You are browsing the archive for Azure Backup.

Azure Backup: Create a Recovery Services vault with Azure PowerShell

9:46 am in Azure, Azure Backup, Azure PowerShell, PowerShell, Public Cloud, Recovery Services vault by Wim Matthyssen

A Recovery Services vault is an online storage entity used to backup workloads to the Azure cloud. You can use it to hold backup data for various Azure services such as IaaS VMs (Linux or Windows) and Azure SQL databases, but it can also be used by System Center Data Protection Manager (SCDPM) or Azure Backup Server (MABS v1 and MABS v2) to enable cloud backups.


These days it is quite easy to create or manage a Recovery Services vault through the Azure portal, but it is even faster when you make use of a scripting language like Azure PowerShell to automate the setup. Therefore, below you can find the PowerShell script I mostly use to do all the work for me. You can just copy and paste or you can download the complete script (.ps1) from the Microsoft TechNet gallery.

To use the script, first adjust all variables to your use. Afterwards login into an Azure PowerShell window as an administrator and when asked login with the credentials for your Azure Subscription.

The script will first create a Resource Group and then the Recovery Services vault in your Azure Subscription. At the end, it will also set the storage redundancy for the newly created vault. Keep in mind that you can only use Locally Redundant Storage (LRS) or Geo Redundant Storage (GRS).




Useful Azure PowerShell cmdlets for Azure Backup

List all available Azure Backup PowerShell cmdlets


List all available Recovery Services vaults in your subscription


Hope this post helps you when you start using Azure Backup.

Wim Matthyssen (@wmatthyssen)

MABS: DPM database size has exceeded the threshold limit (ID 3168)

10:18 am in Azure, Azure Backup, DPM database, ID 3168, MABS, Microsoft Azure Backup Server by Wim Matthyssen

Last week I saw the below Warning message pop up at a customer’s Microsoft Azure Backup Server (MABS). The description of this Warning message described the following:

“DPM database size has exceeded the threshold limit.

DPM database size: 1.15 GB

DPM database location: e:\DPMDB\ on “servername” (ID 3168)”


I could also find the same Warning message in the Event Viewer.


The message itself was confusing because the E: drive where the DPM database is located had plenty of free disk space and the DPM Database size alert was unmarked as you can see in the below screenshots.



Another important point is that the only way to open the Tape Catalog Retention box (on a MABS server) is by clicking the Modify Catalog Alert Threshold size … link which is only show in the Recommended action field of the warning message itself.


However, in the end I was able to solve this warning, by marking the setting Alert me when DPM database size reaches: and changing the size to 10 GB. Afterwards I unmarked this setting again and pressed OK. Almost directly after that, the Warning message disappeared.




Probably this warning message is some sort of bug in the MABS software or some kind of leftover from DPM 2012 (tape backups) on which the MABS v1 code is based. For the moment, the only way to get rid of this Warning message is by using the above workaround.

If you have any questions, feel free to contact me through my twitter handle.

Wim Matthyssen (@wmatthyssen)

Microsoft Azure Backup Server: Unable to configure protection for a SQL database (ID 3170 and 33424)

2:45 pm in Azure, Azure Backup, ID 3170, ID 33424, MABS, Microsoft Azure Backup Server, SQL Server by Wim Matthyssen

Last week while configuring backup for some SQL databases for a customer with the Microsoft Azure Backup Server (MABS), I received the following Protection Status error: Unable to configure protection.


When opening the Monitoring tab on the MABS server, to investigate the problem, I found the following description for the error:

DPM could not start a recovery, consistency check, or initial replica creation job for SQL Server 2012 database “SQLServername\model” on “SQL Server” for following reason: (ID 3170)

The DPM job failed for SQL Server 2012 database “SQLServername\model” on “SQL Server” because the protection agent did not have sysadmin privileges on the SQL Server instance. (ID 33424 Details:)


You can also find the similar error description in the Event Viewer on the MABS server, by opening the Application and Services LogsDPM Alerts.


