| Business service | Owner, criticality, maximum outage, data loss tolerance, regulatory duty | No executive owner or recovery objective | Business impact analysis and owner approval |
| Azure components | VMs, disks, databases, storage, file shares, applications, secrets, configurations, identities, dependencies | Backup covers a VM but not the database, Key Vault, DNS, or application configuration | Architecture map and recovery dependency checklist |
| Protected item | Vault, policy, last successful job, health, data source, region | Critical resource absent, paused, stale, or unhealthy | Backup Center export reconciled to resource inventory |
| Frequency and retention | Schedule, instant recovery, daily, weekly, monthly, yearly, archive, timezone | Recovery-point spacing exceeds the business data loss tolerance | Policy export and restore-point inspection |
| Redundancy | LRS, ZRS, GRS, cross-region restore, availability-zone considerations | Chosen redundancy does not address the regional or zone scenario | Vault properties and approved resilience design |
| Security state | Soft delete, immutability, MUA, Resource Guard, RBAC, alerts, private endpoint | One production administrator can remove protection and delete recovery points | Configuration export and controlled authorization test |
| Encryption and keys | Platform-managed or customer-managed key, Key Vault, identities, recovery | Backup cannot be restored because the key or permission path is unavailable | Key dependency map and recovery exercise |
| Restore evidence | Recovery point, target, time, integrity, application validation, owner acceptance | Jobs succeed but no end-to-end restore has been performed | Observed test with measured RTO and RPO |
| Exception | Unprotected data, reason, compensating control, owner, expiration | “Not supported” with no alternate recovery method | Approved exception and tested alternative |