Agent skill

Azure Site Recovery

by vinayaklatthe in vinayaklatthe/microsoft-security-skills

Guidance for Azure Site Recovery (ASR) — disaster-recovery-as-a-service that replicates Azure VMs and on-premises machines to a secondary region for orchestrated failover.

MITAuto-check passedDevOps & Cloud

Install Azure Site Recovery

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-site-recovery -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills azure-site-recovery --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-site-recovery .claude/skills/azure-site-recovery && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-site-recovery
GitHub stars
175
Token cost
~1.9k tokens
SKILL.md length
891 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for Azure Site Recovery (ASR) — disaster-recovery-as-a-service that replicates Azure VMs and on-premises machines to a secondary region for orchestrated failover.

  • Works in 7 steps: Define RPO and RTO per workload —… → Set up the Recovery Services vault in… → Enable replication on Tier 1 / Tier 2… → …
  • Point-in-time backup / restore (use Azure Backup)
  • SKILL.md covers When to use, Tier workloads by RPO / RTO, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Azure Site Recovery is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Azure Site Recovery (ASR) — disaster-recovery-as-a-service that replicates Azure VMs and on-premises machines to a secondary region for orchestrated failover. Covers RPO / RTO design, replication setup, recovery plans with start-up ordering and scripts, test failover discipline, and the separation between DR (ASR) and backup (Azure Backup) for ransomware resilience. WHEN: Azure Site Recovery, ASR, disaster recovery, DR replication, failover, recovery plan, business continuity, RPO RTO, test failover…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Backup and disaster recovery and Speech recognition and synthesis. It works with Microsoft Azure and SQL. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • Point-in-time backup / restore (use Azure Backup)
  • Database HA / geo-replication only (use SQL geo-replication)
  • General BCDR design without an Azure tilt

Example prompts

  • “/azure-site-recovery”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Define RPO and RTO per workload — Workload owners + business sign-off, not IT
  2. Set up the Recovery Services vault in the paired region — Use Azure **paired
  3. Enable replication on Tier 1 / Tier 2 VMs — Replication is per-VM. Choose target
  4. Build recovery plans with ordered start-up — Group VMs by application; specify
  5. Account for dependencies in the recovery region — Identity (Entra is global; AD DCs
  6. Test failover on a schedule — Run test failover into an isolated network in
  7. Plan failover / failback procedure — Planned failover (with sync) for graceful;

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Site Recovery loads about 1.9k tokens when it runs. Until then it costs about 198 tokens; SKILL.md has 891 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~198
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 891 words, ~1,937 tokens.

Download SKILL.mdSave it as .claude/skills/azure-site-recovery/SKILL.md (or your agent's skills folder).
name
azure-site-recovery
description
Guidance for Azure Site Recovery (ASR) — disaster-recovery-as-a-service that replicates Azure VMs and on-premises machines to a secondary region for orchestrated failover. Covers RPO / RTO design, replication setup, recovery plans with start-up ordering and scripts, test failover discipline, and the separation between DR (ASR) and backup (Azure Backup) for ransomware resilience. WHEN: Azure Site Recovery, ASR, disaster recovery, DR replication, failover, recovery plan, business continuity, RPO RTO, test failover, region failover, ransomware resilience DR, paired region, failover and failback. DO NOT USE for point-in-time backup / restore (use Azure Backup), database HA / geo-replication only (use SQL geo-replication), or general BCDR design without an Azure tilt.
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Azure Site Recovery

Azure Site Recovery (ASR) is Disaster-Recovery-as-a-Service that replicates Azure VMs and on-premises machines to a secondary region, orchestrating failover and failback to keep workloads available during regional outages. It's a critical piece of business continuity - distinct from, and complementary to, backup.

When to use

Providing regional disaster recovery for critical workloads with a tested, orchestrated failover capability. Use this skill to set RPO / RTO, design recovery plans, and run test failovers.

Do not use this skill for point-in-time backup (use Azure Backup), database-only HA, or generic BCDR strategy without Azure-specific design.

Tier workloads by RPO / RTO

Workload tierRPO targetRTO targetStrategy
Tier 0 - mission critical< 1 minute< 15 minutesActive-active multi-region (not ASR alone); ASR as warm fallback
Tier 1 - business critical< 15 minutes< 1 hourASR continuous replication + automated recovery plan
Tier 2 - important< 1 hour< 4 hoursASR replication + manual failover
Tier 3 - standard< 24 hours< 24 hoursAzure Backup + restore in secondary region
Tier 4 - dev / test7 days7 daysAzure Backup only; no DR

Rule of thumb: if RPO is sub-minute or RTO is sub-15-minute, ASR alone isn't enough

  • design active-active. ASR is the right answer for Tier 1 and Tier 2 (RPO minutes, RTO < 4 hours).

Approach

  1. Define RPO and RTO per workload — Workload owners + business sign-off, not IT guessing. Tier per the table. Document the assumption that "Tier 3 = backup-restore, not failover". Verify: RPO / RTO documented and signed off per Tier 1 / Tier 2 workload.

  2. Set up the Recovery Services vault in the paired region — Use Azure paired region (e.g. North Europe ↔ West Europe) for latency, billing, and Microsoft- coordinated patching. One vault per region pair per business unit. Verify: vault in the secondary region; replication policy created (e.g. 24-hour retention, 4-hour app-consistent snapshots).

  3. Enable replication on Tier 1 / Tier 2 VMs — Replication is per-VM. Choose target region, target VNet, target storage, and Availability Zone alignment if used in source. Initial replication can take hours - plan bandwidth. Verify: replication health = healthy on all in-scope VMs; latest recovery point time stamp within the RPO target.

  4. Build recovery plans with ordered start-up — Group VMs by application; specify start-up order (DB tier first, then app, then web). Add pre / post scripts (Automation runbooks) for DNS update, IP changes, app warm-up. Add manual action pauses where a human must validate. Verify: recovery plan dry-runs in test failover; documented runbook for the on-call team.

  5. Account for dependencies in the recovery region — Identity (Entra is global; AD DCs need a regional DC or DR DC), DNS (private DNS zones), Key Vault (regional or geo- replicated), Storage accounts (GRS or RA-GRS), networking (peerings, gateways, firewall), licences. Verify: dependency map; recovery region has working DNS, DC reachability, Key Vault, gateway connectivity.

  6. Test failover on a schedule — Run test failover into an isolated network in the secondary region at least every 6 months for Tier 1 (quarterly is better). Validate app functionality, document timing vs RTO target, capture issues. Verify: test failover report shows actual RTO ≤ documented RTO; issues triaged within 30 days.

  7. Plan failover / failback procedure — Planned failover (with sync) for graceful; unplanned (data-loss-bounded by last recovery point) for outage. Failback procedure tested as part of the test failover lifecycle.

Show full SKILL.md (350 more words)Show less

Guardrails

  • DR is not backup - pair ASR with Azure Backup for point-in-time restore and ransomware recovery (immutable / soft-deleted recovery points). ASR replicates the corruption too; you need immutable backup for ransomware.
  • Test failover on a schedule; an untested DR plan is an assumption, not a capability. First real failover with no test = it doesn't work.
  • Account for dependencies (identity, DNS, networking, Key Vault) in the recovery region. App fails over fine; can't reach DC or Key Vault = still down.
  • Paired regions matter. Microsoft coordinates patching across pairs - non-paired pairs can patch the same week and both go offline.
  • Recovery plans, not just replication. Replication keeps the data; recovery plan starts the app in the right order.
  • Cost: ASR is per-VM-month + storage. Tier carefully - DR for everything is wasteful; DR for nothing is negligent.

Common anti-patterns

  • "We have ASR, so we don't need backup" - ASR replicates ransomware encryption. Backup with immutability is the only ransomware recovery.
  • "Replicate everything to be safe" - 10x cost, slower failover, more test scope. Tier by RPO / RTO.
  • "Never test the failover - it's risky in prod" - Test failover is isolated; it does not affect prod. The risk is not testing.
  • "Run DR drill once, two years ago, never again" - Architecture has drifted. Quarterly test for Tier 1.
  • "Forgot the DC / DNS / Key Vault in the DR region" - VM is up, app can't auth or resolve. Dependency map.
  • "Single global vault for all regions" - Vault is regional; vault in primary lost = no DR. One per region pair.

