Comparison route

Single service comparison

Back to main page

Anti-Ransomware Security

Azure Backup (Immutable Vault)

Azure Backup Immutable Vault applies write-once-read-many (WORM) controls to a Recovery Services vault, locking backup recovery points for a configured retention period so neither users, admins, nor ransomware can delete or modify them before expiry. It complements soft-delete and cross-region restore to harden the backup data plane against malicious deletion, overwrite, and tampering, enforcing retention via Azure Resource Manager policy on the vault rather than on individual jobs.

Azure logo

Azure

Service information

Azure Backup (Immutable Vault) iconAzure Backup (Immutable Vault)

Shortname: Immutable Vault

Huawei equivalent shortnames: HSS, CBR

Keywords: ransomware, immutable backup, security, protection

Differences vs Huawei

Huawei splits the Azure Immutable Vault responsibility across two services. CBR owns the immutable-backup data plane: its vault-level backup locking (WORM) prevents deletion or tampering of backups during a locked retention window, complemented by anti-deletion and access-isolation controls plus cross-region replication. HSS (Premium edition and above) owns the detection and prevention plane, blocking ransomware processes and can trigger CBR backups when an attack is detected. Azure consolidates both planes inside one vault resource; Huawei requires explicit CBR vault configuration plus a separate HSS deployment, so policy and lifecycle boundaries must be reconciled when mapping controls.

API, data-model, and regional footprints differ. Azure exposes the vault, immutability, and recovery-point lifecycle through a unified Azure Resource Manager API and Replay/Recovery Services providers, with immutability enforced server-side on the vault. CBR offers distinct vault types (server, disk, SFS Turbo, file) each with its own API surface and pricing per GB-month, and backup locking is applied per vault rather than uniformly across all Azure backup workloads. Cross-region replication in CBR is configured per backup, whereas Azure ties cross-region restore to the vault and storage redundancy settings. Confirm per-region availability and quotas for CBR backup locking before relying on it as a 1:1 immutable-vault replacement.

Operational responsibility shifts. Azure's immutable vault is a single pane for retention policy, RBAC, monitoring, and audit against the Recovery Services resource. On Huawei, retention and WORM live in CBR, host-level detection and incident response live in HSS, and broader security operations/audit aggregation typically requires SecMaster. Teams migrating must therefore redesign role assignments, alert routing, and runbooks across CBR+HSS+SecMaster instead of porting a single vault IAM model, and must validate that backup-locking and ransomware-triggered backup features are enabled in the target region.

Migration to Huawei

Assess the source Azure immutable-vault configuration first: locked retention durations, soft-delete state, cross-region restore topology, protected workloads (VMs, SQL, blobs), and the RBAC/Policy scope attached to the vault. Map each protected workload to a CBR vault type (server, disk, SFS Turbo, file) and confirm per-region CBR backup-locking (WORM) availability and quotas in your target Huawei region(s). Do not assume feature parity: verify that CBR's lock period and immutability semantics satisfy the source compliance requirement before choosing targets.

For the data plane, configure CBR vaults with backup locking enabled and replicate the retention schedule via CBR backup policies; enable cross-region replication where Azure cross-region restore was in use. Re-protect workloads with CBR agents/policies rather than attempting to import Azure recovery points, since there is no in-place immutable-backup migration path between Azure and Huawei. Rebuild identity and access controls around CBR vault RBAC and IAM, restricting delete privileges to honor the WORM intent of the source immutable vault.

For the detection plane, deploy HSS Premium edition (or higher) on the same ECS/BMS/container estate CBR protects, and configure the HSS-to-CBR ransomware-triggered backup integration so attack detection can drive an emergency backup. Replace Azure Defender/backup-alert integrations with HSS alarms, optionally feeding SecMaster for correlation and SOC runbooks. Validate detection-to-backup timing, alert routing, and isolation behavior in a non-production environment before cutover, since detection semantics and rule sets differ from Azure.

Validate with restore drills before flipping production: perform at least one CBR instant-restore test from a locked backup, one cross-region restore, and one ransomware-triggered backup cycle, comparing RTO/RPO against Azure SLAs. Recompute TCO because the Huawei cost model is additive: CBR charges vault capacity per GB-month plus backup storage and cross-region traffic, while HSS charges per protected server per month by edition and SecMaster separately. Account for peak backup volume, retention period, replication traffic, and edition-level feature gating, and document residual gaps (e.g., unified single-vault policy model, specific Azure Blob immutable-container parity) in the cutover runbook.

Huawei Cloud logo

Huawei Cloud

Huawei equivalent service

Host Security Service iconHost Security Service

Shortname: HSS

General function: Anti-Ransomware Security

Server host security detection and protection.

Keywords: host security, endpoint, protection

Huawei equivalent service

Cloud Backup and Recovery iconCloud Backup and Recovery

Shortname: CBR

General function: Backup and Recovery

Unified backup and recovery service.

Keywords: backup, recovery, snapshot