BLOG · GUIDE ·

vCenter backup and restore: file-based backups, the schedule, the restore and what it misses

Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software

IN BRIEF
  • The file-based backup is set in the vCenter management interface on port 5480 under Backup, Configure, and streams core configuration, inventory and optional stats, events and tasks to an FTP, FTPS, HTTP, HTTPS, SFTP, NFS or SMB server; only one schedule can exist, and retention counts manual backups too
  • A restore deploys a new appliance from the GUI installer and copies the backup into it; the installer has to match the patched build that was backed up, the original appliance must be powered off, and a vCenter HA cluster has to be rebuilt afterwards
  • After a restore, DRS rules, resource pools and VM resource settings revert to the backup, storage policy changes and newly registered storage providers are lost, and the vSphere HA cluster state can roll back while the hosts keep a newer one
  • Broadcom’s KB 318731 says vCenter 6.x to 9.0 support file-based and image-based backups and recommends the process in the management interface; distributed switches need an export after each change, and a Native Key Provider needs one backup of its own before use
  • In VCF 9.0, SDDC Manager sets hourly NSX Manager backups at bring-up, daily vCenter and SDDC Manager backups kept for 7 days are recommended, VCF Operations is backed up image-based, and for ESXi hosts Broadcom supports a configuration backup and a reinstall, not image-level backups

Eurokommerz × Vixen.UNO: VMware Optimisation  Talk to an expert →

How to back up vCenter with the file-based backup

To back up vCenter, open the appliance’s management interface at https://<vcenter-fqdn>:5480, sign in as root, click Backup, then Configure, and enter a backup location, credentials, a schedule, an optional encryption password and the number of backups to retain. vCenter streams its core configuration, inventory and, if selected, historical data to an FTP, FTPS, HTTP, HTTPS, SFTP, NFS or SMB server, and in Broadcom’s words “The backup is not stored on the vCenter.” To restore, the GUI installer deploys a new appliance and copies the backup into it. Broadcom’s KB 318731 says that vCenter 6.x, 7.0, 8.0 and 9.0 “support File-Based and Image-Based backups” and that the recommended process “is done through the VAMI”, this management interface.

A restore returns vCenter to the moment of the backup while the ESXi hosts keep their current state, so some settings revert. NSX Manager, SDDC Manager and VCF Operations have backups of their own.

vCenter backup schedule: protocols, retention and historical data

In the Create backup schedule dialog, Backup location takes the protocol, port, server address and folder, and Backup server credentials a user with write privileges. Schedule runs daily, weekly or on chosen weekdays, by default at 11:59 pm. Encrypt backup sets a password that the restore needs, Number of backups to retain offers Retain all backups or a number, and Stats, events, and tasks adds historical data from the database. Only one schedule can exist, and Backup Now adds a manual backup.

Broadcom’s considerations page warns that “FTP and HTTP are not secure protocols”; FTPS works only in explicit mode, HTTP and HTTPS need WebDAV, and only FTP, FTPS, HTTP and HTTPS pass through an HTTP proxy. The server must accept at least 10 simultaneous connections per vCenter, IPv4 and IPv6 may not be mixed, and KB 322371 says the ports must be open in both directions.

Retention “applies to both manual and scheduled backups”, so with a fixed number, a manual backup before maintenance replaces an older one. KB 435925, which lists no fix as of October 2026, reports that scheduled backups of several vCenter instances on 8.0 Update 3i or later, or 9.x, fail intermittently with “server validation failure” when they write to one directory at exactly the same time. Its workaround offsets the start times by at least 5 to 10 minutes. In VCF, where SDDC Manager and all vCenter backups must start within the same 5-minute window, we would give each vCenter its own folder, since the KB traces the collision to a shared directory. Give the target its own service account, outside the directory that grants vCenter administrator rights; how attackers deleted backups after reaching vCenter is in our guide to ESXi ransomware hardening.

Image-based backup of the vCenter appliance

Broadcom’s vSphere 8.0 and 9.0 guides also document a full image backup of the vCenter VM, made with “vSphere APIs with a third-party product”. The VM needs an FQDN with correct DNS resolution or an IP address as host name, and while vCenter is down the backup product can restore straight onto the ESXi host that runs its appliance. Restoring VMs with snapshots or Fault Tolerance “is unsupported”. VCF 9.0 lists vCenter as “File-based or Image-based”, and its own procedures use the file-based backup. We recommend the file-based schedule as the primary backup and an image-level copy as a second path. Which Veeam job protects what is in our guide to Veeam replication and backup copy jobs.

How to restore vCenter from a file-based backup

The GUI installer restores in two stages, the same in 8.0 and 9.0: stage 1 deploys a new appliance, and stage 2 copies the backup into it.

  1. Mount the installer ISO of the backed-up build; for a patched vCenter, Broadcom asks for “the full ISO of that particular patch”.
  2. Power off the backed-up vCenter, or the active, passive and witness nodes of a vCenter HA cluster.
  3. Pick an ESXi host not in lockdown or maintenance mode or part of a fully automated DRS cluster, and check the forward and reverse DNS records of a static IP address.
  4. Run the installer from the vcsa-ui-installer folder, click Restore, and on Enter backup details give the location and a user with read privileges.
  5. Connect to the target, set the appliance name, root password, deployment size and datastore, and adjust the values from the backup on Configure network settings.
  6. In stage 2, for a node in Enhanced Linked Mode, enter the Single Sign-On credentials and click Validate and Recover, then Finish.
  7. Reapply security patches installed after the backup and rebuild vCenter HA where it was used.

If a restore fails, Broadcom says to power off and delete the partially restored VM. In VCF, the failed vCenter is powered off and renamed, “the backup must be of the version of the vCenter appliance on which you plan to restore the instance”, and when both have failed, the management domain vCenter comes back before the workload domain one. A vCenter upgrade to 9.0 deploys a new appliance, as our vSphere 8 end of support guide describes, so back up again after it and keep the old ISO while you keep old backups.

What a vCenter restore misses: settings that revert or are lost

Broadcom’s considerations pages for 8.0 (16 September 2026) and 9.0 (24 August 2026) list what a restore changes.

AREAAFTER A RESTOREWHAT TO DO
DRS and resource poolsVM resource settings, resource pools, cluster-host membership and DRS rules revertredo the changes made since the backup
Storage DRSdatastore clusters, Storage I/O Control settings and host-datastore membership might changecheck the datastore clusters
VMs and linked clonesvCenter’s view can differ from the hosts’; VMs may be orphanedadd or register them again; let linked clones be discovered before removing VMs
vSphere HAthe cluster state may roll back while the hosts keep a newer oneleave the HA cluster state unchanged while a backup or restore runs
Storage policiesproviders registered and policy changes made after the backup are lostregister the providers, redo the changes
Content librarieslibraries and items created after the backup are unknown; deleted ones are unusableclean them up manually
vSANinconsistencies are possiblecheck vSAN health
vCenter HA and patchesvCenter HA needs reconfiguring; later patches are missingreconfigure it, apply the patches again

Broadcom TechDocs, Considerations and Limitations for File-Based Backup and Restore, vSphere 8.0 and 9.0; actions for DRS, Storage DRS and storage policies are ours.

vSphere Lifecycle Manager adds two cases (9.0, 24 August 2026). A cluster switched from baselines to an image after the backup comes back on baselines, and “you must again use baselines to manage it”. A cluster remediated to a newer image after the backup shows its hosts as incompatible, and “Because you cannot downgrade ESX”, its image must move up to match them; see our guide to vLCM baselines and images.

For vSphere Native Key Provider, which lets VMs have virtual TPMs, Broadcom says it “is backed up as part of the vCenter Server file-based backup”, but that you must back it up on its own “at least once before you can use it”.

Our VMware optimisation service starts with an audit of the estate, its versions and risk profile. Tell us how your vCenter instances are backed up today, which builds they run and whether a restore has been tried.

Distributed switch export and Enhanced Linked Mode

Broadcom advises exporting “the distributed virtual switch configuration before you restore from a backup”, because switch changes made after the backup may be lost, though hosts added or removed are kept. Broadcom’s VCF 9.0 procedure exports a switch “immediately after each change in configuration of that switch”: in the vSphere Client, right-click the switch, select Settings, Export Configuration, choose Distributed switch and all port groups, note the date in Description and store the zip file outside vCenter. After a vCenter restore, Restore Configuration applies such a file to a switch that still exists, and Import Distributed Switch with Preserve original distributed switch and port group identifiers recreates a missing one with its port groups and hosts; neither brings back the connections of physical NICs to uplink ports. The vCenter 8.0 Update 2 release notes say such changes now “persist when a vCenter is restored from backup”; the considerations page still advises the export.

To restore a vCenter in Enhanced Linked Mode, “you must have at least one running vCenter Server that has the VMware Directory Service database”; if all nodes have failed, restore the first without replication partners, then the rest according to the topology. In 9.0, ELM “is deprecated and will be removed in a future release”, and Broadcom names grouping under VCF Operations as the alternative.

NSX Manager, SDDC Manager and VCF Operations backups

The VCF 9.0 backup overview (29 September 2026) calls an external SFTP server “a prerequisite for restoring SDDC Manager file-based backups”.

NSX Manager backs up to SFTP only, its backup includes the NSX Edge configuration, and “If you forget the passphrase, you cannot restore any backups.” A restore needs a new appliance with the IP address or FQDN of the backup, and a cluster returns one node first, with the others added afterwards (NSX 4.2, July 2026). In VCF, SDDC Manager configures hourly NSX Manager backups during bring-up.

In VCF 9.0, SDDC Manager backups are set in VCF Operations under Administration, SDDC Manager, Backup Settings, SDDC Manager Configurations, and its jobs and those of all vCenter instances must start “within the same 5-minute window”. VCF Operations is protected by “full virtual machine image-based backup jobs” in a backup product compatible with vSphere Storage APIs for Data Protection (VADP). In VCF 9.1 (5 October 2026), the file-based schedules of SDDC Manager and vCenter are still configured manually.

For ESX the 9.0 overview has “N/A”, and KB 445744 says image-level and bare-metal backups of ESXi “are not a supported backup or recovery method”, so back up the configuration and reinstall. KB 313510 saves it with vim-cmd hostsvc/firmware/sync_config, then vim-cmd hostsvc/firmware/backup_config, and restores it onto a host of the same build; on hosts with TPM enabled, since 7.0 Update 2, only with “the same TPM that was used on the host during backup”.

COMPONENTHOW TO BACK IT UPHOW OFTEN
vCenterfile-based; image-level copy as a second pathdaily, 7 days kept (VCF 9.0)
Distributed switchesSettings, Export Configurationafter each change; last 3 kept
Native Key ProviderBack Up under Key Providersonce before use, then in the vCenter backup
ESXi hostsconfiguration bundle, reinstallafter changes; the KBs give no interval
NSX Manager and Edgesfile-based to SFTP, passphrasehourly, 7 days kept (VCF 9.0)
SDDC Managerfile-based to SFTP, set in VCF Operationsdaily, 7 days kept (VCF 9.0)
VCF Operationsimage-based, VADP backup productno interval on the pages we read

Broadcom TechDocs: VCF 9.0 backup and restore, vSphere 8.0 Native Key Provider, NSX 4.2 backup; KB 313510 and 445744. The second path for vCenter and the ESXi interval are ours.

Testing a vCenter restore without touching production

Because the restore expects the backed-up vCenter to be powered off and reuses its network settings, a test restore while production runs belongs in an isolated segment with no route to the production management network. These steps are ours, not Broadcom’s.

  1. Take the newest scheduled backup and the ISO of its build, and note the start time.
  2. Give the isolated VLAN, or a virtual switch without uplinks, a DNS server for the vCenter name, a file server with a copy of the backup and a machine with the installer that also reaches the target host.
  3. Restore onto a host outside the production clusters into that segment, keeping the network settings from the backup.
  4. Sign in with a Single Sign-On administrator account and check that the services run and the inventory matches the backup date.
  5. Record the time to that sign-in and every step that failed or lacked a password, then delete the test appliance and update the restore runbook.