Example prompts

  • Design a disaster recovery plan with Azure Site Recovery and clear RPO / RTO targets.
  • How do I run a test failover without affecting production?
  • Set up region-to-region replication and a recovery plan with ordered start-up.
  • Plan DR alongside Azure Backup for ransomware resilience.
  • Map dependencies (identity, DNS, Key Vault) for failover to the paired region.
  • Tier our workloads for RPO / RTO and decide which get ASR vs backup-only.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/azure-site-recovery of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Azure Site Recovery next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Site Recovery compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Site Recovery this skillvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT
Azure Resource Manager SQL Dotnetmicrosoft/skills3.1k5 repos~2.6kAutomated safety check: PassMIT
Multi Cloud ArchitectureHermeticOrmus/LibreUIUX-Claude-Code11211 repos~1.2kAutomated safety check: PassMIT
Cloud ArchitectJeffallan/claude-skills12k—~1.9kAutomated safety check: PassMIT
Azure Resource Manager Mysql Dotnetmicrosoft/skills3.1k5 repos~3.5kAutomated safety check: PassMIT
Azure Resource Manager Postgresql Dotnetmicrosoft/skills3.1k5 repos~4kAutomated safety check: PassMIT

Similar skills

  • Official

    Azure Resource Manager SDK for Azure SQL in .NET. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 5 repos~2.6k tokens
    DevOps & CloudAuto-check passed
  • Multi Cloud Architecture

    HermeticOrmus/LibreUIUX-Claude-Code

    Design multi-cloud architectures using a decision framework to select and integrate services across AWS, Azure, and GCP.

    112 GitHub starsUsed in 11 repos~1.2k tokens
    DevOps & CloudAuto-check passed
  • Cloud Architect

    Jeffallan/claude-skills

    Designs cloud architectures, migration plans, cost optimization recommendations and disaster recovery strategies across AWS, Azure and GCP.

    12k GitHub stars~1.9k tokensUpdated 8 days ago
    DevOps & CloudAuto-check passed
  • Official

    Azure MySQL Flexible Server SDK for .NET. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 5 repos~3.5k tokens
    DevOps & CloudAuto-check passed
  • Azure PostgreSQL Flexible Server SDK for .NET. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 5 repos~4k tokens
    DevOps & CloudAuto-check passed
  • Preset

    microsoft/GitHub-Copilot-for-Azure

    Official

    Intelligently deploys Azure OpenAI models to optimal regions by analyzing capacity across all available regions.

    255 GitHub starsUsed in 1 repo~1.2k tokens
    DevOps & CloudAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Azure Site Recovery

What does Azure Site Recovery do?

Guidance for Azure Site Recovery (ASR) — disaster-recovery-as-a-service that replicates Azure VMs and on-premises machines to a secondary region for orchestrated failover. Azure Site Recovery is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Azure Site Recovery (ASR) — disaster-recovery-as-a-service that replicates Azure VMs and on-premises machines to a secondary region for orchestrated failover.

When should I use Azure Site Recovery?

Azure Site Recovery fits situations like: point-in-time backup / restore (use Azure Backup); database HA / geo-replication only (use SQL geo-replication); general BCDR design without an Azure tilt.

How do I install Azure Site Recovery in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-site-recovery -a claude-code`. Or copy the skill folder (skills/azure-site-recovery in vinayaklatthe/microsoft-security-skills) into .claude/skills/azure-site-recovery in your project. Claude Code loads it when a task matches its description.

How do I install Azure Site Recovery in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-site-recovery -a codex`. Or copy the skill folder (skills/azure-site-recovery in vinayaklatthe/microsoft-security-skills) into .agents/skills/azure-site-recovery in your project. Codex loads it when a task matches its description.

Can I use Azure Site Recovery in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-site-recovery -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-site-recovery, .gemini/skills/azure-site-recovery, .github/skills/azure-site-recovery and .opencode/skills/azure-site-recovery in your project.

What does Azure Site Recovery need to run?

SKILL.md names no scripts, command-line tools or credentials: Azure Site Recovery is instructions for the agent only.

Does Azure Site Recovery access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Azure Site Recovery safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Site Recovery use?

Azure Site Recovery is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Site Recovery use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Site Recovery?

Skills that share tags, products or a category with Azure Site Recovery: Azure Resource Manager SQL Dotnet (microsoft/skills, 3.1k stars), Multi Cloud Architecture (HermeticOrmus/LibreUIUX-Claude-Code, 112 stars), Cloud Architect (Jeffallan/claude-skills, 12k stars) and Azure Resource Manager Mysql Dotnet (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Site Recovery?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.