Manage cloud recovery sites
This article describes how to manage cloud recovery sites including pre-requirements, resources, cost implications, and lifecycle.
Pre-requirements
Cloud recovery site consists of resources such as virtual machines or file storage. These resources are created within the selected cloud service provider, such as Azure or AWS.
Depending on your cloud provider subscription, you might be charged for resources created in the cloud.
To create resources in Azure an Entra ID subscription is required. You can use your existing subscription or consider purchasing a new one.
To create resources in AWS, an AWS account is required. Learn more about AWS pricing.
Azure recovery site
Connection account for Azure
An account with a Contributor role in the resource group is required in case you plan to create a resource group manually and only allow Cayosoft Guardian to create the resources.
A Contributor role for the subscription is required for Cayosoft Guardian to create a resource group with all resources.
Resources in Azure recovery site
By default, Cayosoft Guardian provisions all resources required for the recovery site inside the selected resource group. These resources include a virtual machine, network interface, and disk for each domain controller to be recovered, plus shared resources such as a storage account, virtual network, subnet, network security group, and Relay. If you configure remote access to VMs in the Azure recovery site, additional Azure resources are provisioned during the creation of the Azure recovery site.
In this default mode, Cayosoft Guardian creates a temporary blob storage account inside the recovery site resource group. Cayosoft Guardian uploads backup data to this storage account during recovery, removes the backup data when recovery finishes, and deletes the storage account together with the recovery site. No preparation is required from you.
Microsoft charges you for these resources depending on the type of agreement that you entered with Microsoft, the date of purchase, and the currency exchange rate. Sign in to the Azure pricing calculator to see pricing based on your current offer with Microsoft.
Customer-provided Azure resources
Starting from version 7.3, you can deploy the standby forest recovery site into a customer-provided virtual network, subnet, and network security group.
Starting from version 7.4, you can extend this to a full set of precreated resources. When you select Use precreated resources in the recovery site settings, you point Cayosoft Guardian at Azure resources that your cloud team creates and governs:
| Resource | Provided by you | Notes |
|---|---|---|
| Resource group | Yes | Holds the precreated resources and the recovery site virtual machines. |
| Virtual network and subnet | Yes | Hosts the recovery site virtual machines. |
| Storage account (staging storage) | Yes | Used instead of temporary blob storage. See Staging storage account overview. |
| Azure Relay namespace | Yes | Cayosoft Guardian creates only a hybrid connection inside it. |
| Network security group | Optional | Cayosoft Guardian does not add rules to it. |
| Virtual machines, network interfaces, disks | No | Created by Cayosoft Guardian in your resource group and virtual network. |
| Hybrid connection | No | Created by Cayosoft Guardian inside your Azure Relay namespace. |
| Blobs in the staging storage account | No | Created by Cayosoft Guardian. Backup data is deleted when recovery finishes. |
This mode supports organizations with strict network governance, hub-and-spoke topologies, pre-approved subnet allocations, or a requirement that backup data never traverse public Azure Storage endpoints. To keep backup traffic off the public internet, add Azure private endpoints to the staging storage account. For more information, see Configure Azure private endpoints for the staging storage account.
Cayosoft Guardian does not change the configuration of the resources that you supply. It only creates blobs in the staging storage account and a hybrid connection in the Azure Relay namespace.
Prerequisites for precreated resources
- The virtual network must be in the same Azure region and subscription as the recovery site. We recommend that you keep the resource group, storage account, and Azure Relay namespace in that subscription as well.
- The required services, such as
Microsoft.Storageand any service endpoints used by the Relay and storage account, must be enabled on the selected virtual network or subnet. - The Entra application account must have the roles listed in Permissions for Forest Recovery in Cayosoft Guardian.
- If you disable public network access on the storage account, private endpoints and name resolution must be in place before you deploy.
Cayosoft Guardian checks that the virtual network and the storage account are accessible before deployment begins and reports any failure in the deployment wizard.
NOTE: Recovery plans created in Cayosoft Guardian 7.3 or earlier continue to use their existing templates and temporary blob storage, including plans that already use a customer-provided virtual network. No upgrade procedure is required. Precreated resources are available only for recovery plans created in version 7.4 or later.
NOTE: Configure recovery plans to use a Relay VM instead of the Azure Relay service. This option is available for both new and existing recovery plans and reduces dependency on Azure Relay service availability.
