# Prepare HANA backup keys on both replication nodes before takeover

> Why can HANA user replication leave Azure Backup unable to use the new primary?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:47+00:00
- Modified: 2026-09-10T00:52:38+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Why can HANA user replication leave Azure Backup unable to use the new primary?

## Potentially affected

Use this check for the documented HSR pair in Azure. Verify the source's same-region and same-subscription vault prerequisites; this is not a procedure for extending the pair to a third node in another region.

## DSE recommendation

Treat backup credential preparation as a node-specific takeover prerequisite.

## Article

## Source facts

For SAP HANA System Replication backup on Azure VMs, Microsoft distinguishes replicated users from hdbuserstore, which is not replicated during failover. The same backup key must be created on every HSR node. The preregistration procedure requires the same custom backup user, password, and stored key on both nodes. An expired custom backup-key password causes backup and restore failures. Both nodes must be physically and logically registered to the vault before a planned failover. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/backup/sap-hana-database-with-hana-system-replication-backup).

## Applicability

Use this check for the documented HSR pair in Azure. Verify the source’s same-region and same-subscription vault prerequisites; this is not a procedure for extending the pair to a third node in another region.

## DSE recommendation

Treat backup credential preparation as a node-specific takeover prerequisite. Ask the HANA and backup owners to reconcile both nodes’ protected credential configuration and registration before the change window. Document the rotation process so a password change is not assumed to update every required store. Keep passwords out of tickets, screenshots, and ordinary runbook copies.

## Verification

During an approved takeover rehearsal, confirm the new primary is selected and that backup jobs create usable recovery points. Verify authorized recovery separately. Record node identity, registration evidence, and job results without exposing credentials. If backup fails only after takeover, inspect the node-specific key preparation before rebuilding unrelated backup policy.

## Official references

[Microsoft Learn: Back up SAP HANA System Replication databases on Azure VMs using Azure Backup](https://learn.microsoft.com/en-us/azure/backup/sap-hana-database-with-hana-system-replication-backup).

## Primary reference

- Name: Back up SAP HANA System Replication databases on Azure VMs using Azure Backup - Azure Backup | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/backup/sap-hana-database-with-hana-system-replication-backup
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Prepare HANA backup keys on both replication nodes before takeover,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-129-prepare-hana-backup-keys-on-both-replication-nodes-before-takeover/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
