Create Site Recovery private access before registering protected items

At what point must private access be designed for a new Site Recovery vault, and what traffic does the vault endpoint leave separate?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

At what point must private access be designed for a new Site Recovery vault, and what traffic does the vault endpoint leave separate?

Potentially affected

Use this ordering check when designing a new privately connected recovery vault for on-premises machines. Identify the vault, cache storage, appliance connectivity, and identity-service access before any workload registration is scheduled.

DSE recommendation

Make private connectivity a creation prerequisite in the vault handoff checklist.

Source facts

For on-premises Site Recovery, private endpoints can be created only for a new Recovery Services vault with no registered items. Microsoft instructs operators to create those endpoints before adding items. Creating the vault endpoint restricts vault access to networks with private endpoints. A storage endpoint is separate: without it, protection can succeed while replication traffic uses public endpoints. Microsoft Entra ID also requires allowed outbound access rather than a private endpoint. Microsoft Learn.

Applicability

Use this ordering check when designing a new privately connected recovery vault for on-premises machines. Identify the vault, cache storage, appliance connectivity, and identity-service access before any workload registration is scheduled.

DSE recommendation

Make private connectivity a creation prerequisite in the vault handoff checklist. Require separate decisions for vault access and storage-data transport, with an accountable owner for each. Do not assume that an approved vault endpoint proves the data route is private. If the vault already contains registered items, pause this setup path and review the documented restriction rather than experimenting against the existing protection inventory.

Verification

Before adding workloads, verify the vault’s registration state and endpoint approval, then test the intended appliance route and identity access. Inspect the storage endpoint separately if private replication traffic is required. Record the observed destination and resolution from the actual replication path. Accept the design only when its control, data, and identity dependencies have each been accounted for.

Official references

Microsoft Learn: Enable replication for on-premises machines with private endpoints.

Primary reference

Review the official source

Enable replication for on-premises machines with private endpoints - Azure Site Recovery | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE