Windows Server backups: wbadmin, scheduling and restic with VSS
Contents
For administrators who run an accounting system, remote desktops or files on a dedicated server with Windows Server. You will end up with a system image for bare-metal recovery and scheduled versions of files and database dumps, and you will have tested a restore in practice.
What Windows Server Backup does and where its limits are#
Windows Server Backup is a built-in feature of Windows Server 2016–2025 with a graphical console and the wbadmin command-line utility. It relies on the Volume Shadow Copy Service (VSS): Windows takes a point-in-time snapshot of the volume during the backup, so open files are copied in a consistent state and users do not have to sign out.
| What is backed up | wbadmin parameter | What it contains |
|---|---|---|
| Bare-metal backup | -allCritical | All critical volumes, that is, those holding the operating system and its state. From this backup a server is restored onto empty disks from the Windows Recovery Environment (WinRE). |
| System state | -systemState | The registry, boot files and, on a domain controller, Active Directory and SYSVOL as well. No user data. |
| Volumes, folders, files | -include:D:\Shares,D:\Dumps | Working data: shared folders, database dumps. |
Limitations to know before setup:
- A network folder keeps only the latest version. A new backup of the same server to the same folder overwrites the previous one. Microsoft warns that if the backup is interrupted you can end up with no backup at all, and recommends putting backups in separate subfolders. Several versions are kept only on a local disk or volume, but that sits in the same server.
- The
wbadmin enable backupschedule is daily only, at the times you set. A disk you give as the schedule target will be formatted. - Backups are not encrypted, so access to the folder holding them must be restricted.
- Databases. MS SQL Server has its own VSS component, so its databases are consistent in the snapshot. PostgreSQL has none: for it a snapshot is the same as a sudden power loss. In both cases dumps made with the database server’s own tools remain the basis — see “Database backups”.
Hence the practical scheme: wbadmin makes the system image, restic keeps versions of files and database dumps, and you keep a third copy outside the server.
What you will need#
- Windows Server 2016 or later and an account in the Administrators group. Licensing is not covered here.
- Space for backups outside the server’s disks. United Cloud servers come with backup space on separate storage that does not depend on the server: 500 GB on the Standard, Business, Power and Ultra lines and 100 GB on Classic; Lite has none, and for Turbo see the server card. The storage can be extended to 10 TB as a paid option through support. It makes no backups by itself: you set them up.
- The values in the examples are placeholders: server
SRV01,C:for the system,D:\Sharesfor files,D:\Dumpsfor database dumps;HOST,NAMEandPASSWORDare the host name, the storage name (which is also the login) and the password from support’s email. - Run
wbadmin,schtasksandicaclsin a command prompt (cmd) started as administrator: PowerShell splits comma-separated lists into separate arguments.
How to attach the storage#
The storage works with NFS (version 3 only), SMB (version 2.0 only), FTP and FTPS. wbadmin writes only to a local volume or to a shared folder given as a UNC path, so on Windows the storage is attached over SMB and its path takes the form \\HOST\NAME. Windows negotiates the protocol version automatically. FTP is no use for wbadmin or restic; FTPS is useful only for moving files by hand.
- Ask support to add the server’s IP address to the storage access list and to send the connection details. The storage cannot be reached from other addresses, including your office. Support also changes the password.
- Check access in a command prompt as administrator (the asterisk prompts for the password):
To see the storage as a drive in File Explorer, run
net use \\HOST\NAME /user:NAME * dir \\HOST\NAMENew-PSDrive -Name B -PSProvider FileSystem -Root \\HOST\NAME -Credential NAME -Persistin PowerShell. Inwbadminand restic commands, however, always give the full path:wbadminaccepts a network target only as a UNC path, and the drive letter and thenet useconnection exist only in your session.
No more than three simultaneous connections to the storage are allowed from one IP address, so do not run several backups at once.
Step 1 Install the feature#
In PowerShell as administrator:
Install-WindowsFeature Windows-Server-Backup
Get-WindowsFeature Windows-Server-BackupThe second command should report Installed.
Step 2 Make the first backup manually#
wbadmin start backup -backupTarget:\\HOST\NAME -allCritical -systemState -vssCopy -user:NAME -password:PASSWORD -quiet- The backup appears in the
WindowsImageBackup\SRV01folder on the storage. The-user:and-password:parameters pass the storage login and password. - The
-vssCopyparameter (the default) leaves application logs alone. Use-vssFullonly when no other program backs up the databases on these volumes: otherwise, Microsoft warns, you can break that program’s chain of incremental or differential backups.
Step 3 Set up a schedule#
Daily: wbadmin enable backup#
Warning. If you give
-addtargeta disk rather than a network folder, Windows formats it and all data on it is lost. Check the target before you run the command;wbadmin get diskslists disks and their identifiers.wbadmin disable backupcancels the schedule, but it will not bring back the data on a formatted disk.
The -user and -password parameters pass the storage login and password. According to Microsoft’s documentation, this user must belong to the Administrators or Backup Operators group on the server itself; if wbadmin refuses the storage login, check access with the net use command from the section above and contact support. Enable the schedule in cmd:
wbadmin enable backup -addtarget:\\HOST\NAME -schedule:02:30 -allCritical -systemState -vssCopy -user:NAME -password:PASSWORD -quietThe time in -schedule follows the server clock; several runs a day are separated by commas: 02:30,14:30. wbadmin enable backup without parameters shows the current settings. If support changes the storage password, disable the schedule and enable it again with the new password.
A different interval: Task Scheduler#
The system changes less often than the data, so a weekly image is often enough. wbadmin does not support such a schedule, so create a task instead of the daily schedule (if that is already enabled, run wbadmin disable backup first):
schtasks /create /tn "WSB weekly image" /sc weekly /d SUN /st 03:00 /ru SYSTEM /rl HIGHEST /tr "wbadmin start backup -backupTarget:\\HOST\NAME -allCritical -systemState -vssCopy -user:NAME -password:PASSWORD -quiet"The task runs as SYSTEM and does not see your session’s connections, so the storage login and password have to go into the command, where they are stored in the task in plain text. If that is unacceptable, keep the daily schedule.
Step 4 Versions of files and database dumps: restic with VSS#
restic encrypts backups, stores only changed blocks and keeps as many versions as you specify; as of October 2026 the latest version is 0.19.1. On Windows the --use-fs-snapshot option makes it read files from a VSS snapshot, so files locked by other programs are backed up too. This requires administrator rights. For Linux there is a separate article.
- Download
restic_0.19.1_windows_amd64.zipfrom the releases page linked from the restic documentation, compare its checksum (Get-FileHash) with theSHA256SUMSfile, unpack the archive and save the program asC:\Program Files\restic\restic.exe. - Create the folder
C:\Scriptsand in it two single-line files:restic-password.txtwith a long random repository password (Latin letters and digits) andstorage-password.txtwith the storage password. Leave access to the folder to SYSTEM and administrators only:Keep the repository password outside the server as well: without it you cannot open the repository.icacls C:\Scripts /inheritance:r /grant:r "*S-1-5-18:(OI)(CI)F" "*S-1-5-32-544:(OI)(CI)F" - Save the script
C:\Scripts\restic-backup.ps1. It connects the storage (a task running as SYSTEM cannot use your session’s connections), takes a snapshot and keeps 14 daily, 8 weekly and 12 monthly versions;--prunefrees the space the rest took up:$restic = 'C:\Program Files\restic\restic.exe' $env:RESTIC_REPOSITORY = '\\HOST\NAME\restic' $env:RESTIC_PASSWORD_FILE = 'C:\Scripts\restic-password.txt' $smb = Get-Content 'C:\Scripts\storage-password.txt' net use \\HOST\NAME /user:NAME $smb | Out-Null & $restic backup D:\Shares D:\Dumps --use-fs-snapshot --tag daily if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE } & $restic forget --keep-daily 14 --keep-weekly 8 --keep-monthly 12 --prune exit $LASTEXITCODE - In PowerShell as administrator, create the repository, take the first snapshot and register a daily task. The storage must be connected in this session (
net usefrom the section on attaching it); pick a time for the task when the database dumps have already finished:Set-Alias restic 'C:\Program Files\restic\restic.exe' $env:RESTIC_REPOSITORY = '\\HOST\NAME\restic' $env:RESTIC_PASSWORD_FILE = 'C:\Scripts\restic-password.txt' restic init restic backup D:\Shares D:\Dumps --use-fs-snapshot --tag daily $action = New-ScheduledTaskAction -Execute 'powershell.exe' -Argument '-NoProfile -File C:\Scripts\restic-backup.ps1' $trigger = New-ScheduledTaskTrigger -Daily -At '01:30' Register-ScheduledTask -TaskName 'restic-backup' -Action $action -Trigger $trigger -User 'NT AUTHORITY\SYSTEM' -RunLevel Highest
Like the system image, the repository can be reached only from servers whose addresses support has added to the storage access list. To restore data on another server, ask support to open access from its IP address too.
