# Check SQL replica versions before configuring backup without the primary

> When can Azure Backup protect an availability group without registering its primary node?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:03+00:00
- Modified: 2026-09-10T00:55:36+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

When can Azure Backup protect an availability group without registering its primary node?

## Potentially affected

Use this review when planning a new availability-group backup configuration. Reconcile the complete replica inventory, detected versions, backup preference, policy type, and proposed vault registrations. Basic Availability Groups are excluded; changing existing node registration requires a separate review.

## DSE recommendation

Record a replica-by-replica registration decision before configuring the new protection.

## Article

## Source facts

For SQL Server 2025 and later, Azure Backup can configure availability-group backups using registered secondary nodes when the preference is Secondary Only or Prefer Secondary. A Primary preference still requires the primary node. If any replica runs SQL Server 2022 or earlier, the primary-registration requirement remains. Snapshot backup also requires primary registration regardless of SQL Server version. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/backup/backup-sql-server-on-availability-groups).

## Applicability

Use this review when planning a new availability-group backup configuration. Reconcile the complete replica inventory, detected versions, backup preference, policy type, and proposed vault registrations. Basic Availability Groups are excluded; changing existing node registration requires a separate review.

## DSE recommendation

Record a replica-by-replica registration decision before configuring the new protection. Ask the database and backup owners to reconcile discovered versions with the intended preference. Include the snapshot setting explicitly. Defer configuration when discovery is incomplete or a required node is absent. Keep this eligibility assessment separate from any proposal to unregister a currently protected node; do not use the upgrade milestone as authorization for that operation.

## Verification

Use a controlled group to inspect discovery, registered nodes, policy, and actual backup execution. Exercise the intended preference and validate the resulting recovery point. Record which replica performed each backup type. Recheck eligibility after topology or policy changes, and handle any proposed cross-vault design as a separate coordination review.

## Official references

[Microsoft Learn: Back up SQL Server always on availability groups](https://learn.microsoft.com/en-us/azure/backup/backup-sql-server-on-availability-groups).

## Primary reference

- Name: Back up SQL Server always on availability groups - Azure Backup | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/backup/backup-sql-server-on-availability-groups
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check SQL replica versions before configuring backup without the primary,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-173-check-sql-replica-versions-before-configuring-backup-without-the-primary/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
