{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary/",
        "slug": "dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary/"
        },
        "title": "Check SQL replica versions before configuring backup without the primary",
        "summary": "When can Azure Backup protect an availability group without registering its primary node?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:29:03+00:00",
        "modified_at": "2026-09-10T00:55:36+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 228,
        "potentially_affected": "Use this review when planning a new availability-group backup configuration. Reconcile the complete replica inventory, detected versions, backup preference, policy type, and proposed vault registrations. Basic Availability Groups are excluded; changing existing node registration requires a separate review.",
        "dse_recommendation": "Record a replica-by-replica registration decision before configuring the new protection.",
        "primary_source": {
            "name": "Back up SQL Server always on availability groups - Azure Backup | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/backup/backup-sql-server-on-availability-groups",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>For SQL Server 2025 and later, Azure Backup can configure availability-group backups using registered secondary nodes when the preference is Secondary Only or Prefer Secondary. A Primary preference still requires the primary node. If any replica runs SQL Server 2022 or earlier, the primary-registration requirement remains. Snapshot backup also requires primary registration regardless of SQL Server version. <a href=\"https://learn.microsoft.com/en-us/azure/backup/backup-sql-server-on-availability-groups\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review when planning a new availability-group backup configuration. Reconcile the complete replica inventory, detected versions, backup preference, policy type, and proposed vault registrations. Basic Availability Groups are excluded; changing existing node registration requires a separate review.</p>\n<h2>DSE recommendation</h2>\n<p>Record a replica-by-replica registration decision before configuring the new protection. Ask the database and backup owners to reconcile discovered versions with the intended preference. Include the snapshot setting explicitly. Defer configuration when discovery is incomplete or a required node is absent. Keep this eligibility assessment separate from any proposal to unregister a currently protected node; do not use the upgrade milestone as authorization for that operation.</p>\n<h2>Verification</h2>\n<p>Use a controlled group to inspect discovery, registered nodes, policy, and actual backup execution. Exercise the intended preference and validate the resulting recovery point. Record which replica performed each backup type. Recheck eligibility after topology or policy changes, and handle any proposed cross-vault design as a separate coordination review.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/backup/backup-sql-server-on-availability-groups\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Back up SQL Server always on availability groups</a>.</p>",
        "content_text": "Source facts\nFor SQL Server 2025 and later, Azure Backup can configure availability-group backups using registered secondary nodes when the preference is Secondary Only or Prefer Secondary. A Primary preference still requires the primary node. If any replica runs SQL Server 2022 or earlier, the primary-registration requirement remains. Snapshot backup also requires primary registration regardless of SQL Server version. Microsoft Learn.\nApplicability\nUse this review when planning a new availability-group backup configuration. Reconcile the complete replica inventory, detected versions, backup preference, policy type, and proposed vault registrations. Basic Availability Groups are excluded; changing existing node registration requires a separate review.\nDSE recommendation\nRecord a replica-by-replica registration decision before configuring the new protection. Ask the database and backup owners to reconcile discovered versions with the intended preference. Include the snapshot setting explicitly. Defer configuration when discovery is incomplete or a required node is absent. Keep this eligibility assessment separate from any proposal to unregister a currently protected node; do not use the upgrade milestone as authorization for that operation.\nVerification\nUse a controlled group to inspect discovery, registered nodes, policy, and actual backup execution. Exercise the intended preference and validate the resulting recovery point. Record which replica performed each backup type. Recheck eligibility after topology or policy changes, and handle any proposed cross-vault design as a separate coordination review.\nOfficial references\nMicrosoft Learn: Back up SQL Server always on availability groups.",
        "content_markdown": "## Source facts\n\nFor SQL Server 2025 and later, Azure Backup can configure availability-group backups using registered secondary nodes when the preference is Secondary Only or Prefer Secondary. A Primary preference still requires the primary node. If any replica runs SQL Server 2022 or earlier, the primary-registration requirement remains. Snapshot backup also requires primary registration regardless of SQL Server version. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/backup/backup-sql-server-on-availability-groups).\n\n## Applicability\n\nUse this review when planning a new availability-group backup configuration. Reconcile the complete replica inventory, detected versions, backup preference, policy type, and proposed vault registrations. Basic Availability Groups are excluded; changing existing node registration requires a separate review.\n\n## DSE recommendation\n\nRecord a replica-by-replica registration decision before configuring the new protection. Ask the database and backup owners to reconcile discovered versions with the intended preference. Include the snapshot setting explicitly. Defer configuration when discovery is incomplete or a required node is absent. Keep this eligibility assessment separate from any proposal to unregister a currently protected node; do not use the upgrade milestone as authorization for that operation.\n\n## Verification\n\nUse a controlled group to inspect discovery, registered nodes, policy, and actual backup execution. Exercise the intended preference and validate the resulting recovery point. Record which replica performed each backup type. Recheck eligibility after topology or policy changes, and handle any proposed cross-vault design as a separate coordination review.\n\n## Official references\n\n[Microsoft Learn: Back up SQL Server always on availability groups](https://learn.microsoft.com/en-us/azure/backup/backup-sql-server-on-availability-groups)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check SQL replica versions before configuring backup without the primary",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary/",
                "headline": "Check SQL replica versions before configuring backup without the primary",
                "description": "When can Azure Backup protect an availability group without registering its primary node?",
                "abstract": "When can Azure Backup protect an availability group without registering its primary node?",
                "articleBody": "Source facts\nFor SQL Server 2025 and later, Azure Backup can configure availability-group backups using registered secondary nodes when the preference is Secondary Only or Prefer Secondary. A Primary preference still requires the primary node. If any replica runs SQL Server 2022 or earlier, the primary-registration requirement remains. Snapshot backup also requires primary registration regardless of SQL Server version. Microsoft Learn.\nApplicability\nUse this review when planning a new availability-group backup configuration. Reconcile the complete replica inventory, detected versions, backup preference, policy type, and proposed vault registrations. Basic Availability Groups are excluded; changing existing node registration requires a separate review.\nDSE recommendation\nRecord a replica-by-replica registration decision before configuring the new protection. Ask the database and backup owners to reconcile discovered versions with the intended preference. Include the snapshot setting explicitly. Defer configuration when discovery is incomplete or a required node is absent. Keep this eligibility assessment separate from any proposal to unregister a currently protected node; do not use the upgrade milestone as authorization for that operation.\nVerification\nUse a controlled group to inspect discovery, registered nodes, policy, and actual backup execution. Exercise the intended preference and validate the resulting recovery point. Record which replica performed each backup type. Recheck eligibility after topology or policy changes, and handle any proposed cross-vault design as a separate coordination review.\nOfficial references\nMicrosoft Learn: Back up SQL Server always on availability groups.",
                "datePublished": "2026-09-10T00:29:03+00:00",
                "dateModified": "2026-09-10T00:55:36+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check SQL replica versions before configuring backup without the primary"
                },
                "articleSection": [
                    "Business Continuity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Business Continuity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 228,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Back up SQL Server always on availability groups - Azure Backup | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/backup/backup-sql-server-on-availability-groups"
                }
            }
        ]
    }
}