Warwick Rudd takes us through some steps:
Most people know they need backups. Fewer have thought about what happens when somebody else gets to them first. Ransomware doesn’t start by encrypting your databases. It starts by finding your backups, because once those are gone you have nothing to recover to and every reason to pay. So a backup that anyone with the right credentials can delete is only a partial answer. It protects you from a failed server. It doesn’t protect you from someone who has made their way into your environment.
What you want is a backup that can’t be changed or deleted by anybody until the retention period you set has passed. Not an attacker, not a compromised admin account, and not you on a bad day. SQL Server 2025 makes this a lot more practical. Backup to URL now supports Managed Identity, so you can write backups to immutable Azure Blob Storage without handing out a SAS token or a storage key. There’s no secret sitting in a credential waiting to be found.
Click through for steps to set up the storage account.