What you need to know
At what point must private access be designed for a new Site Recovery vault, and what traffic does the vault endpoint leave separate?
Potentially affected
Use this ordering check when designing a new privately connected recovery vault for on-premises machines. Identify the vault, cache storage, appliance connectivity, and identity-service access before any workload registration is scheduled.
DSE recommendation
Make private connectivity a creation prerequisite in the vault handoff checklist.
Source facts
For on-premises Site Recovery, private endpoints can be created only for a new Recovery Services vault with no registered items. Microsoft instructs operators to create those endpoints before adding items. Creating the vault endpoint restricts vault access to networks with private endpoints. A storage endpoint is separate: without it, protection can succeed while replication traffic uses public endpoints. Microsoft Entra ID also requires allowed outbound access rather than a private endpoint. Microsoft Learn.
Applicability
Use this ordering check when designing a new privately connected recovery vault for on-premises machines. Identify the vault, cache storage, appliance connectivity, and identity-service access before any workload registration is scheduled.
DSE recommendation
Make private connectivity a creation prerequisite in the vault handoff checklist. Require separate decisions for vault access and storage-data transport, with an accountable owner for each. Do not assume that an approved vault endpoint proves the data route is private. If the vault already contains registered items, pause this setup path and review the documented restriction rather than experimenting against the existing protection inventory.
Verification
Before adding workloads, verify the vault’s registration state and endpoint approval, then test the intended appliance route and identity access. Inspect the storage endpoint separately if private replication traffic is required. Record the observed destination and resolution from the actual replication path. Accept the design only when its control, data, and identity dependencies have each been accounted for.
Official references
Microsoft Learn: Enable replication for on-premises machines with private endpoints.
Review the official source
Enable replication for on-premises machines with private endpoints - Azure Site Recovery | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE