# Treat SQL backup discovery as a VM registration change

> Starting discovery from a Recovery Services vault changes workload registration and installs backup components.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-351-treat-sql-backup-discovery-as-a-vm-registration-change/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:05+00:00
- Modified: 2026-09-10T02:01:55+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Starting discovery from a Recovery Services vault changes workload registration and installs backup components.

## Potentially affected

SQL Server databases on Azure VMs being discovered for Recovery Services vault backup.

## DSE recommendation

Confirm the destination vault and required service identity before starting database discovery.

## Article

## Source facts

During SQL database discovery, Azure Backup registers the VM with the Recovery Services vault; all databases on that registered VM can be protected only in that vault.

Discovery also installs AzureBackupWindowsWorkload and creates NT Service\AzureWLBackupPluginSvc. That account performs backup and restore operations and requires SQL sysadmin permissions. The source describes using the SQL IaaS extension to obtain those permissions on Marketplace SQL Server VMs. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/backup/backup-sql-server-database-azure-vms).

## Applicability

Identify the VM by resource group as well as name, its intended vault, existing protection, and SQL instance owners. Review the source’s connectivity and permission prerequisites before starting discovery. Do not present the action to an application owner as a passive inventory scan.

## DSE recommendation

DSE recommends approving the VM-to-vault association before initiating discovery. Have the SQL and backup administrators agree how the required service permissions will be established and reviewed. Preserve the prior protection state and record any existing backup arrangements that need separate assessment; do not disable them merely to complete an inventory request.

## Verification

On an authorized representative VM, inspect the resulting vault registration, workload extension, discovered databases, and service-account permissions. Compare them with the approved mapping. Treat discovery success as completion of that stage only, then separately validate the intended protection configuration and a representative recovery before calling the database protected.

## Official references

[Microsoft Learn: Back up multiple SQL Server VMs from the vault](https://learn.microsoft.com/en-us/azure/backup/backup-sql-server-database-azure-vms). Source retrieved September 9, 2026.

## Primary reference

- Name: Back up multiple SQL Server VMs from the vault - Azure Backup | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/backup/backup-sql-server-database-azure-vms
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Treat SQL backup discovery as a VM registration change,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-351-treat-sql-backup-discovery-as-a-vm-registration-change/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
