Do not equate a MARS volume snapshot with application-consistent backup

Does the MARS agent's use of VSS establish application-consistent recovery for the files it protects?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

Does the MARS agent's use of VSS establish application-consistent recovery for the files it protects?

Potentially affected

Identify the actual backup method for the workload, not just whether a VSS snapshot exists. Apply this limitation to the documented direct MARS path; do not generalize it to every Azure Backup workload or to MARS transporting a backup server's stored data.

DSE recommendation

Match the required application recovery behavior to the selected backup method before accepting coverage.

Source facts

For direct Windows file and folder protection, the MARS agent takes a point-in-time volume snapshot using VSS. Microsoft says it uses only the Windows system write operation, not application VSS writers, and therefore does not capture application-consistent snapshots. The same architecture guide distinguishes DPM/MABS protection of specific applications using application-aware backup settings. Microsoft Learn.

Applicability

Identify the actual backup method for the workload, not just whether a VSS snapshot exists. Apply this limitation to the documented direct MARS path; do not generalize it to every Azure Backup workload or to MARS transporting a backup server’s stored data.

DSE recommendation

Match the required application recovery behavior to the selected backup method before accepting coverage. Ask the application owner what must be consistent at recovery and which supported procedure establishes that result. Record whether the protected content is ordinary files or an active application’s data. If application consistency is required, evaluate the appropriate supported application-aware method rather than assuming the file agent supplies it. Keep existing protection in place while that assessment is completed.

Verification

Restore a representative protected dataset in an approved isolated environment and perform the application’s documented recovery checks. Preserve the chosen method and its consistency boundary with the result. A completed file restore should be recorded as such, not expanded into a claim that transaction state or application recovery requirements were satisfied without testing.

Official references

Microsoft Learn: Architecture Overview.

Primary reference

Review the official source

Architecture Overview - Azure Backup | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE