Hedronite · Cert Lesson · Cert-Prep / AWS SAP · Wed 2026-10-07

AWS SAP multi-account backup Organizations backup policies, cross-account copy, Vault Lock modes, and logically air-gapped vaults

Name the blast radius first. Region, account, or hand: each has its own control.

Lesson Class: Cert (AWS SAP-C02 · multi-account data protection)
Exam Facet: Backup policies · cross-account / cross-Region copy · Vault Lock · air-gapped vaults · DR tier
Paired Ops: AWS Backup coverage census
Paired Dev: Rust Gaps<'a> iterator and RPO breach filter
Grounding: SAP Bootcamp dr.md + AWS Backup, Organizations, and DR whitepaper docs (read 2026-10-07)
Region, Account, Hand
Cross-Region copy · cross-account copy or air-gapped vault · compliance lock.
Effective policy
Inherited JSON, read-only in the member account, invalid if incomplete.
Copy, then restore
No cross-account restore from a standard vault.
A lock an admin can lift stops no admin.

A copy in the same account dies with the account. A lock an admin can lift stops no admin.

§I. Frame

Recent SAP lessons covered SNS fan-out (10-04), Direct Connect resiliency (09-22), PrivateLink (09-07), Route 53 failover (08-26), and the landing zone with SCPs (08-02). Object Lock WORM had its turn on 06-23. AWS Backup across accounts has not.

SAP stems in this area name a threat, then offer four controls that all sound protective. Bootcamp dr.md frames the first cut: backup and restore is the cheap, slow tier, with recovery counted in hours. The second cut is which threat each control answers.

§II. Region, Account, Hand

Region, Account, Hand (named technique). Name the blast radius first. Each one has its own control, and no control covers the other two.

  1. Region. A Regional outage takes the source vault with it. Answer: a cross-Region copy action in the backup rule.
  2. Account. Compromised credentials or a deleted account take every vault in that account. Answer: a cross-account copy into a vault in another account, or a logically air-gapped vault.
  3. Hand. A privileged human, root included, deletes recovery points. Answer: Vault Lock in compliance mode after the grace time.

A stem that says "ransomware with administrator access" is a Hand stem. Cross-Region copy in the same account fails it.

§III. Organizations backup policies

A backup policy is JSON attached to the root, an OU, or an account. Each plan holds rules, regions, and selections, with optional advanced_backup_settings, backup_plan_tags, and scan_settings. Organizations merges inherited and attached policies into one effective policy per account. AWS Backup shows the resulting plan in the member account as immutable: the member can view it and change its tags, nothing else.

Four exam facts from the policy docs:

Per-account plans remain right for one-off workloads. A stem that says "every account, centrally, members cannot opt out" wants a backup policy.

§IV. Cross-account copy

Requirements, in order:

  1. Source and destination accounts in the same organization.
  2. The management account enables cross-account backup (console Settings, or UpdateGlobalSettings).
  3. The destination vault's access policy allows backup:CopyIntoBackupVault. The default vault cannot be a destination, because its key cannot be shared.
  4. The source role holds backup:CopyFromBackupVault and backup:CopyIntoBackupVault.
  5. Resource types not fully managed by AWS Backup need a customer managed KMS key. AWS managed key policies cannot be shared across accounts.

AWS Backup does not restore from one account into another. Copy to the target account, then restore there. Cold-tier storage does not support cross-account copy. If the destination account later leaves the organization it keeps the copies, so the docs recommend an SCP that denies organizations:LeaveOrganization on it. SCP conditions on backup:CopyTargets or backup:CopyTargetOrgPaths restrict where copies may go.

§V. Vault Lock modes

GovernanceCompliance
How createdPutBackupVaultLockConfiguration without ChangeableForDayswith ChangeableForDays, 3 to 36,500 days
Removableby principals with the IAM permissiononly during grace time, before LockDate
After gracen/alock and vault immutable to every user and to AWS while recovery points remain
Retention boundsMinRetentionDays / MaxRetentionDays apply to new backup and copy jobs onlysame

Two traps. A recovery point with "Always" retention in a compliance vault is kept forever, with storage billed forever. And closing the account still ends the story: AWS suspends it for 90 days, then deletes vault contents even with Vault Lock in place.

§VI. Logically air-gapped vaults

A logically air-gapped vault comes locked in compliance mode, with an AWS owned key by default or a customer managed key chosen at creation. Its minimum retention is at least 7 days. Backups are stored in an AWS Backup service-owned account.

The RTO difference is sharing. A standard vault reaches another account only by copy. An air-gapped vault is shared through AWS RAM with individual account IDs, including accounts in another organization but never an OU or a whole organization, and the recovery account restores straight from it. Multi-party approval adds a recovery path when the owning account is inaccessible. Copying from an air-gapped vault back into a standard vault needs a customer managed key.

§VII. RPO, RTO, and tier

The DR whitepaper sets the line. Backup frequency sets achievable RPO. Backup and restore also redeploys infrastructure from IaC, so RTO is hours. Pilot light keeps data live in the recovery Region through continuous replication (RDS read replicas, Aurora global database, DynamoDB global tables, S3 replication) with app servers switched off. Replication carries corruption along with data, so pilot light still needs point-in-time backups. Restore is a control plane operation: the whitepaper suggests scheduled restores so a usable copy exists before the disaster.

Stem signalPrefer
"RPO 24 h, RTO a day, lowest cost"Backup and restore with cross-Region copy
"RPO minutes, RTO under an hour"Pilot light: continuous replication plus point-in-time backups
"Administrator credentials stolen; backups must survive deletion"Compliance-mode Vault Lock, copy in a separate account
"Restore in a clean account fast, no copy job"Logically air-gapped vault shared through RAM
"Enforce one plan in every member account"Organizations backup policy with @@none child control

§VIII. What not to do

  1. Answer a Hand stem with governance mode.
  2. Answer an Account stem with a same-account cross-Region copy.
  3. Restore directly into another account from a standard vault.
  4. Pick a cross-account copy into the default vault.
  5. Call cross-Region backup copies a pilot light.

§IX. Close instruction

On each practice stem, write Region, Account, or Hand before you read the answers. Then pick the control for that radius and check its fine print: same organization for cross-account copy, ChangeableForDays for compliance, account IDs for RAM sharing. Examine the stem twice when it says "root."

Related