Hello @Thais Mello Thank you for contacting us on Microsoft Q&A platform. Happy to answer any questions you may have!
As per translator: Question #1: How to ensure that a ransomware invasion does not affect Microsoft Azure Backup?
Question #2: If I am attacked today by an attack, how does Microsoft ensure that my backup will be intact, unaffected by the attack, and not encrypted?
Please find the answers to your questions below:
Answer #1: Azure Backup provides security to your backup environment, both when your data is in transit and at rest. For more details refer to the doc - https://learn.microsoft.com/en-us/azure/security/fundamentals/backup-plan-to-protect-against-ransomware#azure-backup
Answer #2: If backup was enabled on the source system and backups are healthy prior to the point of attack, then consider the following actions:
- Review the incident timeline to estimate the impact on production workloads.
- Identify the last clean recovery point created before the impact.
- Review the retention duration of the existing recovery points. If more time is required to restore from an attack, then consider extending the retention duration in the backup policy.
- Perform recovery to an isolated and secure network.
- Perform restores on smaller sets of data (for example, item-level recovery) to ensure healthy recovery points.
- Scan the restored data for signs of infection to ensure it’s not compromised.
- Once the data is ascertained to be clean, use it for production system.
- Once complete, ensure backups are configured and healthy on the recovered workloads.
- Identify gaps to check where the process didn’t work as expected. Find opportunities to improve process.
Refer to the detailed FAQ document on "Protect backups from Ransomware"
Hope this answers your question. Feel free to reply if you have any questions.
If the response helped, do "Accept Answer" and up-vote it