As the error suggests, the problem is that the built-in NT Authority\SYSTEM does not have sysadmin rights on that SQL Server instance. So to resolve this issue, perform the following steps. Open Microsoft SQL Server Management Studio on the SQL server. Open Security, open Logins, select the NT\AUTHORITY SYSTEM user and click Properties. In the Server Roles screen sysadmin should be checked, what for this specific database was not the case. So check sysadmin and press OK to save. You need to repeat this step for all instances having this problem.



After fixing this, you need to perform a consistency check on the MABS for all those databases with status Unable to configure protection. To do so right-click the unprotected database and select Perform consistency check …, which will retry the protection and solve the problem.


After completion, the Protection Status should be showing OK.


Hope this helps you fixing this problem when it occurs. If you have, any questions feel free to contact me through my twitter handle.

Wim Matthyssen (@wmatthyssen)

How to install Microsoft Azure Backup Server v2 on Windows Server 2016

7:53 pm in Azure, Azure Backup, Hybrid backup, MABS, MABS v2, Microsoft Azure Backup, Microsoft Azure Backup Server, Microsoft Azure Backup Server v2, Modern Backup Storage, PowerShell, Windows Server 2016 by Wim Matthyssen

Last week Microsoft released the second version (v2) of their Microsoft Azure Backup Server (MABS v2). As a hybrid backup solution, this new release based on System Center Data Protection Manager 2016 (SCDPM 2016) enables you to store data onto disk (low RTO) and in Azure (long retention, up to 99 years). MABS v2 uses RCT-based change tracking by using Windows Server 2016. This makes backups more reliable and scalable, but also improves backup performance (backup jobs could be up to 70 percent faster). MABS v2, which is included with the Azure Backup service and currently has version number 12.0.332.0., now not only supports Windows Server 2016 (W2K16) but also vSphere 6.5 (Preview mode). Beside those, you can also use it now to backup business critical Microsoft workloads such as SQL 2016, SharePoint 2016 and Exchange 2016. Those can be running on premise (physical servers, Hyper-V or VMware) or in the Azure cloud. As a nice extra, you can also back up Windows 10 client workloads.


In a previous blog post, I already told you all about MABS v1 on how to install it on a Windows Server 2012 R2. In this blog post, I will show you how you can deploy MABS v2 on a W2K16 server.

MABS v2 server requirements

  • MABS v2 can be installed as an on premise standalone physical server or VM, but also as an Azure IaaS VM (minimum size A2 Standard).
  • MABS v2 will run on following supported Operating Systems: Windows Server 2012 R2 and Windows Server 2016 (is required if you want to use the Modern Backup Storage feature).
  • MABS v2 must be domain joined. Be sure to add the server to the domain before the MABS installation. Microsoft does not support adding this server to the domain after the MABS installation.
  • The processor minimum requirements for a MABS v2 server are 1GHz dual-core CPU, recommended 2.33 GHz quad-core CPU.
  • The minimum RAM needed by a MABS v2 server is 4GB, recommended is 8 GB.
  • The recommended hard drive space is 3 GB.
  • MABS v2 must have .NET 3.5 SP1, .NET 4.6.1 features installed as a prerequisite.
  • MABS v2 should also have Hyper-V PowerShell installed.
  • MABS v2 should be running a dedicated, single-purpose server. Either it cannot be running on the same server, which has SCDPM or a SCDPM agent installed.
  • A validate Windows Server license is needed for the MABS v2 server.
  • The MABS v2 server needs to have access to the Internet because Microsoft Azure should be accessible from the MABS server.
  • To temporarily store, the largest restore from the Azure cloud, some scratch space is required when needed. So keep approximately 5 % of the total amount of data that needs to be backed-up to the cloud free on the C: drive.
  • A separate data disk for the backup storage pool is required. Like every other backup product the recommendation for the size of this disk is 1.5 times the size of the data you are going to protect.

MABS v2 prerequisites installation

Before we start the prerequisites installation, be shore to have a Recovery Services vault in place (create a new one, or use an existing) and download the vault credentials. When downloaded, place this file on the C:\Temp folder of the MABS server.



To install all required prerequisites, logon to the server you wish to use for your MABS v2 installation, open PowerShell and administrator and run the following commands to install .NET 3.5 SP1 and Hyper-V PowerShell (be shore to have the Windows Server 2016 installation ISO mounted – in my example to the D: drive). Be aware the server will reboot when the installation is completed. You can also download the complete script (.ps1) from the Microsoft TechNet Gallery.