Repeat the test after each vCenter update, since the restore needs the ISO of the backed-up build; our guide to the disaster recovery runbook shows how to write the steps for someone other than their author.

Under our cyber resilience service, our engineering partner Vixen.UNO runs regular test restores to verify backup integrity. Write to us with the date of your last vCenter restore test and what it covered.

What we do

Under VMware optimisation, our engineering partner Vixen.UNO audits your VMware estate, its versions and risk profile, and modernises vSphere, vSAN, NSX and VCF in agreed maintenance windows, with a rollback plan at every stage; Veeam-based backup strategies are part of the same service. Test restores belong to our cyber resilience service. Eurokommerz holds the contract; the first call is free of charge, and the price of the technical assessment is fixed before work begins.

FAQ

How do I back up the vCenter Server appliance?
Use the file-based backup in the appliance’s management interface on port 5480: click Backup, then Configure for a schedule or Backup Now for a single backup, with a location on an FTP, FTPS, HTTP, HTTPS, SFTP, NFS or SMB server. The backup holds the core configuration, the inventory and, if selected, stats, events and tasks, and it is not stored on vCenter itself. Broadcom’s KB 318731 says image-based backups are supported too but names the management interface as the recommended process.
How do I schedule a vCenter backup?
In the management interface, click Backup, then Configure, and fill in Backup location, Backup server credentials, Schedule (daily, weekly or chosen days, default time 11:59 pm), Encrypt backup and Number of backups to retain. Only one schedule can exist at a time, and the retention setting covers manual and scheduled backups alike. Broadcom’s VCF 9.0 example runs daily at 11:00 PM and keeps the last 7 backups.
How do I restore vCenter from a file-based backup?
Run the vCenter GUI installer of the same patched build the backup was taken on, choose Restore, point it at the backup location and deploy a new appliance; stage 2 then copies the data into it. Power off the original appliance first, and in Enhanced Linked Mode enter the Single Sign-On credentials when asked. Afterwards, reapply patches installed since the backup and reconfigure vCenter HA if you used it.
Is image-based backup of vCenter supported?
Yes. Broadcom’s KB 318731 says vCenter 6.x, 7.0, 8.0 and 9.0 support file-based and image-based backups, and its documentation allows a full image backup of the vCenter VM with a third-party product that uses the vSphere APIs. The VM needs an FQDN with correct DNS resolution or an IP address as its host name, restoring VMs with snapshots or Fault Tolerance is unsupported, and Broadcom recommends the file-based process.
What is not restored with a vCenter backup?
Broadcom lists changes made after the backup that a restore reverts or loses: DRS rules, resource pools and VM resource settings revert, storage policy changes and storage providers registered later are lost, and the vSphere HA cluster state may roll back while the hosts keep a newer one. Broadcom also advises a separate export of distributed switch configurations, and a vSphere Native Key Provider has to be backed up once on its own before use. NSX Manager, SDDC Manager, VCF Operations and the ESXi host configuration have backups of their own.
How do I back up NSX Manager and SDDC Manager in VCF?
In VCF 9.0, SDDC Manager configures hourly NSX Manager backups to an SFTP server during bring-up, Broadcom recommends 7 days of retention, and the NSX Edge configuration is part of that backup. SDDC Manager backups are set in VCF Operations under Administration, SDDC Manager, Backup Settings, and Broadcom recommends daily backups kept for 7 days. VCF Operations itself is backed up image-based, with a product compatible with vSphere Storage APIs for Data Protection.

Send us your vCenter build and, where you run them, your NSX Manager and SDDC Manager versions, where each is backed up today with its schedule and retention, and the date of your last restore test. We reply within one business day to arrange a first call, from which you leave with 2 to 3 possible solution scenarios. The first call is free of charge.

Talk to an expert
Talk to an expert

We reply within one business day

By sending this form you agree that we process your details to answer your enquiry – see our privacy policy.

request@eurokommerz.at
Jordangasse 7, 1010 Vienna