{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover/",
        "slug": "dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover/"
        },
        "title": "Prepare HANA backup keys on both replication nodes before takeover",
        "summary": "Why can HANA user replication leave Azure Backup unable to use the new primary?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:29:47+00:00",
        "modified_at": "2026-09-10T00:52:38+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 236,
        "potentially_affected": "Use this check for the documented HSR pair in Azure. Verify the source's same-region and same-subscription vault prerequisites; this is not a procedure for extending the pair to a third node in another region.",
        "dse_recommendation": "Treat backup credential preparation as a node-specific takeover prerequisite.",
        "primary_source": {
            "name": "Back up SAP HANA System Replication databases on Azure VMs using Azure Backup - Azure Backup | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/backup/sap-hana-database-with-hana-system-replication-backup",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>For SAP HANA System Replication backup on Azure VMs, Microsoft distinguishes replicated users from hdbuserstore, which is not replicated during failover. The same backup key must be created on every HSR node. The preregistration procedure requires the same custom backup user, password, and stored key on both nodes. An expired custom backup-key password causes backup and restore failures. Both nodes must be physically and logically registered to the vault before a planned failover. <a href=\"https://learn.microsoft.com/en-us/azure/backup/sap-hana-database-with-hana-system-replication-backup\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this check for the documented HSR pair in Azure. Verify the source&#8217;s same-region and same-subscription vault prerequisites; this is not a procedure for extending the pair to a third node in another region.</p>\n<h2>DSE recommendation</h2>\n<p>Treat backup credential preparation as a node-specific takeover prerequisite. Ask the HANA and backup owners to reconcile both nodes&#8217; protected credential configuration and registration before the change window. Document the rotation process so a password change is not assumed to update every required store. Keep passwords out of tickets, screenshots, and ordinary runbook copies.</p>\n<h2>Verification</h2>\n<p>During an approved takeover rehearsal, confirm the new primary is selected and that backup jobs create usable recovery points. Verify authorized recovery separately. Record node identity, registration evidence, and job results without exposing credentials. If backup fails only after takeover, inspect the node-specific key preparation before rebuilding unrelated backup policy.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/backup/sap-hana-database-with-hana-system-replication-backup\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Back up SAP HANA System Replication databases on Azure VMs using Azure Backup</a>.</p>",
        "content_text": "Source facts\nFor SAP HANA System Replication backup on Azure VMs, Microsoft distinguishes replicated users from hdbuserstore, which is not replicated during failover. The same backup key must be created on every HSR node. The preregistration procedure requires the same custom backup user, password, and stored key on both nodes. An expired custom backup-key password causes backup and restore failures. Both nodes must be physically and logically registered to the vault before a planned failover. Microsoft Learn.\nApplicability\nUse this check for the documented HSR pair in Azure. Verify the source’s same-region and same-subscription vault prerequisites; this is not a procedure for extending the pair to a third node in another region.\nDSE recommendation\nTreat backup credential preparation as a node-specific takeover prerequisite. Ask the HANA and backup owners to reconcile both nodes’ protected credential configuration and registration before the change window. Document the rotation process so a password change is not assumed to update every required store. Keep passwords out of tickets, screenshots, and ordinary runbook copies.\nVerification\nDuring an approved takeover rehearsal, confirm the new primary is selected and that backup jobs create usable recovery points. Verify authorized recovery separately. Record node identity, registration evidence, and job results without exposing credentials. If backup fails only after takeover, inspect the node-specific key preparation before rebuilding unrelated backup policy.\nOfficial references\nMicrosoft Learn: Back up SAP HANA System Replication databases on Azure VMs using Azure Backup.",
        "content_markdown": "## Source facts\n\nFor SAP HANA System Replication backup on Azure VMs, Microsoft distinguishes replicated users from hdbuserstore, which is not replicated during failover. The same backup key must be created on every HSR node. The preregistration procedure requires the same custom backup user, password, and stored key on both nodes. An expired custom backup-key password causes backup and restore failures. Both nodes must be physically and logically registered to the vault before a planned failover. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/backup/sap-hana-database-with-hana-system-replication-backup).\n\n## Applicability\n\nUse this check for the documented HSR pair in Azure. Verify the source’s same-region and same-subscription vault prerequisites; this is not a procedure for extending the pair to a third node in another region.\n\n## DSE recommendation\n\nTreat backup credential preparation as a node-specific takeover prerequisite. Ask the HANA and backup owners to reconcile both nodes’ protected credential configuration and registration before the change window. Document the rotation process so a password change is not assumed to update every required store. Keep passwords out of tickets, screenshots, and ordinary runbook copies.\n\n## Verification\n\nDuring an approved takeover rehearsal, confirm the new primary is selected and that backup jobs create usable recovery points. Verify authorized recovery separately. Record node identity, registration evidence, and job results without exposing credentials. If backup fails only after takeover, inspect the node-specific key preparation before rebuilding unrelated backup policy.\n\n## Official references\n\n[Microsoft Learn: Back up SAP HANA System Replication databases on Azure VMs using Azure Backup](https://learn.microsoft.com/en-us/azure/backup/sap-hana-database-with-hana-system-replication-backup)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Prepare HANA backup keys on both replication nodes before takeover",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover/",
                "headline": "Prepare HANA backup keys on both replication nodes before takeover",
                "description": "Why can HANA user replication leave Azure Backup unable to use the new primary?",
                "abstract": "Why can HANA user replication leave Azure Backup unable to use the new primary?",
                "articleBody": "Source facts\nFor SAP HANA System Replication backup on Azure VMs, Microsoft distinguishes replicated users from hdbuserstore, which is not replicated during failover. The same backup key must be created on every HSR node. The preregistration procedure requires the same custom backup user, password, and stored key on both nodes. An expired custom backup-key password causes backup and restore failures. Both nodes must be physically and logically registered to the vault before a planned failover. Microsoft Learn.\nApplicability\nUse this check for the documented HSR pair in Azure. Verify the source’s same-region and same-subscription vault prerequisites; this is not a procedure for extending the pair to a third node in another region.\nDSE recommendation\nTreat backup credential preparation as a node-specific takeover prerequisite. Ask the HANA and backup owners to reconcile both nodes’ protected credential configuration and registration before the change window. Document the rotation process so a password change is not assumed to update every required store. Keep passwords out of tickets, screenshots, and ordinary runbook copies.\nVerification\nDuring an approved takeover rehearsal, confirm the new primary is selected and that backup jobs create usable recovery points. Verify authorized recovery separately. Record node identity, registration evidence, and job results without exposing credentials. If backup fails only after takeover, inspect the node-specific key preparation before rebuilding unrelated backup policy.\nOfficial references\nMicrosoft Learn: Back up SAP HANA System Replication databases on Azure VMs using Azure Backup.",
                "datePublished": "2026-09-10T00:29:47+00:00",
                "dateModified": "2026-09-10T00:52:38+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Prepare HANA backup keys on both replication nodes before takeover"
                },
                "articleSection": [
                    "Business Continuity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Business Continuity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 236,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Back up SAP HANA System Replication databases on Azure VMs using Azure Backup - Azure Backup | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/backup/sap-hana-database-with-hana-system-replication-backup"
                }
            }
        ]
    }
}