A backed-up OS image can have malware that can reinfect a machine after recovery.
The safe recovery functionality allows you to prevent recurrence of infections by using the integrated anti-malware scanning and malware deletion during the recovery process.
Limitations:
Safe recovery is supported only for physical or virtual Windows machines with Agent for Windows installed inside the machine.
The supported backup types are "Entire machine" or "Disks/volumes" backups.
Safe recovery is supported only for the volumes with NTFS file system. Non-NTFS partitions will be recovered without anti-malware scanning.
Safe recovery is not supported for CDP backups. The machine will be recovered based on the last regular backup without the data in the CDP backup. To recover the CDP data, start a Files/folders recovery.
How it works
If you enable the Safe recovery option during the recovery process, then the system will perform the following:
Scan the image backup for malware and mark the infected files. One of the following statuses is assigned to a backup:
No malware – no malware was found in a backup during scanning.
Malware detected – malware was found in a backup during scanning.
Not scanned – backup was not scanned for malware.
Recover the backup to the selected machine.
Delete the detected malware.
You can filter backups by using the Status parameter.