Create a runbook that specifies the cleanroom site and the region to recover to.
Note
For details about the resources that Commvault Cloud creates in your Azure subscription when you use the express configuration and/or Create new options, see Resources automatically created in your Azure or Commvault subscription for cleanroom recovery.
Start the add runbook wizard
-
In the Command Center navigation pane, go to Security services > Cleanroom.
-
On the Recovery groups tab, click the recovery group to create a runbook for.
-
On the Runbooks tab, click Add runbook.
-
Select Microsoft Azure.
-
Click Next.
General page
-
Enter a name for the runbook.
-
For Cleanroom site, leave Create new selected.
-
For Region, select the region to recover VMs/instances to.
-
Create an Azure application using either the express or custom configuration.
The express configuration creates an Azure application called Commvault Cloud App for you.
-
Select Express configuration.
-
Sign in with Microsoft as a Global Administrator for your cleanroom recovery Azure subscription, and then consent on behalf of your organization.
-
If you are a Commvault software customer, when you're prompted to sign in again and asked to grant access to Azure Resource Manager, sign in as an Owner for your cleanroom recovery Azure subscription, and then consent on behalf of your organization.
Commvault Cloud creates the app.
-
Return to the wizard, and then enter your Azure subscription ID.
The custom configuration provides Bash and PowerShell commands for creating the Azure application, and a button to open Azure Cloud Shell for running the commands. (You can also create the Azure application in the Azure portal. For instructions, see Quickstart: Register an application with the Microsoft identity platform.)
-
For Destination hypervisor, leave Create new selected.
-
Enter the ID of your cleanroom recovery Azure subscription.
-
In the information box, click Deploy a new application.
The Deploy a new application dialog box appears.
-
In the commands, replace
"Contributor"withCommvault_Cleanroom.json. -
In the information box, click Open Azure Cloud Shell, log on to the Azure portal as the subscription owner, and then execute the displayed commands to deploy the application.
-
Copy the following values, and then return to the wizard:
- Tenant ID
- Application ID
- Application secret
-
Use the copied values to create a new credential.
-
-
Click Next.
Resources page
The Resources page displays the resources associated with the recovery group.
Advanced options page
-
Specify validation options:
-
Run threat scan: Run a threat scan on all VMs/instances.
Every 7 days, the count of discovered threats is reset to 0.
Threat scan requires auto-scaling. For AWS cleanroom sites, you must configure auto-scaling. For Azure cleanroom sites, auto-scaling is configured by default.
-
Run Windows Defender: Run a Microsoft Windows Defender Antivirus scan on Windows VMs/instances.
-
-
For Custom scripts, you can specify scripts to validate VMs/instances after they're recovered:
-
Click Add.
-
Upload a file or enter a UNC path and credentials to access the path.
UNC path examples:
- Windows: Enter the UNC path as WindowsPathwin.ps1.
- Unix: Enter the UNC path as \\Pathtofile\file.sh.
-
Enter a name for the script, and then click Save.
-
-
To finish creating the runbook, click Submit.
For information about other settings on this page, see Modify settings for a cleanroom recovery group.