{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items/",
        "slug": "dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items/"
        },
        "title": "Create Site Recovery private access before registering protected items",
        "summary": "At what point must private access be designed for a new Site Recovery vault, and what traffic does the vault endpoint leave separate?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:22:17+00:00",
        "modified_at": "2026-09-10T02:14:31+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 244,
        "potentially_affected": "Use this ordering check when designing a new privately connected recovery vault for on-premises machines. Identify the vault, cache storage, appliance connectivity, and identity-service access before any workload registration is scheduled.",
        "dse_recommendation": "Make private connectivity a creation prerequisite in the vault handoff checklist.",
        "primary_source": {
            "name": "Enable replication for on-premises machines with private endpoints - Azure Site Recovery | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/site-recovery/hybrid-how-to-enable-replication-private-endpoints",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>For on-premises Site Recovery, private endpoints can be created only for a new Recovery Services vault with no registered items. Microsoft instructs operators to create those endpoints before adding items. Creating the vault endpoint restricts vault access to networks with private endpoints. A storage endpoint is separate: without it, protection can succeed while replication traffic uses public endpoints. Microsoft Entra ID also requires allowed outbound access rather than a private endpoint. <a href=\"https://learn.microsoft.com/en-us/azure/site-recovery/hybrid-how-to-enable-replication-private-endpoints\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this ordering check when designing a new privately connected recovery vault for on-premises machines. Identify the vault, cache storage, appliance connectivity, and identity-service access before any workload registration is scheduled.</p>\n<h2>DSE recommendation</h2>\n<p>Make private connectivity a creation prerequisite in the vault handoff checklist. Require separate decisions for vault access and storage-data transport, with an accountable owner for each. Do not assume that an approved vault endpoint proves the data route is private. If the vault already contains registered items, pause this setup path and review the documented restriction rather than experimenting against the existing protection inventory.</p>\n<h2>Verification</h2>\n<p>Before adding workloads, verify the vault&#8217;s registration state and endpoint approval, then test the intended appliance route and identity access. Inspect the storage endpoint separately if private replication traffic is required. Record the observed destination and resolution from the actual replication path. Accept the design only when its control, data, and identity dependencies have each been accounted for.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/site-recovery/hybrid-how-to-enable-replication-private-endpoints\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Enable replication for on-premises machines with private endpoints</a>.</p>",
        "content_text": "Source facts\nFor on-premises Site Recovery, private endpoints can be created only for a new Recovery Services vault with no registered items. Microsoft instructs operators to create those endpoints before adding items. Creating the vault endpoint restricts vault access to networks with private endpoints. A storage endpoint is separate: without it, protection can succeed while replication traffic uses public endpoints. Microsoft Entra ID also requires allowed outbound access rather than a private endpoint. Microsoft Learn.\nApplicability\nUse this ordering check when designing a new privately connected recovery vault for on-premises machines. Identify the vault, cache storage, appliance connectivity, and identity-service access before any workload registration is scheduled.\nDSE recommendation\nMake private connectivity a creation prerequisite in the vault handoff checklist. Require separate decisions for vault access and storage-data transport, with an accountable owner for each. Do not assume that an approved vault endpoint proves the data route is private. If the vault already contains registered items, pause this setup path and review the documented restriction rather than experimenting against the existing protection inventory.\nVerification\nBefore adding workloads, verify the vault’s registration state and endpoint approval, then test the intended appliance route and identity access. Inspect the storage endpoint separately if private replication traffic is required. Record the observed destination and resolution from the actual replication path. Accept the design only when its control, data, and identity dependencies have each been accounted for.\nOfficial references\nMicrosoft Learn: Enable replication for on-premises machines with private endpoints.",
        "content_markdown": "## Source facts\n\nFor on-premises Site Recovery, private endpoints can be created only for a new Recovery Services vault with no registered items. Microsoft instructs operators to create those endpoints before adding items. Creating the vault endpoint restricts vault access to networks with private endpoints. A storage endpoint is separate: without it, protection can succeed while replication traffic uses public endpoints. Microsoft Entra ID also requires allowed outbound access rather than a private endpoint. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/site-recovery/hybrid-how-to-enable-replication-private-endpoints).\n\n## Applicability\n\nUse this ordering check when designing a new privately connected recovery vault for on-premises machines. Identify the vault, cache storage, appliance connectivity, and identity-service access before any workload registration is scheduled.\n\n## DSE recommendation\n\nMake private connectivity a creation prerequisite in the vault handoff checklist. Require separate decisions for vault access and storage-data transport, with an accountable owner for each. Do not assume that an approved vault endpoint proves the data route is private. If the vault already contains registered items, pause this setup path and review the documented restriction rather than experimenting against the existing protection inventory.\n\n## Verification\n\nBefore adding workloads, verify the vault’s registration state and endpoint approval, then test the intended appliance route and identity access. Inspect the storage endpoint separately if private replication traffic is required. Record the observed destination and resolution from the actual replication path. Accept the design only when its control, data, and identity dependencies have each been accounted for.\n\n## Official references\n\n[Microsoft Learn: Enable replication for on-premises machines with private endpoints](https://learn.microsoft.com/en-us/azure/site-recovery/hybrid-how-to-enable-replication-private-endpoints)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Create Site Recovery private access before registering protected items",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items/",
                "headline": "Create Site Recovery private access before registering protected items",
                "description": "At what point must private access be designed for a new Site Recovery vault, and what traffic does the vault endpoint leave separate?",
                "abstract": "At what point must private access be designed for a new Site Recovery vault, and what traffic does the vault endpoint leave separate?",
                "articleBody": "Source facts\nFor on-premises Site Recovery, private endpoints can be created only for a new Recovery Services vault with no registered items. Microsoft instructs operators to create those endpoints before adding items. Creating the vault endpoint restricts vault access to networks with private endpoints. A storage endpoint is separate: without it, protection can succeed while replication traffic uses public endpoints. Microsoft Entra ID also requires allowed outbound access rather than a private endpoint. Microsoft Learn.\nApplicability\nUse this ordering check when designing a new privately connected recovery vault for on-premises machines. Identify the vault, cache storage, appliance connectivity, and identity-service access before any workload registration is scheduled.\nDSE recommendation\nMake private connectivity a creation prerequisite in the vault handoff checklist. Require separate decisions for vault access and storage-data transport, with an accountable owner for each. Do not assume that an approved vault endpoint proves the data route is private. If the vault already contains registered items, pause this setup path and review the documented restriction rather than experimenting against the existing protection inventory.\nVerification\nBefore adding workloads, verify the vault’s registration state and endpoint approval, then test the intended appliance route and identity access. Inspect the storage endpoint separately if private replication traffic is required. Record the observed destination and resolution from the actual replication path. Accept the design only when its control, data, and identity dependencies have each been accounted for.\nOfficial references\nMicrosoft Learn: Enable replication for on-premises machines with private endpoints.",
                "datePublished": "2026-09-10T00:22:17+00:00",
                "dateModified": "2026-09-10T02:14:31+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Create Site Recovery private access before registering protected items"
                },
                "articleSection": [
                    "Business Continuity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Business Continuity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 244,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Enable replication for on-premises machines with private endpoints - Azure Site Recovery | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/site-recovery/hybrid-how-to-enable-replication-private-endpoints"
                }
            }
        ]
    }
}