|
2 | 2 | title: Support matrix for Azure VM disaster recovery with Azure Site Recovery
|
3 | 3 | description: Summarizes support for Azure VMs disaster recovery to a secondary region with Azure Site Recovery.
|
4 | 4 | ms.topic: conceptual
|
5 |
| -ms.date: 11/04/2024 |
| 5 | +ms.date: 12/20/2024 |
6 | 6 | ms.service: azure-site-recovery
|
7 | 7 | author: ankitaduttaMSFT
|
8 | 8 | ms.author: ankitadutta
|
@@ -33,6 +33,7 @@ This article summarizes support and prerequisites for disaster recovery of Azure
|
33 | 33 | **Migrate VMs across regions within supported geographical clusters (within and across subscriptions)** | Supported within the same Microsoft Entra tenant.
|
34 | 34 | **Migrate VMs within the same region** | Not supported.
|
35 | 35 | **Azure Dedicated Hosts** | Not supported.
|
| 36 | +**AVD infrastructure VMs** | Supported, provided all the Azure to Azure replication prerequisites are fulfilled. |
36 | 37 |
|
37 | 38 | ## Region support
|
38 | 39 |
|
@@ -63,11 +64,11 @@ This table summarizes support for the cache storage account used by Site Recover
|
63 | 64 | General purpose V2 storage accounts (Hot and Cool tier) | Supported | Usage of GPv2 is recommended because GPv1 doesn't support ZRS (Zonal Redundant Storage).
|
64 | 65 | Premium storage | Supported | Use Premium Block Blob storage accounts to get High Churn support. For more information, see [Azure VM Disaster Recovery - High Churn Support](./concepts-azure-to-azure-high-churn-support.md).
|
65 | 66 | Region | Same region as virtual machine | Cache storage account should be in the same region as the virtual machine being protected.
|
66 |
| -Subscription | Can be different from source virtual machines | Cache storage account need not be in the same subscription as the source virtual machine(s). |
| 67 | +Subscription | Can be different from source virtual machines | Cache storage account must be in the same subscription as the source virtual machine(s). <br> To use cache storage from the target subscription, use PowerShell. |
67 | 68 | Azure Storage firewalls for virtual networks | Supported | If you're using firewall enabled cache storage account or target storage account, ensure you ['Allow trusted Microsoft services'](../storage/common/storage-network-security.md#exceptions).<br></br>Also, ensure that you allow access to at least one subnet of source Vnet.<br></br>Note: Don't restrict virtual network access to your storage accounts used for Site Recovery. You should allow access from 'All networks'.
|
68 | 69 | Soft delete | Not supported | Soft delete isn't supported because once it is enabled on cache storage account, it increases cost. Azure Site Recovery performs frequent creates/deletes of log files while replicating causing costs to increase.
|
69 | 70 | Encryption at rest (CMK) | Supported | Storage account encryption can be configured with customer managed keys (CMK)
|
70 |
| -Managed identity | Not supported | The cached storage account must allow shared key access and Shared Access Signatures (SAS) signed by the shared key. |
| 71 | +Managed identity | Not supported | The cached storage account must allow shared key access and Shared Access Signatures (SAS) signed by the shared key. Recent changes in Azure Policy disable key authentication due to security concerns. However, for ASR, you need to enable it again. |
71 | 72 |
|
72 | 73 | The following table lists the limits in terms of number of disks that can replicate to a single storage account.
|
73 | 74 |
|
@@ -117,7 +118,7 @@ Windows 7 (x64) with SP1 onwards | From version [9.30](https://support.microsoft
|
117 | 118 |
|
118 | 119 | **Operating system** | **Details**
|
119 | 120 | --- | ---
|
120 |
| -Red Hat Enterprise Linux | 6.7, 6.8, 6.9, 6.10, 7.0, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6,[7.7](https://support.microsoft.com/help/4528026/update-rollup-41-for-azure-site-recovery), [7.8](https://support.microsoft.com/help/4564347/), [7.9](https://support.microsoft.com/help/4578241/), [8.0](https://support.microsoft.com/help/4531426/update-rollup-42-for-azure-site-recovery), 8.1, [8.2](https://support.microsoft.com/help/4570609/), [8.3](https://support.microsoft.com/help/4597409/), [8.4](https://support.microsoft.com/topic/883a93a7-57df-4b26-a1c4-847efb34a9e8) (4.18.0-305.30.1.el8_4.x86_64 or higher), [8.5](https://support.microsoft.com/topic/883a93a7-57df-4b26-a1c4-847efb34a9e8) (4.18.0-348.5.1.el8_5.x86_64 or higher), [8.6](https://support.microsoft.com/topic/update-rollup-62-for-azure-site-recovery-e7aff36f-b6ad-4705-901c-f662c00c402b), 8.7, 8.8, 8.9, 8.10, 9.0, 9.1, 9.2, 9.3, 9.4 <br> RHEL `9.x` is supported for the [following kernel versions](#supported-kernel-versions-for-red-hat-enterprise-linux-for-azure-virtual-machines). |
| 121 | +Red Hat Enterprise Linux | 6.7, 6.8, 6.9, 6.10, 7.0, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6,[7.7](https://support.microsoft.com/help/4528026/update-rollup-41-for-azure-site-recovery), [7.8](https://support.microsoft.com/help/4564347/), [7.9](https://support.microsoft.com/help/4578241/), [8.0](https://support.microsoft.com/help/4531426/update-rollup-42-for-azure-site-recovery), 8.1, [8.2](https://support.microsoft.com/help/4570609/), [8.3](https://support.microsoft.com/help/4597409/), [8.4](https://support.microsoft.com/topic/883a93a7-57df-4b26-a1c4-847efb34a9e8) (4.18.0-305.30.1.el8_4.x86_64 or higher), [8.5](https://support.microsoft.com/topic/883a93a7-57df-4b26-a1c4-847efb34a9e8) (4.18.0-348.5.1.el8_5.x86_64 or higher), [8.6](https://support.microsoft.com/topic/update-rollup-62-for-azure-site-recovery-e7aff36f-b6ad-4705-901c-f662c00c402b) (4.18.0-348.5.1.el8_5.x86_64 or higher), 8.7, 8.8, 8.9, 8.10, 9.0, 9.1, 9.2, 9.3, 9.4 <br> RHEL `9.x` is supported for the [following kernel versions](#supported-kernel-versions-for-red-hat-enterprise-linux-for-azure-virtual-machines). |
