# Create Site Recovery private access before registering protected items

> At what point must private access be designed for a new Site Recovery vault, and what traffic does the vault endpoint leave separate?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:17+00:00
- Modified: 2026-09-10T02:14:31+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

At what point must private access be designed for a new Site Recovery vault, and what traffic does the vault endpoint leave separate?

## Potentially affected

Use this ordering check when designing a new privately connected recovery vault for on-premises machines. Identify the vault, cache storage, appliance connectivity, and identity-service access before any workload registration is scheduled.

## DSE recommendation

Make private connectivity a creation prerequisite in the vault handoff checklist.

## Article

## Source facts

For on-premises Site Recovery, private endpoints can be created only for a new Recovery Services vault with no registered items. Microsoft instructs operators to create those endpoints before adding items. Creating the vault endpoint restricts vault access to networks with private endpoints. A storage endpoint is separate: without it, protection can succeed while replication traffic uses public endpoints. Microsoft Entra ID also requires allowed outbound access rather than a private endpoint. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/site-recovery/hybrid-how-to-enable-replication-private-endpoints).

## Applicability

Use this ordering check when designing a new privately connected recovery vault for on-premises machines. Identify the vault, cache storage, appliance connectivity, and identity-service access before any workload registration is scheduled.

## DSE recommendation

Make private connectivity a creation prerequisite in the vault handoff checklist. Require separate decisions for vault access and storage-data transport, with an accountable owner for each. Do not assume that an approved vault endpoint proves the data route is private. If the vault already contains registered items, pause this setup path and review the documented restriction rather than experimenting against the existing protection inventory.

## Verification

Before adding workloads, verify the vault’s registration state and endpoint approval, then test the intended appliance route and identity access. Inspect the storage endpoint separately if private replication traffic is required. Record the observed destination and resolution from the actual replication path. Accept the design only when its control, data, and identity dependencies have each been accounted for.

## Official references

[Microsoft Learn: Enable replication for on-premises machines with private endpoints](https://learn.microsoft.com/en-us/azure/site-recovery/hybrid-how-to-enable-replication-private-endpoints).

## Primary reference

- Name: Enable replication for on-premises machines with private endpoints - Azure Site Recovery | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/site-recovery/hybrid-how-to-enable-replication-private-endpoints
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Create Site Recovery private access before registering protected items,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-579-create-site-recovery-private-access-before-registering-protected-items/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
