# Identify whether a Hyper-V backup product uses host VSS or the WMI path

> Which Hyper-V backup interface and change-tracking model is a backup implementation using?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-135-identify-whether-a-hyper-v-backup-product-uses-host-vss-or-the-wmi-path/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:56+00:00
- Modified: 2026-09-08T18:23:27+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which Hyper-V backup interface and change-tracking model is a backup implementation using?

## Potentially affected

Administrators and developers reviewing Hyper-V backup implementations.

## DSE recommendation

Ask the backup owner or vendor to document the interface, reference-point lifecycle, and supported restore workflow.

## Article

## Source facts

Hyper-V supports host-side VM backup without requiring custom backup software inside each VM. Microsoft describes the host VSS writer as a small-scale approach that backs up the server’s VMs together. From Windows Server 2016, the Hyper-V WMI backup API uses reference points and resilient change tracking instead of host VSS, while still using VSS inside the guest for backup purposes. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/backup-approaches).

## Applicability

Identify the host release, backup product version, protected guests, and vendor-supported interface. Review the product’s guest consistency and data-reading behavior instead of inferring it from a generic statement that Hyper-V backup is supported.

## DSE recommendation

Ask the backup owner or vendor to document the interface, reference-point lifecycle, and supported restore workflow. Record how failures and stale tracking state are investigated. Keep the implementation decision separate from retention policy and the business recovery objective.

## Verification

Run a controlled backup and restore of a representative VM and verify the application’s recovered state. Preserve job and guest consistency evidence and compare the observed behavior with the product’s documented method. Resolve missing application data or uncertain tracking behavior before depending on the implementation for that workload.

## Official references

[Microsoft Learn: Hyper-V Backup Approaches](https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/backup-approaches). Source reviewed September 8, 2026.

## Primary reference

- Name: Hyper-V Backup Approaches
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/backup-approaches
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Identify whether a Hyper-V backup product uses host VSS or the WMI path,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-135-identify-whether-a-hyper-v-backup-product-uses-host-vss-or-the-wmi-path/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