Deploy Azure recovery site
You can deploy an Azure recovery site from a forest recovery plan or standby forest recovery plan.
To deploy an Azure recovery site from a forest recovery plan:
- Open the Cayosoft Guardian web portal.
- Expand the Forest Recovery node.
- Select the Recovery plans node.
- Open a configured forest recovery plan, or click Add and select Forest Recovery plan to create a new one.
- Click Deploy recovery site, and then select Deploy to Azure.
- On the recovery site settings page, choose one of the following:
- Leave Use precreated resources cleared. Cayosoft Guardian provisions a dedicated resource group, virtual network, subnet, network security group, temporary blob storage, and Relay. This is the default and the recommended option when there are no governance constraints on Azure networking.
- Select Use precreated resources, and then select the existing Resource group, Virtual network, Storage account, and Relay. Use this option when your organization requires the recovery site to run in customer-managed resources or to transfer backup data over a private endpoint.
- Review the site isolation options and adjust them if required.
- Review the remaining settings, and then click Deploy.
If a check fails, the wizard displays the error before deployment proceeds. Resolve the underlying issue, and then retry the deployment.
For a full walkthrough of the precreated resources scenario, see Deploy Forest Recovery to customer-provided Azure resources.
Delete Azure recovery site
Delete a recovery site when you no longer need it.
- Expand the Forest Recovery node.
- Click Recovery Sites.
- Select the recovery site and click Delete.
- Keep the Delete linked Azure resources option enabled to delete resources in Azure.
When the recovery site uses precreated resources, Cayosoft Guardian deletes only the objects that it created: virtual machines, network interfaces, disks, and the hybrid connection. Your resource group, virtual network, storage account, Azure Relay namespace, and private endpoints remain in place. Backup data was already removed from the staging storage account when recovery finished, and the agent installers stay there for reuse.
Deploy Azure recovery site
You can deploy an Azure recovery site from a forest recovery plan or standby forest recovery plan.
To deploy an Azure recovery site from a forest recovery plan:
- Open the Cayosoft Guardian web portal.
- Expand the Forest Recovery node.
- Select the Recovery plans node.
- Click Add, and then select Forest Recovery plan.
- In the forest recovery plan, click Deploy recovery site, and then select Deploy to Azure.
-
On the Network page of the wizard, select one of the following options:
- Create new network resources — Cayosoft Guardian provisions a dedicated virtual network, subnet, and network security group inside the recovery resource group. This is the recommended option when there are no governance constraints on Azure networking.
- Use existing network resources — Select an existing virtual network, subnet, and, optionally, network security group from the same subscription and region as the recovery site. Use this option when your organization requires the recovery site to be placed in customer-managed networking.
- Review the site isolation options and adjust them if required.
- Review the remaining settings, and then click Deploy.
If any validation check fails, such as a region mismatch, subscription mismatch, missing required services on the virtual network, or insufficient permissions on the network resources, the wizard displays the error before deployment proceeds. Resolve the underlying issue, and then retry the deployment.
Delete Azure recovery site
Consider deleting a recovery site in case it is no longer required.
Expand theForest Recovery node.
Click on Recovery Sites.
Select the recovery site and click Delete.
Keep theDelete linked Azure resources option enabled to delete resources in Azure.
Deployment schema for Azure
AWS recovery site
Connection account for AWS
Account credentials with necessary permissions are required to connect to Gssuardian. For the detailed list of requirements on the Guardian side, see Planning and preparation: Cayosoft Guardian system requirements . To create an account in AWS with the required permissions, see Forest Recovery: How to create AWS access keys.
Deploy an AWS recovery site
You can deploy an AWS recovery site from a forest or standby forest recovery plan. To deploy an AWS recovery site from a forest recovery plan:
Open the Cayosoft Guardian web portal.
Expand the Forest Recovery node.
Select the Recovery plans node.
Press Add and select Forest Recovery plan.
Click Deploy recovery site in the forest recovery plan and select Deploy to AWS.
Review settings and click Deploy.
Delete an AWS recovery site
Consider deleting a recovery site in case it is no longer required.
Expand the Forest Recovery node.
Click on Recovery Sites.
Select the recovery site and click Delete.
Comments
0 comments
Please sign in to leave a comment.