Microsoft Azure

Backup and recovery for Microsoft Azure

Eon connects to your subscriptions without storing credentials and without any Microsoft Graph permissions. You get coverage you can prove across the estate, recovery down to a single file or record, and backups Microsoft Fabric can query in place. Available on Azure Marketplace, so you can buy through your existing Azure account.

Coverage

What Eon backs up on Azure

Eon works natively through Azure's own APIs, with no appliances to run, and recovers any resource across your subscriptions down to a single file, blob or record.

Virtual Machines & Managed Disks

Instance view, disks and network configuration captured together. Restore a whole VM, or a new one from the same backup. Disks encrypted with Azure Disk Encryption are supported on both the backup and the restore path, and Premium SSD v2 and Ultra disks are covered.

Learn more

Blob Storage

Blob-level capture, stored incrementally after the first backup so you keep only what changed. Restore a container or individual blobs.

Learn more

Azure Files

Native file share protection with a policy-driven model rather than a per-share configuration. Restore back to the original location.

Azure SQL Database

Point-in-time recovery and restore to a new database, using database-level copy rather than a whole-server operation. Databases encrypted with a customer-managed key are supported, on backup and restore.

Learn more

PostgreSQL, MySQL & SQL Server

Azure Database for PostgreSQL Flexible Server, with cross-subscription point-in-time restore. Azure Database for MySQL Flexible Server. And SQL Server running on Azure VMs, re-registered as a SQL VM when it is restored.

Learn more

How Eon connects to your Azure subscriptions

No Microsoft Graph permissions, so Eon has no visibility into Entra ID users, groups or sign-in logs. No role is ever assigned at tenant root. You choose whether source onboarding covers a single subscription or a management group.

Restore uses workload identity federation, exchanging a federated assertion for short-lived tokens at runtime. The restore worker needs outbound HTTPS only, and can sit in a VNet and subnet you choose with egress filtered by Azure Firewall or NSG rules.

Eon creates a dedicated resource group in each onboarded subscription, and the short-lived resources it needs to run a job live there. Permissions like disk delete are scoped to that group rather than the subscription, so the writeable footprint stays narrow and auditable.

From connection to recovery

Connect a subscription with a read-only role and Eon takes it from there. Nothing to size, patch or operate, and recovery lands back in your own subscriptions.

Eon and Microsoft

Built with Microsoft

Eon collaborated with Microsoft to make backup data usable inside Fabric, and the OneLake integration is available in public preview. Eon is listed on Azure Marketplace with usage-based billing, so you can buy through the Azure account you already have. Backups are written as Iceberg tables in open format, not locked into a vendor format you cannot read.

View on Azure Marketplace
Proof

Protecting petabytes across regulated, multi-subscription Azure estates

>100% ROI

in year one

SoFi more than covered the cost of Eon in its first twelve months, across five AWS Regions.

Read the case study

88% faster

recovery

NETGEAR cut restore time on a 10TB SQL Server database and reduced backup costs by 35%.

Read the case study

Petabytes

protected in 3 days

AlphaSense completed its initial backup in three days and reached production in 25.

Read the case study

40% lower

backup cost

Innago consolidated posture management and agentless Kubernetes backup onto Eon.

Read the case study
Cyber resilience

Ransomware and rogue AI agents

Both come down to something with valid credentials destroying data, starting with the backups. Recovery depends on whether your backups sit where those credentials can't reach, and whether you can tell which copy is clean.

Credentials from production do not open your backups

Backups land in an isolated, immutable vault, kept apart from the subscription they came from. Access is time-bound, so a key stolen out of production does not reach your recovery data, and nothing in there can be quietly overwritten or deleted.

You know which copy is clean before you restore

Every backup is scanned as it lands, for entropy shifts, mass deletion, suspicious file changes and ransomware notes. That runs across instances, object storage and databases, so you pick a clean recovery point rather than restoring and finding out.

Roll back what the agent touched

An automation with write access can do a lot of damage in a few seconds. Because Eon reads data down to the record, you restore the rows or blobs it changed and keep every good write that happened alongside them.

