Backup: a VM can be protected by one vault only, in its own region; disks up to 32 TB.
  • Microsoft recommends at most 20 concurrent VM deployments from one snapshot.

What Azure snapshots and backups don't protect against

Snapshots are resources in your subscription. Deleting their resource group deletes them, so keep them in their own group, away from server cleanups.

Azure Backup is better isolated: soft delete holds deleted backup data for 14 days by default (extendable to 180), and immutable vaults can block deleting recovery points early. But the vault still sits in your Azure tenant and is paid for by your subscription.

  • Compromised identity. An account with enough rights can delete snapshots outright and stop protection.
  • Subscription problems. If the subscription is disabled or you lose access to the tenant, snapshots and vaults are out of reach along with the VMs.
  • Bad data. Corruption and ransomware-encrypted files are backed up faithfully. A restore test catches it.

Keep a copy of the data that matters outside Azure: database dumps and file archives in storage at another provider, under separate credentials. That is the off-site copy in the 3-2-1 rule, and why a snapshot is not a backup on its own.

A snapshot is the whole disk, but not a deleted account or a change you notice too late. For what else to keep, see what to back up on a Linux server, and for how often, RPO and RTO explained.

Frequently asked questions

Should I use full or incremental snapshots on Azure?
Incremental, in most cases. They bill only for changes, use zone-redundant storage where the region supports it, and are the only kind you can copy to another region.
Can I snapshot a running Azure VM?
Yes, but the snapshot holds only what is on the disk at that moment. Microsoft recommends a clean shutdown first if you'll create a new VM from it.
Does Azure Backup replace manual snapshots?
For scheduled protection, mostly yes. It snapshots every disk of the VM on a schedule, keeps recent snapshots for fast restores, and copies data to a vault with its own retention and soft delete.
How long does Azure Backup keep recovery points?
As long as the policy says. The default CLI policy keeps daily points for 30 days; Enhanced policies default to 180 days of daily points and can keep yearly points for 10 years.

How this was checked

Commands, limits and prices were checked against these official pages, on October 3, 2026: