Azure Backup: Unable to undelete recovery services vault backup items — Soft delete and protection status clarification

Austin-2398 0 Reputation points
2026-09-08T14:59:20.3966667+00:00

Problem description

I am experiencing an issue with a backup item protected by Azure Recovery Services. Despite the last successful backup being on 9/3/2026 at 11:00 AM, the item no longer performs daily backups. In the portal, the 'Undelete' option is unavailable, and an error code 'BMSUserErrorInvalidAPIVersionMABProtectedItemsList' is displayed. PowerShell diagnostics indicate the item's 'DeleteState' is 'NotDeleted', suggesting it isn't soft-deleted. I need to understand whether the item is soft-deleted or marked for deferred deletion, and how to restore or re-enable backups.

Environment

Recovery Services vault configured for file-and-folder backups using the Microsoft Azure Recovery Services (MARS) agent; a Windows server protected by the MARS agent; soft-delete configuration for the vault has not been determined.

What I've already tried

I reviewed the backup item in the Azure portal and noted that the 'Undelete' action is unavailable. I executed PowerShell commands to list backup containers and items, set and retrieved vault context, and queried the item’s properties. Diagnostics show that 'DeleteState' is 'NotDeleted' and 'LastBackupStatus' is 'Completed'. I also checked the protection status and the last backup time. Additionally, I attempted to confirm whether the item is soft-deleted or in deferred deletion, but the portal and diagnostic data do not provide clear information. I have not tried restoring the item or modifying vault settings.

Current status

I am seeking clarification on whether the backup item is soft-deleted or in deferred deletion state and guidance on how to restore or re-enable backups for this item. Any steps or best practices to resolve this issue would be appreciated.

Azure Backup
Azure Backup

An Azure backup service that provides built-in management at scale.


1 answer

Sort by: Most helpful
  1. Bharath Y P 10,610 Reputation points Microsoft External Staff Moderator
    2026-09-08T17:57:12.7833333+00:00

    Hello Austin, thank you for posting your query on Microsoft Q&A platform.

    It looks like your PowerShell output already answers the first question: DeleteState = NotDeleted means the item is neither soft-deleted nor in deferred deletion. Azure Backup only sets DeleteState to ToBeDeleted when protection is stopped with delete data (which starts the 14-day soft-delete clock). Since your item never entered that state, Undelete is correctly greyed out, there is nothing to undelete, and no vault/soft-delete change is needed.

    The missing daily backups are a separate, client-side cause. For MARS file-and-folder backup, the schedule lives in the MARS console on the server, not in the vault. "Stop protection and retain backup data" halts all future jobs while keeping every existing recovery point which is exactly your fingerprint: last backup 9/3/2026 11:00 AM, LastBackupStatus = Completed, recovery points intact, no failed job to alert on.

    Hear you can try:

    1. On the protected Windows server, open the MARS console > Actions > Schedule Backup > Modify a backup schedule for your files and folders. Verify: check whether "Stop using this backup schedule but keep the stored backups until a schedule is activated again" is selected, if yes, that's the cause.
    2. Select Re-enable backup schedule, set your daily frequency and retention, and finish the wizard. Verify: the MARS Jobs pane shows a newly scheduled job.
    3. Run Back Up Now to validate end-to-end. Verify: job completes as Completed, and the vault's Backup items → Azure Backup Agent blade shows an advanced Latest restore point.
    4. If a schedule is already active and still nothing runs, check the MARS pre-checks: agent up to date, network connectivity to Azure, Microsoft Azure Recovery Services service Running, 5–10% free space on the scratch/cache volume, antivirus not blocking, and Get-ExecutionPolicy -List. if LocalMachine is restricted, set it to Unrestricted or RemoteSigned from an elevated prompt.

    On the error code: BMSUserErrorInvalidAPIVersionMABProtectedItemsList is a service-side error on the list protected items call for MAB (MARS/MABS) workloads. It affects how the portal reads/renders item state — it does not stop your backups. Re-read the item with a current module to confirm:

    Install-Module -Name Az.RecoveryServices -Force 
    
    
    $vault = Get-AzRecoveryServicesVault -ResourceGroupName "<rg>" -Name "<vault>" 
    
    Get-AzRecoveryServicesBackupItem -BackupManagementType MAB -WorkloadType FileFolder -VaultId $vault.ID | Select-Object Name, ProtectionState, ProtectionStatus, DeleteState, LastBackupTime, LastBackupStatus
    
    
    

    Two cautions: please don't disable soft delete to "release" the item — it isn't engaged here and disabling it only weakens ransomware protection. And Undo-AzRecoveryServicesBackupItemDeletion won't apply: it acts only on ToBeDeleted items and returns "Undo-deletion is only supported for AzureVMs" for non-VM workloads.

    Official documentation

    Please share the screenshot from Step 1 and the PowerShell output above, if the schedule was stopped, Steps 2–3 will restore daily backups today.

    Hope this helps, IF you have any question, please do let us know.

    Thanks,

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.