Why robocopy is not a backup#
robocopy with the /MIR parameter makes a mirror: whatever was deleted, damaged or encrypted by malware on the server becomes the same in the copy after the next run. There are no versions, and files held open by applications cannot be copied. It is fine for moving data to a new server (see the migration checklist), but not for backups.
How to check the result#
- List the backups:
The version identifier is in UTC, so it does not match the time in the Backup time line; use the identifier in commands.
wbadmin get versions - List the contents of a backup and restore a folder from it to a separate location (the identifier in the example is a backup made on 4 October at 02:30 Kyiv time):
Without
wbadmin get items -version:10/03/2026-23:30 mkdir D:\RestoreTest wbadmin start recovery -version:10/03/2026-23:30 -itemType:File -items:C:\Windows\System32\drivers\etc -recursive -recoveryTarget:D:\RestoreTest -quiet-recoveryTargetfiles return to their original location. Compare the restored files with the originals. - Check restic in the PowerShell window where the alias and variables from step 4 are set:
restic snapshots restic check restic restore latest --target D:\RestoreTest --include /D/Dumpsrestic ls latestshows the path inside the snapshot; the restored files appear inD:\RestoreTest\D\Dumps. - Restore the latest dump from that folder into a separate test database and open it in the accounting system. The procedure for PostgreSQL, MS SQL Server and BAS is in “Database backups”.
- The next day, make sure both lists have new entries and the tasks in Task Scheduler finished with code 0. Code 3 from restic means the snapshot was created but some files could not be read. Repeat the trial restore every quarter.
Bare-metal recovery is started from WinRE booted from installation media, so you will need the remote console: United Cloud provides it on request through support, and its Java version lets you attach an ISO image. The Lite line may not have a console. Agree the procedure with support beforehand, not on the day of the failure.
Common mistakes#
- Checking access to the storage only from your own session. Network drives and passwords entered in an RDP session do not exist for a task running as SYSTEM. Use the full
\\HOST\NAMEpath and pass the storage login and password in the task itself, as in the examples above; run the task manually and check its exit code. - Keeping the restic password only on the server. Lose the server and you cannot open the repository either.
- Not watching free space. The system image and the restic repository together must fit into the storage. When space runs out, the storage switches to read-only mode and new backups cannot be written until you free some space.
- Treating RAID or a second disk in the server as a backup. A mirror protects against a disk failure, not against deletion or encryption — see “How to check software RAID and disk health”.
What next#
- The storage has no append-only mode: a process on the server that can write backups can also delete them, so ransomware with administrator rights will reach them too. That is why you should add a third copy outside the server and the storage: in the office or at another site, for example in a second restic repository. The 3-2-1 rule explains how to distribute copies.
- If downtime is expensive, consider a standby site.
- Full syntax is in the wbadmin reference on Microsoft Learn and in the restic documentation.
- Servers with backup space are in the catalogue. Questions about attaching the storage go to support: +38 044 206 08 08, info@united.net.ua.