azure_analyze_backup_security
Analyze Azure Backup and Site Recovery security configurations. Check vault encryption, soft delete, immutable vault, replication policies, and failover readiness for compliance with the 3-2-1 backup rule.
Instructions
NEW in v1.14.0 Analyze Azure Backup and Site Recovery (ASR) security configurations. Checks: backup vault encryption, soft delete enabled/disabled, cross-region restore, backup policies, retention periods, immutable vault (ransomware protection), ASR replication policies, failover readiness, recovery vault access control. Returns: vault security posture, backup coverage gaps, replication health, compliance with 3-2-1 backup rule.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| subscriptionId | Yes | Azure subscription ID | |
| resourceGroup | No | Optional: Filter by specific resource group | |
| includeASR | No | Include Azure Site Recovery (ASR) analysis for disaster recovery configurations. Default: true | |
| checkImmutability | No | Validate immutable vault configuration for ransomware protection. Default: true | |
| format | No | Output format: 'markdown' (default, human-readable) or 'json' (machine-readable) |