Prepare HANA backup keys on both replication nodes before takeover

Why can HANA user replication leave Azure Backup unable to use the new primary?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

Why can HANA user replication leave Azure Backup unable to use the new primary?

Potentially affected

Use this check for the documented HSR pair in Azure. Verify the source's same-region and same-subscription vault prerequisites; this is not a procedure for extending the pair to a third node in another region.

DSE recommendation

Treat backup credential preparation as a node-specific takeover prerequisite.

Source facts

For SAP HANA System Replication backup on Azure VMs, Microsoft distinguishes replicated users from hdbuserstore, which is not replicated during failover. The same backup key must be created on every HSR node. The preregistration procedure requires the same custom backup user, password, and stored key on both nodes. An expired custom backup-key password causes backup and restore failures. Both nodes must be physically and logically registered to the vault before a planned failover. Microsoft Learn.

Applicability

Use this check for the documented HSR pair in Azure. Verify the source’s same-region and same-subscription vault prerequisites; this is not a procedure for extending the pair to a third node in another region.

DSE recommendation

Treat backup credential preparation as a node-specific takeover prerequisite. Ask the HANA and backup owners to reconcile both nodes’ protected credential configuration and registration before the change window. Document the rotation process so a password change is not assumed to update every required store. Keep passwords out of tickets, screenshots, and ordinary runbook copies.

Verification

During an approved takeover rehearsal, confirm the new primary is selected and that backup jobs create usable recovery points. Verify authorized recovery separately. Record node identity, registration evidence, and job results without exposing credentials. If backup fails only after takeover, inspect the node-specific key preparation before rebuilding unrelated backup policy.

Official references

Microsoft Learn: Back up SAP HANA System Replication databases on Azure VMs using Azure Backup.

Primary reference

Review the official source

Back up SAP HANA System Replication databases on Azure VMs using Azure Backup - Azure Backup | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE