---
title: Automated Ransomware Recovery for Azure
description: This guide explains how to safely recover from ransomware attacks using Arpio's Enterprise feature, which quarantines systems and performs malware scanning during recovery.
---

[Skip to content](https://docs.arpio.io/azure/automated-ransomware-recovery-for-azure#main-content)

English

Show submenu for translations

[Customer ticket portal](https://docs.arpio.io/tickets-view?hsLang=en)

- Home
- Products
- Pricing
- Blog
- Company

Open main navigation

Close main navigation

- Home
- Products
- Pricing
- Blog
- Company
- English
  
  Show submenu for translations
- [Customer ticket portal](https://docs.arpio.io/tickets-view)

 Welcome to Arpio Technical Docs

- There are no suggestions because the search field is empty.

1. [Arpio Documentation](https://docs.arpio.io/?hsLang=en)
2. [Azure Reference Guides](https://docs.arpio.io/azure-reference-guides?hsLang=en)
3. [Azure Scenarios](https://docs.arpio.io/azure-reference-guides?hsLang=en#azure-scenarios)

# Automated Ransomware Recovery for Azure

This guide explains how to safely recover from ransomware attacks using Arpio's Enterprise feature, which quarantines systems and performs malware scanning during recovery.

### Enabling Ransomware Recovery

To activate this protection, check the "Enable Ransomware Recovery" box in the Failover dialog (this functionality is not available during a test).

![azure-unquarantine](https://docs.arpio.io/hs-fs/hubfs/azure-unquarantine.png?width=670&height=312&name=azure-unquarantine.png)

 

The system then:

- Completes a full failover of all resources, data, and configuration
- For each virtual network, Arpio provisions a deny-all Quarantine Network Security Group (NSG) and an empty Forensics Application Security Group (ASG). The Quarantine NSG blocks all outbound traffic and allows inbound traffic only from members of the Forensics ASG.
- For each Virtual Machine (VM) in the VNet, its NIC is configured to use the Quarantine NSG, effectively isolating the VM.
- Each VM is then started so it can be investigated via the Forensics ASG.
- Quarantined resources display a QUARANTINED status.

[![azure-quarantinelist](https://docs.arpio.io/hs-fs/hubfs/azure-quarantinelist.png?width=670&height=327&name=azure-quarantinelist.png)](https://github.com/caricalabs/arpio-docs-poc/blob/50650944f140f76cc5682aca0f69af0400387b04/docs/assets/images/azure-quarantinelist.png)

### Unquarantine Process

The UNQUARANTINE button opens a dialog allowing selection of single or multiple resources to release from quarantine.

![azure-unquarantine](https://docs.arpio.io/hs-fs/hubfs/azure-unquarantine.png?width=670&height=312&name=azure-unquarantine.png)

For each resource selected:

- On the NIC, the Quarantine NSG is replaced with the original NSG (if one existed) or removed if there was no NSG originally. This restores original network connectivity.
- The resource's "QUARANTINED" status is removed.

### Conclusion

Once all resources are unquarantined, you can proceed with failback or conclude recovery operations.

- [Getting Started](https://docs.arpio.io/getting-started?hsLang=en#main-content)
  
  
  
  
  
    - [New Account Setup](https://docs.arpio.io/getting-started?hsLang=en#new-account-setup)
    - [New Application Setup](https://docs.arpio.io/getting-started?hsLang=en#new-application-setup)
- [Arpio Fundamentals](https://docs.arpio.io/arpio-fundamentals?hsLang=en#main-content)
  
  
  
  
  
    - [Platform Fundamentals](https://docs.arpio.io/arpio-fundamentals?hsLang=en#platform-fundamentals)
    - [Platform Features](https://docs.arpio.io/arpio-fundamentals?hsLang=en#platform-features)
- [Arpio Reference Guides](https://docs.arpio.io/arpio-reference-guides?hsLang=en#main-content)
  
  
  
  
  
    - [Arpio API](https://docs.arpio.io/arpio-reference-guides?hsLang=en#arpio-api)
    - [Lifecycle Events](https://docs.arpio.io/arpio-reference-guides?hsLang=en#lifecycle-events)
    - [Role-Based Access Controls (RBAC)](https://docs.arpio.io/arpio-reference-guides?hsLang=en#role-based-access-controls-rbac)
    - [Single Sign-On (SSO) Integration](https://docs.arpio.io/arpio-reference-guides?hsLang=en#single-sign-on-sso-integration)
    - [Test Planning](https://docs.arpio.io/arpio-reference-guides?hsLang=en#test-planning)
    - [Test & Recovery How-To](https://docs.arpio.io/arpio-reference-guides?hsLang=en#test-recovery-how-to)
- [AWS Reference Guides](https://docs.arpio.io/aws-reference-guides?hsLang=en#main-content)
  
  
  
  
  
    - [AWS Resource Reference](https://docs.arpio.io/aws-reference-guides?hsLang=en#aws-resource-reference)
    - [AWS Configuration Tags](https://docs.arpio.io/aws-reference-guides?hsLang=en#aws-configuration-tags)
    - [AWS Access](https://docs.arpio.io/aws-reference-guides?hsLang=en#aws-access)
    - [AWS Testing](https://docs.arpio.io/aws-reference-guides?hsLang=en#aws-testing)
    - [AWS Solutions](https://docs.arpio.io/aws-reference-guides?hsLang=en#aws-solutions)
- [Azure Reference Guides](https://docs.arpio.io/azure-reference-guides?hsLang=en#main-content)
  
  
  
  
  
    - [Azure Resource Reference](https://docs.arpio.io/azure-reference-guides?hsLang=en#azure-resource-reference)
    - [Azure Configuration Tags](https://docs.arpio.io/azure-reference-guides?hsLang=en#azure-configuration-tags)
    - [Azure Scenarios](https://docs.arpio.io/azure-reference-guides?hsLang=en#azure-scenarios)
- [FAQ](https://docs.arpio.io/faq?hsLang=en#main-content)
  
  
  
  
  
    - [AWS FAQ](https://docs.arpio.io/faq?hsLang=en#aws-faq)
    - [Contact Support](https://docs.arpio.io/faq?hsLang=en#contact-support)
    - [License & Billing](https://docs.arpio.io/faq?hsLang=en#license-billing)
    - [Tests and Recoveries](https://docs.arpio.io/faq?hsLang=en#tests-and-recoveries)

- Home
- Products
- Pricing
- Blog
- Company

[![bubble-wand-tight.64](https://docs.arpio.io/hs-fs/hubfs/bubble-wand-tight.64.png?width=64&height=64&name=bubble-wand-tight.64.png "bubble-wand-tight.64")](https://arpio.io)

Copyright © 2026, Arpio