MABS v2 software download

To download the MABS v2 software open PowerShell as an administrator and run the following PowerShell script. You can download the complete script (.ps1) from the Microsoft TechNet gallery. The script will download all the necessary files (8 files), extract them and start the setup.

MABS v2 installation

Click Microsoft Azure Backup Server to launch the setup wizard.


Setup will start copying some temporary files.


On the Welcome screen, click the Next.

This opens up the Prerequisite Check section. On this screen, click on the Check button to determine if the hardware and software prerequisites for Azure Backup Server have been met. If all of is OK, you will see a message indicating that the machine meets the requirements. Click Next.


On the SQL Settings page select, Install new Instance of SQL Server with this Setup, to install SQL 2016 SP1. Click Check and Install. You could encounter some error messages. If so follow the instructions and most likely, you should reboot the server and start the MABS installation all over again.


If the computer meets, the software and hardware requirements click Next.


Provide a location for the installation of all the files and click Next. In my example, I changed all locations to my E: drive.

Provide a strong password for restricted local user accounts (this password will not expire) and click Next.

It is strongly recommended to use Microsoft update when you check for updates because this will offer all security and important updates for MABS. Select whether to use Microsoft Update or not and click Next.


Review all settings and if all are OK click Install.



Click Next to start the Microsoft Azure Recovery Service Agent installation.


Click Install.



When the agent installation is completed, click Next.


Provide your vault credentials to register the machine to the Azure backup vault. Click Next.

Provide a passphrase to encrypt/decrypt the data sent between Azure and your premises. You can automatically generate a passphrase or provide your own minimum 16-character passphrase. Also, enter a location to save the passphrase. If all is done click Next.


Once registration succeeded the wizard proceeds with the installation and configuration of SQL Server 2016 SP1. This could take some time.



It is possible that you receive the following error message, if so just click OK (you can change the staging area after the MABS setups completes).

When setup completes successfully, click Close.

Double click the Microsoft Azure Backup server icon on your desktop to launch MABS.



You can also verify if the MABS server connection to the Recovery Services vault. To do so go to your Recovery Services vault, click Overview and click Backup management servers. There you should see the newly installed MABS server.


As a final step, do not forget to run Windows update to install all necessary updates after the MABS installation.


Now you are ready to start working with this brand new product. Have fun and till next time!

Wim Matthyssen (@wmatthyssen)

New features for Azure Backup and Azure Site Recovery released

10:02 am in Azure, Azure Backup, Azure Site Recovery, Cloud, Modern Backup Storage, Windows Server 2016 by Wim Matthyssen

Microsoft was very busy on the last day of May, because yesterday they launched many new features, not only for Azure Backup but also for Azure Site Recovery. I tried to list some of them below.

Azure Backup

  • Windows Server System State backups with Azure Backup now in public preview

This new extension allows the Azure Backup agent (MARS Agent) to integrate with the Windows Server Backup feature that is available natively on every Windows Server. It allows and provides seamless and secure backups of your Windows Server System State directly to Azure without the need to provision any on-premises infrastructure.

You can read more about it here



  • Microsoft Azure Backup Server v2 released which allows Windows Server 2016 and vCenter/ESXi 6.5 protection

This week Microsoft also released the second version (v2) of their Microsoft Azure Backup Server (MABS v2), which supports Windows Server 2016, vSphere 6.5 and the latest business critical applications such as SQL 2016, SharePoint 2016 and Exchange 2016. This new version is available for download from a Recovery Services vault in the Azure Portal or directly from here.



If you are interested to read more about MABS v2 you can do so over here

An important remark to make is that when you install MABS v2 on a Windows Server 2016 the VMware protection will be in preview mode, because VMware first needs to release support for VDDK 6.5.

In addition, the UserVoice I opened to address this issue to the Azure Team will be closed, so everyone who voted will get some votes back.

  • Introducing Modern Backup Storage with Azure Backup Server on Windows Server 2016

With the latest release of Azure Backup Server (MABS v2), which is based on System Center Data Protection Manager 2016 (SCDPM 2016), Modern Backup Storage can be used. This technology will improve performance and reduces consumption (50 % disk storage savings and 3x faster backups) by leveraging ReFS block cloning and deduplication.



