Azure Backup Linux snapshot extension keeps retrying after backup was disabled

Bernie Luksich 0 Reputation points
2026-09-17T20:22:58.16+00:00

I have a Linux Azure VM where Azure Backup is no longer enabled, and the portal shows no VM extensions. However, the Azure Linux Guest Agent continues to retry the Azure Backup VMSnapshotLinux extension and reports that the extension status file is missing.

The backup setup page offers to enable backup again, so I do not want to create a new backup policy merely to test it. A referenced restore-point resource is no longer present.

What is the supported way to clear a stale Azure Backup snapshot-extension assignment or desired state without enabling a new backup policy? Is this something that requires an Azure support request?

Azure Backup
Azure Backup

An Azure backup service that provides built-in management at scale.

0 comments No comments

4 answers

Sort by: Most helpful
  1. Bernie Luksich 0 Reputation points
    2026-09-21T20:30:23.17+00:00

    What was wrong with the answer I provided??? It worked and you deleted it for some rule??? Trying to help others.

    One more time, took a long time to type that last one so just a short note then in case you delete it again.

    Title: VMSnapshotLinux 1.0.9225.0 fails on Debian 13 (Python 3.13.5): missing distutils/imp; extension stuck "Transitioning", Run Command blocked

    Cause

    Python 3.12 removed distutils and imp from the standard library, and 3.13 removed crypt. The 1.0.9225.0 handler imports them, so its enable step crashes before it can write a status file.

    Fix

    sudo apt install python3-setuptools python3-zombie-imp python3-crypt-r

    python3 -c "import distutils, imp, crypt; print('ok')"

    sudo systemctl restart walinuxagent

    Versions:

    Failed: 1.0.9225.0 on Python 3.13.5. Others report 1.0.9231.0 failing on the same imports on Ubuntu 26.04 with Python 3.14.

    Newer build: on a fresh install, Azure Backup installed 1.0.9232.0. Its source wraps crypt, distutils and imp in try/except ImportError with fallbacks (a legacycrypt alternative, a built-in LooseVersion shim, and importlib for imp). It installed and enabled cleanly on Debian 13 / Python 3.13.5, and the Take Snapshot step completed.

    Workaround for others: on Debian 13 or any Python 3.12+ system, install the three packages above before enabling Azure Backup.

    Related: https://github.com/Azure/azure-linux-extensions/issues/2172

    Was this answer helpful?

    1 person found this answer helpful.

  2. Bernie Luksich 0 Reputation points
    2026-09-21T20:39:09.6466667+00:00

    My last post was to say this was resolved.

    Was this answer helpful?

    0 comments No comments

  3. Bernie Luksich 0 Reputation points
    2026-09-21T20:23:18.3366667+00:00

    To help others here is exactly the problem how we resolved and what to look out for with the Azure VMSnaptop. There is also on GitHub Azure which reports this same problem. This would be used to get out of the stuck situation. As noted, this problem prevents the "run command" from working with PowerShell scripts.

    OBSERVED

    • VMSnapshotLinux 1.0.9225.0 fails on Debian 13 (Python 3.13.5): missing distutils/imp;
    • Extension stuck "Transitioning", Run Command blocked

    Environment

    • Azure Linux VM, Debian 13 (trixie), Python 3.13.5, South Central US
    • WALinuxAgent 2.12.0.2 (Debian package), self-updated to goal-state agent 2.16.0.2
    • Extension: Microsoft.Azure.RecoveryServices.VMSnapshotLinux 1.0.9225.0 (config sequence 18)
    • No Recovery Services vault protected the VM, and az vm extension list showed no extensions

    Symptoms

    Extension status stuck at Transitioning. The portal and CLI showed no ARM-visible extensions, and the Backup page only offered "Enable backup."

    waagent logged every 30 minutes: no status file was reported by extension Microsoft.Azure.RecoveryServices.VMSnapshotLinux ... status/18.status does not exist.

    The handler was re-run on each new goal state or agent restart and failed each time, exit code 1, with ModuleNotFoundError: No module named 'distutils', then No module named 'imp' (from WAAgentUtil.py, HandlerUtil.py, DiskUtil.py).

    • Run Command (Invoke-AzVMRunCommand) failed while the extension state was pending.

    Cause

    • Python 3.12 removed distutils and imp from the standard library, and 3.13 removed crypt. The 1.0.9225.0 handler imports them, so its enable step crashes before it can write a status file.

    Fix

    • No backup enabled, nothing under /var/lib/waagent edited)

    sudo apt install python3-setuptools python3-zombie-imp python3-crypt-r

    python3 -c "import distutils, imp, crypt; print('ok')"

    sudo systemctl restart walinuxagent

    After the restart the agent logged Extension status: VMSnapshotLinux 'success' and All extensions in the goal state have reached a terminal state. Get-AzVM -Status showed the handler as Ready / Plugin enabled, and Run Command worked again.

    Versions / Notes

    Failed: 1.0.9225.0 on Python 3.13.5. Others report 1.0.9231.0 failing on the same imports on Ubuntu 26.04 with Python 3.14.

    Newer build: on a fresh install, Azure Backup installed 1.0.9232.0. Its source wraps crypt, distutils and imp in try/except ImportError with fallbacks (a legacycrypt alternative, a built-in LooseVersion shim, and importlib for imp). It installed and enabled cleanly on Debian 13 / Python 3.13.5, and the Take Snapshot step completed.

    Caveat: the shim packages were installed on that machine before the backup, so I could not confirm whether 1.0.9232.0 works without them. Result of the full backup job: [fill in: completed / failed].

    Workaround for others: on Debian 13 or any Python 3.12+ system, install the three packages above before enabling Azure Backup.

    Was this answer helpful?

    0 comments No comments

  4. Andriy Bilous 12,276 Reputation points MVP
    2026-09-18T03:42:14.9066667+00:00

    Hello Bernie Luksich

    I would recommend to verify the extension state with Azure CLI rather than relying only on the portal:

    az vm extension list --resource-group <RG> --vm-name <VM> -o table

    Microsoft documents this as the way to check the VMSnapshotLinux deployment state. VM Snapshot Linux extension for Azure Backup

    If a VMSnapshotLinux extension resource is still returned, remove that extension through Azure rather than deleting files inside /var/lib/waagent. Microsoft specifically recommends uninstalling the backup extension when it is in an inconsistent/stuck state. Troubleshoot Azure VM backup errors

    However, if:

    • Backup protection has already been stopped/deleted,
    • az vm extension list shows no backup extension, and
    • waagent continues receiving/retrying Microsoft.Azure.RecoveryServices.VMSnapshotLinux,

    then the issue is likely a stale platform/Backup desired state, not simply leftover files inside the guest.

    There is no documented supported guest-side command to remove such a service-side assignment.
    I would not manually delete the extension/waagent state as a permanent fix. In that situation, opening an Azure Support request is appropriate so Microsoft can check and clear the stale Backup/VM extension association or goal state.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.