# List excluded data before approving an Azure VM restore-point plan

> Which disks and mounted data remain outside a proposed Azure VM restore point?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-038-list-excluded-data-before-approving-an-azure-vm-restore-point-plan/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:31:18+00:00
- Modified: 2026-09-10T00:32:00+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Checklist
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Which disks and mounted data remain outside a proposed Azure VM restore point?

## Potentially affected

Teams evaluating Azure VM restore points against a workload's disk and mounted-data inventory.

## DSE recommendation

Create a coverage map that names every excluded disk or data path before approving the restore-point design.

## Article

## Source facts

Azure VM restore points support managed disks, but not ephemeral OS disks or shared disks. Ultra Disks and Premium SSD v2 support application-consistent restore points, not crash-consistent ones. Temporary-disk contents are absent from restore points. Microsoft also excludes mounted NFS files: restore points cover locally attached VM disks rather than data from an NFS server. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/concepts-restore-points).

## Applicability

Review the actual VM architecture, operating system, orchestration mode, consistency choice, and disk types against the full support matrix. Identify application data reached through mounts as well as data on attached disks. Do not assume that a VM-level label establishes coverage for every path the application uses.

## DSE recommendation

Create a coverage map that names every excluded disk or data path before approving the restore-point design. Have the workload owner classify each item as reproducible, protected through another approved mechanism, or an unresolved recovery gap. Choose the required consistency mode with that owner rather than selecting it solely because a restore-point request is available in the interface.

## Verification

For an approved test workload, reconcile the created restore point with the intended disk inventory and exclusions. Restore the covered data into a permitted test context and exercise the application against the separately recovered dependencies. Record missing data as a coverage defect, even if the restore-point operation itself succeeded. Keep the matrix decision and the recovery evidence together when accepting or rejecting the proposed protection plan.

## Official references

[Microsoft Learn: Support matrix for VM restore points](https://learn.microsoft.com/en-us/azure/virtual-machines/concepts-restore-points). Source reviewed September 9, 2026.

## Primary reference

- Name: Support matrix for VM restore points - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/concepts-restore-points
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “List excluded data before approving an Azure VM restore-point plan,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-038-list-excluded-data-before-approving-an-azure-vm-restore-point-plan/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