You can read more about it here


Azure Site Recovery

  • Disaster recovery for Azure IaaS virtual machines with Azure Site Recovery is now in public preview

This will allow you to use Azure Site Recovery (ASR) to easily replicate and protect IaaS based applications running on Azure to a different Azure region of your choice without deploying any additional infrastructure components or software appliances in your subscription.



You can read more about it here


Enjoy reading about these nice new features and have fun testing them out.

Wim Matthyssen (@wmatthyssen)

Microsoft Azure Backup Server: Anti-Virus Exclusions

1:05 pm in Anti-Virus Exclusions, Azure, Azure Backup, Cloud, hybrid cloud, MABS, Microsoft Azure Backup Server by Wim Matthyssen

Running a solid, constantly updated antivirus product on your servers is a necessity to keep a healthy and secure server environment. However, with installing an antivirus product, you also risk having issues with certain workloads and services on those severs. Just like System Center Data Protection Manager (SCDPM), the Microsoft Azure Backup Server (MABS) is compatible with most antivirus software products. Though, the implemented antivirus product can also affect MABS performance and, if not configured properly, can cause data corruption of replicas and recovery points.


So, to avoid file conflicts and to minimize performance degradation between your MABS server and the antivirus software running on top of it, you should disable real-time monitoring by the antivirus software for all of the following processes and directories, which are listed below.

MABS processes to exclude from antivirus real-time monitoring

For information about configuring real-time monitoring based on process name or folder name, check the documentation of your antivirus vendor.

  • DPMRA.exe (*full path: C:\Program Files\Microsoft Azure Backup\DPM\DPM\bin\DPMRA.exe)
  • csc.exe  (*full path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe -> you can also exclude csc.exe in all the other Microsoft.NET Framework folders)
  • cbengine.exe (*full path: C:\Program Files\Microsoft Azure Backup\DPM\MARS\Microsoft Azure Recovery Services Agent\bin\cbengine.exe)






MABS directories in the MABS Program Files folder to exclude from antivirus real-time monitoring

Be aware that when you installed MABS on another drive then “C:”, like in the example below, look under the correct drive for the folders to exclude.

  • C:\Program Files\Microsoft Azure Backup\DPM\DPM\Temp\MTA\*
  • C:\Program Files\Microsoft Azure Backup\DPM\DPM\XSD\*
  • C:\Program Files\Microsoft Azure Backup\DPM\DPM\bin
  • C:\Program Files\Microsoft Azure Backup\DPM\MARS\Microsoft Azure Recovery Services Agent\bin
  • C:\Program Files\Microsoft Azure Backup\DPM\DPM\Cache (*MABS scratch folder)








Delete infected files on the MABS server

As a final remark, I would also advise to configure to delete infected files by default on the MABS server rather than automatically cleaning or quarantining them. Automatic cleaning and quarantining can result in data corruption because these processes cause the antivirus software to modify files, making changes MABS cannot detect.


In summary, there are a lot of antivirus settings you should keep track of when running MABS. I’ve tried to list all of the exclusions, so hopefully it will help you with getting the most out of your MABS setup. If you have any questions, feel free to contact me through my Twitter handle.

Wim Matthyssen (@wmatthyssen)

Microsoft Azure Backup Server: Error when installing on Windows Server 2016 – The Single Instance Store (SIS) component is not installed

3:36 pm in Azure, Azure Backup, hybrid cloud, MABS, Microsoft Azure Backup, Microsoft Azure Backup Server, PowerShell, Public Cloud, SIS, SIS-Limited, Windows Server 2016, WS2016 by Wim Matthyssen

Hi All,

Last week I was contacted by a customer who tried to install Microsoft Azure Backup Server (MABS) on an on-premise Windows Server 2016. However, when he started the installation he always received an error because a prerequisite was not installed, namely the Single Instance Store (SIS) component.


When opening the DpmSetup.log with PowerShell (as Administrator), you could see the following error:



However, when you try to install this missing component through PowerShell it gives you an Error: 0x800f080cFeature name SIS-Limited is unknown.


