Azure Backup vs AWS Backup: features, pricing, and when to use which
Both services exist for the same reason: snapshots scattered across individual resources do not add up to a backup strategy. AWS Backup and Azure Backup centralise backup into policies you define once and apply across many resources, with a vault for storage and a reporting layer for compliance. The differences are in coverage, the recovery model, and how you pay.
This comparison sits inside our wider cloud backup and disaster recovery guide, which covers the concepts (RTO, RPO, immutability) and the other providers. Here we go head to head on the two biggest.
At a glance
| AWS Backup | Azure Backup | |
|---|---|---|
| Model | Central backup plans across AWS services | Recovery Services vault + Backup vault, policy-driven |
| Coverage | EC2, EBS, RDS, Aurora, DynamoDB, EFS, FSx, S3, Storage Gateway, VMware (via Gateway) | Azure VMs, SQL/SAP HANA in VMs, Azure Files, Blobs, managed disks, on-prem via MARS/MABS |
| Immutability | Vault Lock (WORM), compliance mode | Immutable vaults, soft delete on by default |
| Cross-region | Cross-region copy in backup plans | GRS vaults / cross-region restore |
| Cross-account / cross-tenant | Cross-account backup via Organizations | Cross-subscription; cross-tenant more limited |
| Pricing shape | Per-GB stored + restore + cross-region transfer | Per-instance fee + per-GB stored (tiered) |
Coverage: what each one actually backs up
This is usually the deciding factor, because it is dictated by where your workloads already live.
AWS Backup is strongest as the single control plane for AWS-native data services. If your estate is EC2/EBS, RDS and Aurora, DynamoDB, EFS/FSx, and S3, AWS Backup covers it under one set of plans, with tags driving which resources a plan applies to. It also reaches on-prem and VMware through Storage Gateway.
Azure Backup is built around the Recovery Services vault and the newer Backup vault, covering Azure VMs, SQL Server and SAP HANA running in VMs, Azure Files, Blob storage, and managed disks. For on-prem it uses the MARS agent or MABS/DPM. Its SQL-in-VM and SAP HANA support is particularly mature.
The honest read: neither is a reason to switch clouds. You back up where your workloads run. The comparison matters most when you are multi-cloud, or deciding how much to standardise.
Retention, immutability, and ransomware resilience
Immutability is the feature that actually matters against ransomware - a backup an attacker can delete is not a backup.
- AWS Backup offers Vault Lock in compliance mode: once locked, backups cannot be deleted or shortened in retention, even by the root account, until the retention period expires. This is the WORM guarantee auditors and ransomware playbooks want.
- Azure Backup provides immutable vaults and has soft delete enabled by default, so accidental or malicious deletion has a recovery window; immutability locks prevent retention from being weakened.
Both are credible; the AWS compliance-mode lock is marginally stricter in its “nobody, not even root” guarantee. We go deeper on this in the resilience section of the backup and DR guide.
Not sure your backup strategy would survive a ransomware event?
Book a free 30-min call
Recovery model: region and account boundaries
Where backups can be restored to is as important as where they are taken.
- AWS Backup supports cross-region copy as part of a backup plan (your DR copy lands in a second region automatically) and cross-account backup through AWS Organizations, which is the pattern for isolating backups in a dedicated, hardened account an attacker in the production account cannot reach.
- Azure Backup uses geo-redundant storage and cross-region restore for the regional story; the cross-subscription story is solid, but cross-tenant isolation is more constrained than AWS’s cross-account model.
For teams whose threat model includes “the production account itself is compromised,” AWS’s cross-account backup into an isolated account is the stronger built-in pattern.
Pricing: the shapes are different
The models do not line up one-to-one, which makes raw per-GB comparisons misleading.
- AWS Backup bills primarily on warm/cold storage per GB-month, plus restore charges and cross-region data transfer. There is no per-resource fee, so backing up many small resources is relatively cheap, and large datasets with long retention are where cost accumulates.
- Azure Backup adds a per-instance protected fee (tiered by the size of the protected instance) on top of per-GB storage. For a few large instances this is predictable; for a very large number of small protected items the per-instance fee can dominate.
The practical takeaway: model your own mix. Many small items favour AWS’s pure per-GB shape; a modest number of large VMs is comfortable on Azure’s per-instance model. And in both, forgotten long-retention backups are the silent cost - lifecycle rules to tier and expire old recovery points matter more than the headline per-GB rate. This is the same discipline we cover in when to use AWS managed services.
Which should you use?
| Choose AWS Backup when... | Choose Azure Backup when... |
|---|---|
| Your workloads are on AWS (EC2/EBS/RDS/DynamoDB/EFS/S3) | Your workloads are on Azure (VMs, SQL/SAP HANA in VMs, Files/Blob) |
| You need cross-account backup into an isolated, hardened account | You want mature SQL Server and SAP HANA in-VM backup |
| You want compliance-mode WORM where not even root can delete | You want soft delete on by default as a safety net |
| Your cost profile is many small resources (no per-instance fee) | Your cost profile is a modest number of large instances |
If you run both clouds, the right answer is usually both, under one backup policy standard - the same RTO/RPO targets, retention tiers, and immutability rules enforced natively in each. Standardising the policy, not the tool, is what keeps a multi-cloud backup estate auditable.
FAQ
Is AWS Backup or Azure Backup cheaper? It depends on your mix. AWS Backup has no per-instance fee, so it tends to win for many small resources; Azure Backup’s per-instance fee is predictable for a modest number of large VMs. In both, long-retention storage dominates the bill, so lifecycle rules matter more than the per-GB rate.
Can I use AWS Backup to back up Azure workloads (or vice versa)? Not natively, and it is not recommended. Each service is built for its own cloud. For multi-cloud, run each natively and standardise the backup policy across them, or use a third-party backup tool with cross-cloud support.
Which is better against ransomware? Both offer immutable backups. AWS Backup’s Vault Lock compliance mode is marginally stricter (“not even root can delete until retention expires”); Azure’s immutable vaults plus default soft delete are also credible. Immutability plus a cross-account/region copy is the combination that matters.
Do I still need a disaster recovery plan if I use one of these? Yes. Backup is one input to disaster recovery, not the whole of it. You still need defined RTO/RPO, a tested restore runbook, and a recovery target. See our cloud backup and disaster recovery guide.
Summary
- Coverage follows your workloads. AWS Backup for AWS-native data services, Azure Backup for Azure VMs and SQL/SAP HANA in VMs. Neither is a reason to change clouds.
- Immutability and cross-account isolation are the resilience features that matter. Both deliver immutable backups; AWS’s compliance-mode WORM and cross-account model are marginally stronger for a “production is compromised” threat model.
- The pricing shapes differ - AWS pure per-GB, Azure per-instance plus per-GB - so model your own mix, and treat lifecycle rules as the real cost lever.
If you want help designing a backup and recovery strategy that holds up across AWS and Azure, explore our backup and disaster recovery services.
Designing backup and DR across AWS and Azure?
Book a free 30-minute call. We help teams set RTO/RPO targets, standardise backup policy across clouds, and make sure restores actually work when you need them.