Use the Conformity Knowledge Base AI to help improve your Cloud Posture

Enable Email Notifications for Backup Alerts

Trend Cloud One™ – Conformity is a continuous assurance tool that provides peace of mind for your cloud infrastructure, delivering over 1000 automated best practice checks.

Risk Level: High (not acceptable risk)
Rule ID: RecoveryServices-001

Enable and configure notifications to generate emails when a Warning and/or Critical backup alert occurs within your Microsoft Azure cloud account. This feature can be configured to send an email notification for every backup alert raised or once an hour (along with a list of alerts triggered in that hour).

This rule resolution is part of the Conformity Security & Compliance tool for Azure.

Security

Using Azure Backup service alerting capabilities to get email notifications when backup alert occurs represents an efficient way to monitor your backup jobs and keep your VM backup data safe and secure. For example, once the feature is enabled, you can receive an email notification for the following critical backup alert: "Backup data for a virtual machine backup item has been deleted. The deleted data will be kept with Azure Backup service for 14 days and deleted permanently after that.". This notification will allow you to take action and undelete the VM backup item within 14 days and recover your deleted backup.


Audit

To determine if email notifications are enabled for backup alerts in your Microsoft Azure cloud account, perform the following actions:

Note: Getting email notification configuration status for Azure backup alerts using Microsoft Azure CLI and/or Azure PowerShell is not currently supported.

Using Azure Portal

01 Sign in to Azure Management Console.

02 Navigate to All resources blade at https://portal.azure.com/#blade/HubsExtension/BrowseAll to access all your Microsoft Azure resources.

03 Choose the Azure subscription that you want to access from the Subscription filter box.

04 From the Type filter box, select Recovery Services vault to list only the Recovery Services vaults available in the selected subscription. An Azure Recovery Services (ARS) vault is a storage entity within Azure cloud that houses data such as VM configuration information and backup data.

05 Click on the name of the ARS vault that you want to examine.

06 On the navigation panel, under Monitoring, select Backup Alerts to access the page with the alert items generated by the Azure Backup service for the virtual machine backups stored within the selected Recovery Services vault.

07 Click on Configure notifications button from the dashboard top menu and check the Email notifications configuration setting. If the setting is set to Off, the selected Azure Recovery Services vault is not configured to send email notifications for virtual machine backup alerts.

08 Repeat steps no. 5 – 7 for each Azure Recovery Services vault available in the selected subscription.

09 Repeat steps no. 3 – 8 for each subscription created in your Microsoft Azure cloud account.

Remediation / Resolution

To enable email notifications for Warning and Critical backup alerts that occur within you Microsoft Azure cloud account, perform the following actions:

Note: Enabling email notifications for Azure backup alerts using Microsoft Azure CLI and/or Azure PowerShell is not currently supported.

Using Azure Portal

01 Sign in to Azure Management Console.

02 Navigate to All resources blade at https://portal.azure.com/#blade/HubsExtension/BrowseAll to access all your Microsoft Azure resources.

03 Choose the Azure subscription that you want to access from the Subscription filter box.

04 From the Type filter box, select Recovery Services vault to return the names of the Recovery Services vaults available in the selected subscription. An Azure Recovery Service (ARS) vault is a storage entity that holds the virtual machine (VM) backups.

05 Click on the name of the ARS vault that you want to reconfigure.

06 On the navigation panel, under Monitoring, select Backup Alerts to access the page that contains the alert items generated for the virtual machine backups stored in the selected Recovery Services vault.

07 Click on Configure notifications button from the dashboard top menu to access the backup alert notifications configuration settings.

08 On the Configure notifications page, perform the following commands:

  1. Click On under Email notifications to enable the feature.
  2. In the Recipients (Email) box, enter the email address(es) where you want your backup alerts to go to. Use a semi-colon (;) to separate multiple email addresses. Ideally, you should provide the email address(es) of mail groups and notification systems and not the email addresses of individual people.
  3. For the Notify setting, choose Per Alert option to receive one email for every alert raised or Hourly Digest to receive an email once an hour, along with a list of backup alerts activated in that hour.
  4. For Severity, select what kind of backup alerts you want to be notified about. There are 3 types of severity. Cloud Conformity recommends enabling both Critical and Warning type alerts:
    • Critical – any VM backup or recovery failure (scheduled or user triggered) would trigger a Critical alert. Destructive operations such as "delete backup" would also trigger a Critical alert.
    • Warning – any backup operations that succeed but have few warnings will be listed as Warning alerts.
    • Informational – as of today, there are no informational alerts generated by Microsoft Azure Backup service.
  5. Click Save to apply the configuration changes and enable email notifications for backup alerts.

09 Repeat steps no. 5 – 8 to enable backup alert notifications for other Azure Recovery Services (ARS) vaults available in the selected subscription.

10 Repeat steps no. 3 – 9 for each subscription created within your Microsoft Azure cloud account.

References

Publication date Nov 8, 2019