An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
For Azure VM backup, the backup traffic does not go through the virtual network or Azure Firewall. The data transfer between the VM disks, storage, and the Recovery Services vault happens on the Azure backbone network.
Because of that, there isn’t a supported way to force standard Azure VM backup traffic through a firewall in the VNet.
Key points:
- Azure VM backup doesn’t require allowing IPs or FQDNs in the VNet for backup traffic.
- The communication and data transfer stay within Azure’s internal network.
- If the goal is to inspect or control backup traffic with a firewall, that model doesn’t apply to VM-level Azure Backup.
- Private endpoints are relevant for workloads such as SQL Server on Azure VM, SAP HANA on Azure VM, and MARS/on-premises servers, where secure network connectivity to the Recovery Services vault is needed.
If the requirement is specifically to send backup-related traffic through a firewall, that applies to some workload backups inside VMs, not to Azure VM backup itself.