The reason for this is that because from Windows Server 2016 the SIS-Limited component is replaced by Microsoft’s deduplication or data footprint reduction (DFR) technology, like you can read in the following article from MVP Greg Schulz:

Also, when you go to the Microsoft Azure Backup Server download page and you expand System Requirements you can see that Windows Server 2016 at the present time is not listed as a supported Operating System (OS) to deploy MABS, probably because it does not have this SIS component.



Currently you’re not able to use Windows Server 2016 as OS for you MABS server. Probably in the near future Microsoft will release a new version of MABS which will allow it, but until then you need to stick with Windows Server 2012 (R2) or Windows Server 2008 R2 to install your MABS on.

Hope this helps you with this error.

Wim Matthyssen (@wmatthyssen)

2016: My blog year in an overview

2:37 pm in Azure, Azure Backup, Azure RemoteApp, Client Hyper-V, Cloud, DC, Hyper-V, IaaS, PowerShell, Private Cloud, Public Cloud, Replica DC, SCAC 2012 R2, SCVMM 2012 R2, System Center 2016, W2K12R2, Windows 10 by Wim Matthyssen

Hi all,

As a blogger completely focused on Microsoft technologies, it was a fun year of writing about all those interesting and ever changing products and services. As we almost end the year 2016 and are preparing for 2017 to start, I wanted to make a list of all the blog posts I wrote throughout the twelve months of 2016. During the year, I’ve published 26 blog posts mostly about Azure, the System Center Suite and Hyper-V. Below you can find them all divided by technology.



Azure Compute – IaaS (ASM)

Step-by-step: Move an Azure IaaS VM between different Azure Subscriptions

Clean up Azure PowerShell when using different Azure subscriptions

Replica DCs on Azure – Removing the Azure Endpoints

Replica DCs on Azure – Transferring FSMO roles to the IaaS DCs

Replica DCs on Azure – Manage the Time Configuration settings on the DCs

Replica DCs on Azure – Domain Controller Health Check

Replica DCs on Azure – Promote the Azure IaaS VMs to a domain controller

Replica DCs on Azure – Add the Active Directory Domain Services role

Replica DCs on Azure – Adjustment of some server settings before promoting the DCs

Replica DCs on Azure – Initialize and format the additional data disk

Replica DCs on Microsoft Azure – Create the VMs with Azure PowerShell

Step by step: Change the drive letter of the Temporary Storage on an Azure IaaS v1 VM


Azure Networking

How to connect an Azure ARM VNet to an ASM VNet using VNet Peering

Replica DCs on Azure – Switch DNS servers for the VNet

Replica DCs on Azure – Create the Active Directory site for the Azure VNet


Azure Backup

Microsoft Azure Backup Server: Install a new version of the Microsoft Azure Recovery Services Agent

Microsoft Azure Backup Server: System State backup fails with WSB Event ID: 546

Microsoft Azure Backup Server: System State backup fails with the message replica is inconsistent

Step by step: How to install Microsoft Azure Backup Server (MABS)


Azure RemoteApp

An RDP connection to the Azure RemoteApp custom VM fails with the following error: “No Remote Desktop License Servers available”


Windows 10

How to deploy Windows 10 from a USB flash drive


System Center

System Center 2016 evaluation VHDs download links

Step by step: How to connect SCAC 2012 R2 to SCVMM 2012 R2 and Microsoft Azure

Step by step: Installing SCAC 2012 R2



A list of tools that can be used to do a V2V from VMware to Hyper-V

Client Hyper-V – Using nested virtualization to run Client Hyper-V on a Windows 10 VM


Before I wrap up this blog post, I want to thank you all for reading my blog posts in 2016, and I really hope you will keep doing so in 2017. I wish you all a healthy, successful and outstanding New Year! See you all in 2017!

