# Separate requester, writer, and provider roles when reviewing VSS backups

> Identify the VSS components involved in a shadow-copy operation and collect evidence from each role during backup verification.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-020-separate-requester-writer-and-provider-roles-when-reviewing-vss-backups/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:16:51+00:00
- Modified: 2026-09-08T18:17:13+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Explainer
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Identify the VSS components involved in a shadow-copy operation and collect evidence from each role during backup verification.

## Potentially affected

Administrators reviewing Windows backups that use Volume Shadow Copy Service.

## DSE recommendation

Map the actual backup requester, application writers, and shadow-copy provider before evaluating a VSS backup or failure.

## Article

## Source facts

[Microsoft’s VSS reference](https://learn.microsoft.com/en-us/windows-server/storage/file-server/volume-shadow-copy-service) separates three roles. A requester initiates shadow-copy operations and is commonly the backup application. A writer prepares a consistent application data set. A provider creates and maintains the shadow copy; that work can occur in software or storage hardware. VSS coordinates the components during shadow-copy creation.

## Applicability

Identify the backup product, protected applications, and storage arrangement actually in use. Check the relevant product documentation before assuming that a particular application supplies a writer or that a storage array supplies the selected provider. Keep this component review distinct from decisions about backup retention and recovery objectives.

## DSE recommendation

Create a short component map for each protected workload. Name the requester, required writers, selected provider, and administrator responsible for investigating each. During a failure review, preserve the original job details and timestamps before retrying. Ask which component reported the failure and which application data was included, rather than assigning every failure to the backup application by default.

## Verification

Record component status around a controlled backup and preserve the corresponding application and backup logs. Restore a representative data set through the approved recovery procedure and have the application owner validate it. Keep successful snapshot creation and successful application restoration as separate results in the evidence record. Document missing components or unexplained errors as unresolved findings.

## Official references

[Microsoft Learn: Volume Shadow Copy Service](https://learn.microsoft.com/en-us/windows-server/storage/file-server/volume-shadow-copy-service). Source reviewed September 8, 2026.

## Primary reference

- Name: Volume Shadow Copy Service (VSS)
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/storage/file-server/volume-shadow-copy-service
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate requester, writer, and provider roles when reviewing VSS backups,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-020-separate-requester-writer-and-provider-roles-when-reviewing-vss-backups/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
