Skip to main content
Azure Resiliency Map
Scenarios

IaaS Lift-and-Shift

VM-based workload migrated as-is, fronted by a load balancer, connected on-prem via a network gateway, protected by Backup & Site Recovery.

Tier 1 — 1 hour RPO/RTO. Business-critical. Significant business impact if unavailable for more than an hour.
Zonal (AZ) redundancy

Bottlenecked by Azure Backup & Site Recovery

Regional / cross-region

Bottlenecked by VPN Gateway / ExpressRoute

ComponentZonal (AZ) redundancyRegional / cross-region
Virtual Machines / VMSS
Compute
RPO 0 for stateless compute — depends entirely on whether the backing data tier is also zone-redundant·RTO Seconds to a few minutes — load balancer health probes reroute automatically
RPO As low as ~30 sec–5 min under normal conditions — not an SLA-backed number·RTO Minutes to roughly an hour depending on VM count and recovery plan complexity — execution time only, after someone triggers it
Load Balancer / Application Gateway / Front Door
Networking
RPO N/A — routing layer·RTO Seconds — automatic
RPO N/A — routing layer only; the RPO for your application still depends entirely on the data tier behind each backend·RTO Probe-interval driven — typically well under a minute once a backend is marked unhealthy
VPN Gateway / ExpressRoute
Networking
RPO N/A — stateless connectivity layer, no persistent customer data·RTO Brief interruption, typically up to about one minute while traffic redistributes
RPO N/A — connectivity layer·RTO Entirely dependent on your architecture — client/on-premises devices must be configured or reconfigured to reach the surviving gateway
Azure Backup & Site Recovery
Data Protection
RPO Same as the underlying policy schedule·RTO Same as Local — restore time is unaffected by vault storage redundancy
RPO Backup: bounded by policy schedule. Site Recovery: as low as ~30 sec–5 min under normal conditions·RTO Backup + CRR: hours (restore time). Site Recovery: minutes to roughly an hour, execution time only, once a recovery plan is triggered
Storage Account (Blob / Files / Queue / Table)
Storage
RPO 0·RTO Effectively 0 — reads/writes continue through a zone loss; some DNS repointing may briefly affect in-flight requests
RPO ≤15 min, SLA-backed — but only for Block Blobs. Files/Tables/Queues/Page Blobs replicate best-effort with no committed RPO·RTO Reads: near-0, automatic, 99.99% SLA on the RA- secondary endpoint. Writes: failover process plus DNS update, typically under an hour once triggered