121 | 122 | Ubuntu 14.04 LTS Server | Includes support for all 14.04.*x* versions; [Supported kernel versions](#supported-ubuntu-kernel-versions-for-azure-virtual-machines);
|
122 | 123 | Ubuntu 16.04 LTS Server | Includes support for all 16.04.*x* versions; [Supported kernel version](#supported-ubuntu-kernel-versions-for-azure-virtual-machines)<br/><br/> Ubuntu servers using password-based authentication and sign-in, and the cloud-init package to configure cloud VMs, might have password-based sign-in disabled on failover (depending on the cloudinit configuration). Password-based sign in can be re-enabled on the virtual machine by resetting the password from the Support > Troubleshooting > Settings menu (of the failed over VM in the Azure portal.
|
123 | 124 | Ubuntu 18.04 LTS Server | Includes support for all 18.04.*x* versions; [Supported kernel version](#supported-ubuntu-kernel-versions-for-azure-virtual-machines)<br/><br/> Ubuntu servers using password-based authentication and sign-in, and the cloud-init package to configure cloud VMs, might have password-based sign-in disabled on failover (depending on the cloudinit configuration). Password-based sign in can be re-enabled on the virtual machine by resetting the password from the Support > Troubleshooting > Settings menu (of the failed over VM in the Azure portal.
|
@@ -324,7 +325,7 @@ Hybrid Use Benefit (HUB) | Supported | If the source VM has a HUB license enable
|
324 | 325 | Virtual Machine Scale Set Flex | Availability scenario - supported. Scalability scenario - not supported. |
|
325 | 326 | Azure gallery images - Microsoft published | Supported | Supported if the VM runs on a supported operating system.
|
326 | 327 | Azure Gallery images - Third party published | Supported | Supported if the VM runs on a supported operating system.
|
327 |
| -Custom images - Third party published | Supported | Supported if the VM runs on a supported operating system. |
| 328 | +Custom images - Third party published | Supported | The VM is supported if it runs on a supported operating system. During test failover and failover, Azure creates a VM with an Azure Marketplace image. Ensure that no custom Azure Policy blocks this operation. |
328 | 329 | VMs migrated using Site Recovery | Supported | If a VMware VM or physical machine was migrated to Azure using Site Recovery, you need to uninstall the older version of Mobility service running on the machine, and restart the machine before replicating it to another Azure region.
|
329 | 330 | Azure RBAC policies | Not supported | Azure role-based access control (Azure RBAC) policies on VMs aren't replicated to the failover VM in target region.
|
330 | 331 | Extensions | Not supported | Extensions aren't replicated to the failover VM in target region. It needs to be installed manually after failover.
|
@@ -379,8 +380,8 @@ Double Encryption at rest | Supported | Learn more on supported regions for [Win
|
379 | 380 | FIPS encryption | Not supported
|
380 | 381 | Azure Disk Encryption (ADE) for Windows OS | Supported for VMs with managed disks. | VMs using unmanaged disks aren't supported. <br/><br/> HSM-protected keys aren't supported. <br/><br/> Encryption of individual volumes on a single disk isn't supported. |
|
381 | 382 | Azure Disk Encryption (ADE) for Linux OS | Supported for VMs with managed disks. | VMs using unmanaged disks aren't supported. <br/><br/> HSM-protected keys aren't supported. <br/><br/> Encryption of individual volumes on a single disk isn't supported. <br><br> Known issue with enabling replication. [Learn more.](./azure-to-azure-troubleshoot-errors.md#enable-protection-failed-as-the-installer-is-unable-to-find-the-root-disk-error-code-151137) |
|
382 |
| -SAS key rotation | Not Supported | If the SAS key for storage accounts is rotated, customer needs to disable and re-enable replication. | |
383 |
| -Host Caching | Supported |
| 383 | +SAS key rotation | Supported | If the access key is rotated for cache storage account it won't impact the replication, so there is no need to disable or enable the replication. | |
| 384 | +Host Caching | Supported | | |
384 | 385 | Hot add | Supported | Enabling replication for a data disk that you add to a replicated Azure VM is supported for VMs that use managed disks. <br/><br/> Only one disk can be hot added to an Azure VM at a time. Parallel addition of multiple disks isn't supported. |
|
385 | 386 | Hot remove disk | Not supported | If you remove data disk on the VM, you need to disable replication and enable replication again for the VM.
|
386 | 387 | Exclude disk | Supported. You can use [PowerShell](azure-to-azure-exclude-disks.md) or navigate to **Advanced Setting** > **Storage Settings** > **Disk to Replicate** option from the portal. | Temporary disks are excluded by default.
|
|
0 commit comments