Wim Matthyssen (@wmatthyssen)

Microsoft Azure Backup Server: Install a new version of the Microsoft Azure Recovery Services Agent

3:06 pm in Azure, Azure Backup, Cloud, hybrid cloud, Microsoft Azure Backup Server by Wim Matthyssen

Hi all,

Some time ago a client received following alert on his Microsoft Azure Backup Server (MABS):

“Azure Backup raised the following alert for the subscription in use: (ID 33406). A new version of Windows Azure Backup Agent is available. You can review details about the new version and download it from (ID 100083) More information

Like you all can read this alert was raised because there is a new version of the Azure Backup Agent available. In the Event Viewer on the MABS server you can also find following Warning message under the Application and Services Logs, CloudBackup, Operational:

“A newer version of Microsoft Azure Recovery Services Agent is required.”


To install this new agent the following steps were taken:

1) Check the current Azure Backup Agent Version. To do so open the MABS console and click Management. Under Online you can find the Azure Backup agent version. Like you can see in the screenshot below for the moment version 2.0.9032.0 is installed


2) Download the latest version of the agent via following link: . Go to the section Update information were you can find the update package for agent version 2.0.9037.0 In my example I saved it under the Temp folder



3) Go to the Temp folder and Run the MARSAgentInstaller as administrator


4) If the UAC screen pops up, click Yes


5) To continue installing the update, click Next


6) If all required software is in place, click Upgrade. This will start the upgrade process



7) When the Upgrade is successful click Finish


8) If you check the Azure Backup Agent version again, you can see version 2.0.9037.0 is installed


9) You can also verify the current version by opening Run and typing appwiz.cpl to open Programs and Features. Look for the Microsoft Azure Recovery Services Agent which should have version 2.0.9037.0



10) Be aware that by default the Warning message will stay there for 30 days. To clear this message after the update you can inactivate it by right clicking the message and selecting Inactivate alert or by rebooting the MABS server several times (3 times at least)


This concludes this blog post, hope it helps!

Wim Matthyssen (@wmatthyssen)

Microsoft Azure Backup Server: System State backup fails with WSB Event ID: 546

7:07 am in Azure, Azure Backup, DC, IaaS, Microsoft Azure Backup Server, PowerShell, Public Cloud by Wim Matthyssen

After setting up a Microsoft Azure Backup Server (MABS) running on an IaaS v1 VM for a customer, I encountered a problem with a System State backup. The server having the problem was a Domain Controller (DC) also running as an Azure IaaS v1 VM and a member of the Domain Controller Protection Group on the MABS server. You can see the error message found on the MABS server in the screenshot below


“DPM cannot create a backup because Windows Server Backup (WSB) on the protected computer encountered an error (WSB Event ID: 546, WSB Error Code: 0x1751870). (ID 30229 Details: Internal error code: 0x80990ED0)”

On the DC itself following error message was found:


“The backup operation attempted at ‘‎2016‎-‎05‎-‎10T14:00:28.139491000Z’ has failed to start, error code ‘2155348032’ (The backup storage location is invalid. You cannot use a volume that is included in the backup as a storage location. ). Please review the event details for a solution, and then rerun the backup operation once the issue is resolved.”

To fix this problem I followed the steps below:

1) On the server with the problem, verify if no other backup or recovery operation is running by opening a PowerShell window (as administrator) and typing:


If the command output indicates that no operation is running, then you can proceed to step 2. Otherwise wait until the current job is completed and retry the failed System State backup job

2) In the same PowerShell windows type the following command:


Verify of the writer named System Writer is running Stable and without any errors. If so proceed to step 3. Otherwise manually restart the VSS Writer, if it fails again it’s necessary to reboot the server

3) Open Services and verify if the Cryptographic Services is running and set to startup Automatically.



4) The check if Windows Server Backup (WSB) is able to take a local System State Backup, open up PowerShell (as an administrator) and run the below command. When asked press (Y). Be aware it could take a while before the job completes:




If the backup is successfully proceed to step 5. Otherwise check the Windows event viewer for other errors

5) Open the registry editor and go to the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wbengine. Create a key called SystemStateBackup and set the values of this entry as follows:

Name: AllowSSBToAnyVolume
Data type: DWORD
Value data: 1



You also can use PowerShell (as an administrator) to create the registry key, to do so run following command:

6) When done, logon to the MABS server and retry the failed System State backup job by right-clicking and selecting Perform consistency check … Verification will start and at the end the job will complete with success



This concludes this blog post, hope it’s useful. Till next time!

Wim Matthyssen (@wmatthyssen)