What business continuity looks like after you move off legacy on-premises ERP — and the
Four Tiers of Protection
Nearly every serious conversation about leaving a legacy on-premises ERP reaches the same moment. The demo has gone well, the licensing math works, everyone agrees the old system is holding the business back — and then somebody near the end of the table asks the question that has been sitting underneath all the others. What happens if it disappears?
It is a fair question, and the people who ask it are rarely obstructionists. They are usually the ones who have carried the operation on their backs for two decades. They have a server they can walk to. They know which drive whines. They have restored from tape at two in the morning and watched the order desk come back to life. That knowledge is real, and no amount of enthusiasm about modern platforms should be allowed to dismiss it.
But it is worth being precise about what that server actually provided, because the comfort it offered and the protection it offered were never quite the same thing.

On-Premises Promises
A machine you can touch supplies a powerful feeling of custody. Underneath it, though, most on-premises ERP deployments were single points of failure wearing a cardigan. One building. One power feed. One aging RAID controller. One backup routine that ran nightly and was verified — honestly, now — how often? One person who understood the restore procedure and who is three years from retirement. The risk was not absent. It was simply familiar, and familiarity is easily mistaken for safety.
Moving to Dynamics 365 Business Central does not trade that risk for a new and stranger one. It relocates the ordinary failures — hardware, power, patching, physical security, geographic redundancy — onto infrastructure engineered and staffed at a scale no mid-market company could fund on its own. Those are the failures that actually took companies down. They are now largely someone else’s full-time job.

What We All Worry About
What remains is a narrower and more sophisticated worry, and it deserves to be met directly rather than talked around: if my data lives entirely inside one provider’s cloud, what happens if I cannot reach that provider at all? Not a bad update or a deleted record — a regional outage, a tenant compromise, a scenario in which the platform itself is the thing that is unavailable.
Here is the honest answer, which turns out to also be the reassuring one. Microsoft’s native protections in Business Central are genuinely good, and they are not the whole of a continuity plan. What they do not provide is an independent copy outside the provider’s control. Anyone who tells you otherwise is selling rather than advising.
That gap is real, it is entirely closable, and closing it is ordinary work. Here is the actual roadmap, from simplest to most comprehensive.

Four Tiers of Resiliency
Tier One — Microsoft’s Native Protection
Included with Business Central SaaS at no additional cost, and effective against the failures that occur most often: accidental deletion, data corruption, a failed update, an honest mistake by a user.
- Microsoft-managed database backups
- Environment restore, including to a point in time
- Sandbox refresh and recovery options
- Geo-redundant Azure storage, managed for you
The limit: recovery remains dependent on Microsoft’s infrastructure, and none of it constitutes an independent copy under your own control. Keep this as your baseline. Do not let it be your whole plan.
Tier Two — Independent Recovery Repository
Periodic exports of data and configuration written to a separate Azure subscription, with its own storage account, its own administration, and its own credentials.
- A security boundary that a compromise of your production tenant does not cross
- Recovery dramatically faster than rebuilding from scratch
- Relatively low complexity, and the fastest of the independent options to restore from
- Can be designed, implemented, and managed on your behalf
The limit: it still resides within Azure, so it does not fully answer a provider-wide scenario. Even so, for most companies this is the single highest-value step past the baseline — the best balance of cost and resiliency available.
Tier Three — Cross-Cloud Archive
Critical exports and recovery assets replicated out of Azure entirely, to AWS S3 or another independent platform.
- Genuine independence from any single cloud provider
- Protection against provider-specific outages
- Long-term retention on your own schedule
- Strong ransomware protection where immutable storage is used
The cost: higher spend, more operational complexity, and recovery that depends on documented and rehearsed procedures. This is the tier that actually answers the question about the provider itself being unavailable, and it is the closest match to what most companies mean when they raise the concern.
Tier Four — Immutable or Offline Backup
A local appliance or a purpose-built backup platform — Datto, Veeam, Rubrik, Cohesity and their peers — holding an air-gapped copy outside every cloud.
- Complete independence from cloud providers
- Supports cyber-recovery and ransomware scenarios
- Frequently what security auditors and cyber insurers want to see
The cost: hardware, disciplined testing and maintenance, and the highest operational responsibility of the four. This is the right tier when cybersecurity or compliance requirements specifically mandate offline copies.
Notice what tiers one through three amount to together: production, an independent copy, and a copy on separate infrastructure. That is the same 3-2-1 discipline the best on-premises shops always practiced.
The principle has not changed at all. Only the addresses have.

What Needs Protecting
One point gets missed more often than any other, and it matters more than which tier you choose. In a modern Business Central environment, the database is not the whole asset. A continuity plan should cover:
- Configuration — setup tables, extensions, security roles and permissions
- Master data — customers, vendors, items, dimensions
- Transactional data — orders, inventory, general ledger, receivables and payables
- Integrations — EDI configurations and mappings, storefront and marketplace connections, 3PL interfaces
- Warehouse and shipping setup — including any industry-specific extensions
- Reporting assets — Power BI models and datasets
- Documentation — integration specifications and the operational notes that explain why any of it is arranged the way it is
Restoring transactions without those means being back in business on paper and nowhere near it in practice. Where a company has invested years in EDI, warehouse configuration, and integration work, exports of those configurations must be part of the plan — not just the database.
Insist on that point with whoever is advising you.

The New Dependency
Candor requires naming one genuine change. When the application lived down the hall, a carrier outage was an inconvenience. When it lives in the cloud, the circuit is part of the system. If the building loses internet, the warehouse stops scanning and EDI stops moving, however healthy the platform may be.
This is a solved problem, and inexpensively so. Carrier-diverse connectivity combines circuits from two different providers into a single managed service:
- Redundant circuits from separate carriers
- Automatic failover, with no manual intervention during an outage
- Load balancing across both circuits during normal operation
- Continuous monitoring and optimization
These solutions are often available at a monthly cost comparable to the single enterprise circuit already in place.
It is the least glamorous item on any continuity list and frequently the highest return.

The Plan, In Order
Layered, and sequenced so that each step is worth doing on its own:
- Continue leveraging Microsoft’s native Business Central protection as the baseline.
- Stand up an independent recovery repository in a separate subscription under separate credentials.
- Replicate critical backups and configuration exports to AWS or another independent platform.
- Add immutable or offline storage where cyber-recovery or compliance requirements call for it.
- Implement carrier-diverse internet connectivity with automatic failover and load sharing.
- Test the restore, on a schedule, and document what you learned.
That last step is the one most often skipped, and it is the one that converts a plan into a capability. An untested backup is a belief.
Together, these measures cover application availability, data protection, disaster recovery, cyber-resilience, and network connectivity — the full set of ways an operation actually goes dark.

Peace of Mind, Delivered
The deepest misconception about moving to the cloud is that it means handing over the keys. It does not. It means deciding, deliberately, where each copy of your business lives and who can reach it — a decision most companies never actually made about the server in the closet. They inherited it.
You can hold your own copy. You can put it somewhere your primary provider cannot touch. You can prove the restore works before you need it. The question was never whether the cloud is safe. It is whether you have been given a clear-eyed account of the risks and a specific answer to each one. If you have, the move is not a leap. It is an upgrade to a discipline you already believed in.
That clear-eyed account is what we would like to give you, whether you ever become a client (or not).
Ask us for a business continuity review of your environment. We will map your current protections against the four tiers, identify exactly where the gaps are, tell you which ones are worth closing and which are not, and put a cost and a sequence against each one. No obligation, and no pressure toward the most expensive answer — for most companies the right plan is tier two plus tested restores, and we will say so.
If you are evaluating a move off a legacy on-premises system, bring the continuity question to the table early rather than late. It is far easier to design the plan alongside the implementation than to retrofit it afterward. And if you are already running Business Central and have never tested a restore, that is the conversation worth having this quarter.
We will set up a work session with the right technical resources to review business continuity architectures, costs, and options for your organization.


Leave a comment