Home›Guides›IT backup

IT backup

How should you back up a physical server?

A physical server should be backed up as a whole machine: system, applications, accounts and data, in the form of a restorable image, supplemented by a backup of files and databases. Backing up only the data folder means that, on the day of the failure, you have to reinstall everything before putting the files back, which often takes several days.

Updated October 20263 min read5 sources cited

Key points

  • A system image (bare-metal) to restart, files and databases to restore a document or a table.
  • A SQL database must be backed up with a tool that understands the database, not by copying files while it is running.
  • The copy must leave the server: a second internal disk survives neither fire nor ransomware.
  • Plan for replacement hardware: RAID controller, licence tied to the serial number, dongle.
  • Restore the image at least once a year on a test machine, and a file every quarter.

Two levels, both useful

The system image, or bare-metal backup. It captures the server’s disks. You use it when the server no longer boots, when the disk has died, or when ransomware has hit the system. Microsoft recommends this type of backup to rebuild a domain controller, notably because it can be restored to different hardware. You still need to know which replacement hardware it will boot on: a very specific physical server (RAID controller, licence tied to the serial number, dongle) is difficult to restore elsewhere. Planning for this before the failure is part of the backup.

Files and databases, in addition to the image. They are used to restore a document or a table without restoring the whole machine. A SQL database must be backed up with a tool that understands the database (transaction consistency), not just by copying the files while the engine is writing. For SQL Server, Microsoft describes three recovery models: only the full model, with frequent transaction log backups, lets you return to a precise point in time.

The image can be taken daily. The database can be backed up hourly if data is entered continuously. The two histories do not need to have the same duration.

System imageFiles and databases
Used toRestart a dead or infected serverRestore a document, a mailbox, a table
Usual frequencyDailyDaily to hourly (database log)
RestoreEquivalent hardware or virtual machineTo a folder or a test database
Point to watchDrivers, RAID, hardware-bound licencesTransaction consistency

What not to forget on a physical server

  • The content of the data disks and the configuration (shares, scheduled tasks, certificates, service accounts).
  • Databases and business applications, using a consistent method.
  • Email, if it is still hosted on this server (on-premises Exchange), separately from Microsoft 365.
  • A copy outside the server itself. Microsoft points this out for SQL Server: backups must be on a different physical device from the database files, not on another partition of the same disk. A second internal disk does not survive a burnt-out power supply, nor encryption of the system.
  • Installation media and software configuration: the ANSSI, France’s national cybersecurity agency, recommends documenting them so you can rebuild without searching.
  • The backup encryption key, stored somewhere other than on this server.
  • A test: restore the image at least once a year on a test machine, and a file every quarter. The method is described in How do you test that a backup works?.

Typical recovery times

Without an image: reinstalling the system, drivers and applications, then copying the files. For a business server, it often takes one to three days, provided the installers and licences can be found.

With an image and an offsite copy: the time depends on the volume to be brought back and on the replacement hardware. This is the RTO, which must be measured, not guessed. NIST advises planning hardware replacement through agreements with suppliers. If this time remains unacceptable, the physical server needs a DRP: restarting on a standby instance from the backup while the hardware is repaired.

If several servers need to be brought back, the order matters. The ANSSI recommends setting a restore order in advance that takes account of dependencies (directory, DNS, databases) and the criticality of applications.

At WeDoBack

WeDoBack backs up Windows and Linux physical servers, as well as SQL Server, Exchange and business software, and can restore the complete server, including software and settings, or just files. Data is encrypted on the machine before being sent; the key stays with the client. The agent for a physical server is billed at €20 excl. VAT per month under the public SMART price list, in addition to storage at €49.99 excl. VAT per TB per month; with INTEGRAL, storage ranges from €100 down to €65 excl. VAT per TB per month depending on volume, with agents included depending on the tier. An archived system image option is available: €15 excl. VAT per month for a half-yearly image, or €60 excl. VAT per month for a monthly image, per server and per TB. If the hardware cannot be replaced in time, the DRP restarts the servers on standby instances from the chosen version.

Frequently asked questions

Can a system image be restored to different hardware?

Often, yes: Microsoft states, for example, that a Windows Server bare-metal backup can be restored to different hardware. In practice, storage drivers, RAID controllers and hardware-bound licences cause problems. You need to have tried it once, on a physical or virtual machine, before you need it.

Do you still need to back up a physical server if its disks are in RAID?

Yes. RAID lets you keep running when a disk dies. It also faithfully replicates a deletion, a corruption or ransomware encryption. It is not a backup: there is no history and no copy outside the server.

How often should a physical server be backed up?

The image can be taken daily. A database with continuous data entry may justify backing up its log every hour, or even more often: this is what lets you return to a precise point in time. The frequency follows from the acceptable data loss, the RPO.

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.