Cost

Backup storage cost

Backup spend grows quietly. Retention gets extended once and never revisited, snapshots outlive the resources they came from, and nobody owns the line item until Finance asks about it. Eon stores less to begin with, and shows you where the rest is going, by subscription and by region.

You store what changed, not another full copy

After the first backup, Eon keeps only what is new, and deduplicates across your whole estate rather than within one dataset at a time. Most teams take over 40% off backup storage spend.

One copy, not one per region

Protecting three regions the native way usually means paying to store three copies. Eon keeps one, and it stays searchable and restorable from any region or subscription you need it in.

Retention that matches what the data is

Because Eon classifies what it protects, retention follows the content instead of one default applied to everything. Snapshots of resources nobody owns any more expire, rather than sitting on the bill for years.

Beyond protection

Backups Microsoft Fabric can query

Eon stores your Azure backups in an open format Microsoft Fabric can read directly, so they show up as tables in your lakehouse, ready for Power BI, SQL or Spark. No copy, no restore. Available in public preview.

Eon Mind
Comparison

Eon and Azure Backup

Azure Backup is built into Azure and handles the basics well. It gets harder as you grow: each vault only covers one region, every service restores a different way, and checking that everything is protected is up to you.

Azure Backup

Eon

Scope of a deployment

A vault and the resources it protects must sit in the same region.

Subscription or management group, with one view across the estate.

Knowing what your data holds

Not classified. Retention is a default you apply.

Classified on discovery, so protection follows the content.

Consistency of recovery

Differs by workload. File-level for VMs and Files, container or prefix for Blob, and no record-level inside a database.

The same path everywhere, down to a single record.

Reading backup data

Restore it first, then look.

Query it in place from Microsoft Fabric, in open Iceberg.

ADE-encrypted disks

Not supported by Azure Disk Backup.

Open Iceberg tables you can read directly.

Clouds

Azure only.

AWS, Google Cloud and Azure in one view.

FAQs

Which Azure resources does Eon back up?
Virtual Machines and Managed Disks, Blob Storage, Azure Files, Azure SQL Database, Azure Database for PostgreSQL and MySQL Flexible Server, and SQL Server running on Azure VMs. Eon discovers these across every subscription you connect and picks up new resources as they appear rather than waiting for someone to tag them.
What permissions does Eon need?
Less than most people expect. No Microsoft Graph permissions, so no access to Entra ID users, groups or sign-in logs. No role is assigned at tenant root. Source onboarding is scoped to a subscription or a management group, and restore onboarding is always subscription-scoped. Destructive permissions are confined to a dedicated resource group Eon creates. We can share the full permissions reference for a security review.
What runs inside my environment?
Discovery and backup run through the Azure APIs, so there is nothing to roll out across your subscriptions before you are protected. During a restore, Eon provisions a restore worker in its own resource group, which needs outbound HTTPS and no inbound access, and can sit in a VNet and subnet you choose. Eon stores no credentials at any point.
Do you support Cosmos DB?
Not for backup today. Eon discovers Cosmos DB accounts as part of building your inventory, so you can see them alongside everything else, but protection is not available. If Cosmos DB is on your list, talk to us about what is planned.
Can I back up Azure data into another cloud?
Yes. Azure SQL Server and Azure Database for PostgreSQL Flexible Server can be backed up into a vault hosted in AWS or Google Cloud, which puts your recovery data outside the blast radius of an Azure-level incident. A full restore returns the resource to Azure. Cosmos DB and AKS namespaces are excluded.
Can I query my backups?
Yes. Backups are written as Iceberg tables in open format. With the OneLake integration, currently in public preview, they appear as native tables in your Microsoft Fabric lakehouse and can be queried from Power BI, SQL, Spark or an AI workload without a restore and without ETL.

See it against your own subscriptions

Connect a subscription and Eon will show you what is there: every resource across your subscriptions and regions, what each one holds, what is currently protected, and what is not. Most teams find something they did not know was unprotected. Bring a recovery scenario you have had to handle and we will walk through it.