Azure Recovery Services Vault public network access needs review

Restrict unnecessary public access while preserving required backup and restore paths.

Description

Allowing public network access on a Recovery Services Vault can broaden the service access paths available over public networks. Environments that require private connectivity need network restrictions appropriate to their backup workloads.

Public access does not grant anonymous read or restore permissions for backup data. Connectivity differs by workload, and Azure VM backups do not inherently require data transfer over the internet.

Potential impact

  • Actual service access paths may not meet the organization’s private-connectivity requirements.
  • Disabling public access without preparing the required paths can leave necessary restores failing even when backups succeed.

Remediation

Check private-endpoint support for the backup workload and configuration restrictions on the existing vault. Prepare required private endpoints, DNS and service connectivity, and test both backup and restore before setting public_network_access_enabled to false. Vaults with protected items have restrictions on new private-endpoint configuration; plan any required migration while preserving existing recovery options.

Examples

These excerpts change public access on the same vault. Private endpoints and DNS are omitted; verify workload support and restore paths before applying the change.

Before

hcl
resource "azurerm_recovery_services_vault" "recovery_vault" {
  name                = "app-recovery-vault"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  sku                 = "Standard"
  public_network_access_enabled = true
}

This allows public network access. It does not by itself let everyone read or restore backup data.

After

hcl
resource "azurerm_recovery_services_vault" "recovery_vault" {
  name                = "app-recovery-vault"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  sku                 = "Standard"
  public_network_access_enabled = false
}

This disables public network access. Verify required restores and item-level recovery rather than relying on successful backups alone.

References