What backup do you need for a virtual machine?
A virtual machine is backed up so that it can be started up again elsewhere: on another disk, another hypervisor or a standby instance. You use either an agent inside the machine or a backup taken from the hypervisor, but never a simple copy of the disk file while the machine is running, nor a snapshot left in place as a substitute for a backup.
Updated October 20263 min read5 sources cited
Key points
- Two valid methods: an agent inside the VM or a backup from the hypervisor; they work well together.
- A snapshot (checkpoint) is not a backup: Microsoft says so explicitly for Hyper-V.
- Database consistency depends on the guest tools (VSS on Windows, file system freeze on Linux).
- The copy must leave the hypervisor’s storage: otherwise a storage array failure takes out both the VMs and their backups.
- Test that the restored VM actually boots, not just that the file is there.
Two valid methods
From inside the machine (agent). An agent in the guest operating system backs up files, databases and, depending on the tool, the full image. It sees what the system sees. It works even if you do not manage the hypervisor (rented machine, cloud, hosting provider). You need one agent per machine, and it must be able to freeze databases for the duration of the copy.
From the hypervisor. The tool asks VMware, Hyper-V, Proxmox or an equivalent for a consistent snapshot, then copies the VM’s disks. A single console covers many machines. Application consistency depends on the guest tools: on Hyper-V, production checkpoints rely on VSS in Windows guests and on a file system freeze in Linux guests, without capturing memory. This method assumes that you control the hypervisor and that the tool supports it.
The ANSSI, France’s national cybersecurity agency, presents this same choice in its backup guide: disk image or agent inside the machine, depending on disk encryption, the restore granularity required and the volume of changes.
The two can coexist: a hypervisor image to restart the VM, and an agent to restore a single file or mailbox without bringing back the whole disk. If you can only do one, choose the one that has already been successfully restored in your environment.
| Agent inside the VM | Backup from the hypervisor | |
|---|---|---|
| Access to the hypervisor required | No | Yes |
| Restoring a single file | Direct | Depends on the tool |
| Restarting the complete VM | Depends on the tool (image) | Direct |
| Database consistency | Handled by the agent | Depends on the guest tools |
| Number of agents | One per VM | None inside the VMs |
A snapshot is not a backup
A snapshot (called a checkpoint in Hyper-V) freezes the state of a VM on the same storage. Microsoft is explicit: checkpoints are not backups and must not be used as a permanent recovery solution. They reduce the VM’s disk performance and consume space; if the storage fills up, the machine may be paused. A snapshot is useful for a few hours, around an update. Beyond that, it is a risk.
What breaks VM backups
- A snapshot left open for days: the differencing disk grows and eventually fills the hypervisor’s storage.
- Backing up only the disk files with a file copy, while the VM is running and an SQL database is in the middle of a write.
- All VMs and their backups on the same disk group. A storage failure takes out both.
- No boot test. A “backed-up” VM that does not start (driver, boot loader, forgotten system disk) is useless.
- Licences and dongles that refuse to start away from the original hardware. Identify them before an incident.
Frequency and location
The same logic applies as for a physical server: the frequency follows the RPO of the application hosted in the VM, not the fact that “it is virtual”. The copy must leave the hypervisor’s storage. If a standby restart is required, it must be prepared: network, addresses, instance size, and the start-up order of VMs that depend on one another (directory, then database, then application). The ANSSI recommends setting this restore order in advance.
At WeDoBack
WeDoBack backs up Windows and Linux servers, whether virtual or physical, as well as system images. The public SMART price list distinguishes the virtual server agent, at 6 € excl. VAT per month, from the physical server agent, at 20 € excl. VAT, in addition to storage at 49.99 € excl. VAT per TB per month; the SMART agent is reserved for this offer. With INTEGRAL, a single agent per machine covers the services subscribed for it, and virtual agents are included depending on the storage tier. A restore can bring the machine back to its previous state, operating system included. The DRP adds a restart on standby instances from the version you choose, with a monthly boot test that does not affect production. The BCP keeps cloud instances running continuously, ready to take over.
Frequently asked questions
Are my hypervisor’s snapshots enough as a backup?
No. A snapshot depends on the original disk: if the storage fails, both disappear. Microsoft advises against using Hyper-V checkpoints as a permanent recovery solution, and notes that they degrade disk performance and consume space. A snapshot is for rolling back just after an update, not for replacing an external copy.
Do I need an agent in every virtual machine?
Not necessarily. If you manage the hypervisor, a hypervisor-level backup covers many VMs from a single console. An agent becomes necessary when you do not control the hypervisor (rented machine, cloud), or when you want to restore an individual file or database precisely.
Can a VM be restored to a different hypervisor?
It is possible with an agent-based backup or a tool that converts disk formats, but it is not automatic. Drivers, the virtual network card and the boot loader must be checked. The only way to be sure is a boot test on the intended target.
Sources
Documents consulted in October 2026.
- Backing up information systems – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI
- Using checkpoints — Microsoft Learn
- Checkpoints and Snapshots Overview — Microsoft Learn
- DRP offer (Disaster Recovery Plan) — WeDoBack
- Offers and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
