What you need to know
Which Network Controller state must an SDN maintenance recovery plan preserve?
Potentially affected
Administrators maintaining the multi-node SDN infrastructure described in Microsoft’s upgrade and recovery guidance.
DSE recommendation
Have the SDN owner identify the database backup artifact, protected destination, retention owner, and approved restore instructions.
Source facts
Microsoft’s SDN maintenance guidance distinguishes a Network Controller database backup from backups of the controller VMs. It states that VM backups alone do not ensure session continuity across multiple controller nodes. After upgrading a controller node, the procedure checks its status with Get-NetworkControllerNode and waits for Up before upgrading another node. Microsoft documentation.
Applicability
Identify the actual SDN architecture and releases and compare them with the documented procedure. Review the supported backup and restore process for that design before applying guidance from a different controller hosting model.
DSE recommendation
Have the SDN owner identify the database backup artifact, protected destination, retention owner, and approved restore instructions. Record controller node status before maintenance. Establish a pause condition if a node does not return to the expected state, and keep the backup decision separate from ordinary VM snapshot activity.
Verification
Verify that the intended backup operation completed and that its artifact can be located and checked. In an approved recovery exercise, validate the documented restoration path and representative network policy state. During maintenance, record each node’s return to service before proceeding and retain unexplained controller errors for investigation.
Official references
Microsoft Learn: Upgrade, backup, and restore SDN infrastructure. Source reviewed September 8, 2026.
Review the official source
Upgrade, backup, and restore SDN infrastructure · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE