Introduction
An enterprise client running Microsoft Dynamics 365 Finance & Operations (F&O) and Supply Chain Management (version 10.0.45) depended on Microsoft’s cloud services to back up its cloud-hosted database. The business needed something that cloud-based backup could not give it: a copy of its ERP data held outside the Microsoft cloud.
The client asked Nalashaa to replace manual, ad-hoc exports with a scheduled, resilient architecture. The objective was clear: build a fully automated pipeline that produces native SQL .BAK files in local cold storage, independent of the Microsoft cloud, and prove it works with a real restore.
The Challenge
Owning a Recoverable Copy of a Cloud-Hosted ERP
-
Backup That Depends on the Cloud It Protects
Backups held only in the same cloud as the system they protect offer limited protection when access is lost. Challenges included:
- No independent, locally held copy of ERP data that survives a connectivity or tenant-access disruption
- Reliance on manual, ad-hoc exports, with no fixed schedule, no monitoring and no clear owner
- No evidence that a given backup could actually be restored, and how quickly
- A need for true offline data sovereignty rather than another copy inside the Microsoft cloud
-
A Cloud ERP That Does Not Hand Over Its Database
Dynamics 365 F&O does not give direct access to the production database, so a local copy has to be built in stages. Key obstacles:
- Production data can only leave through a controlled route: a database export from a Sandbox to the Lifecycle Services Asset Library as a .BACPAC file
- A .BACPAC is a logical, portable representation of the database, and rebuilding from it is slower than restoring a native SQL backup, which matters for recovery time
- Producing a native .BAK file requires an intermediate SQL Server, a Tier-1 developer instance acting as a “Staging Bridge”
- Microsoft documents that exports leave out certain data, such as non-admin users, batch job state and document attachments, so restore expectations have to be explicit
-
Automating a Multi-Hop Process Without Losing Control
The path from production to a local disk crosses several services and long-running steps. Challenges included:
- Long-running exports with asynchronous status, so downloads must wait for completion rather than run on a fixed timer
- Scheduling at a configurable 12- or 24-hour cadence, with failures visible rather than silent
- Confirming that the environment (v10.0.45, Sandbox tiers, a Tier-1 instance) could support automated extraction without affecting daily operations
- Delivering within the client's own Azure tenant, without third-party tools or licences
Our Solution: A Staging-Based Backup Framework with a Restore-Based Acceptance Gate
Nalashaa implemented a client-aligned staging-based backup approach: the cloud export is automated through the LCS and Power Platform APIs, a Tier-1 Staging Bridge converts the data into native SQL .BAK files, and the files land in local NAS/HDD cold storage, all orchestrated from the client's own Azure tenant.
The solution allowed the client to:
- Replace manual exports with a scheduled, hands-off pipeline running every 12 or 24 hours
- Hold both a portable .BACPAC archive and a native .BAK file for the fastest possible recovery
- Keep a cold-storage copy independent of the Microsoft cloud
- Prove the design with a successful restore before sign-off
- Achieve all of this without new third-party tools or licences
This approach ensured the client's data sovereignty was demonstrated, not just designed. We delivered the solution as three tasks, closed by a restore-based acceptance gate.
-
Technical Discovery & Automated Cloud Extraction
SOLUTION HIGHLIGHTS
- Ran an environmental compatibility audit of the Dynamics 365 F&O v10.0.45 environment and Sandbox tiers, confirming that automated extraction would not affect daily operations
- Completed an asset inventory and integration review of the Power Apps, Power Automate flows and Power BI reports in scope, so the wider ecosystem is mapped for backup
- Automated the database export chain through the LCS and Power Platform APIs: production data to the Sandbox, then out to the LCS Asset Library as a .BACPAC file
- Built status monitoring so the .BACPAC is downloaded to local storage only once the export has completed
TECHNICAL ENHANCEMENTS
- Azure Logic App and PowerShell orchestration, replacing manual export steps
- Status polling instead of fixed waits, so long-running exports finish cleanly
Outcome: A hands-off cloud extraction that turned an ad-hoc task into a repeatable, monitored process.
-
Staging Bridge & Native .BAK Generation
SOLUTION HIGHLIGHTS
- Configured a Tier-1 developer instance as the Staging Bridge, the physical bridge between the cloud export and local SQL Server backups
- Used the SqlPackage utility to synchronise the exported production data into the Staging Bridge
- Generated native SQL .BAK files from the staged database, enabling restoration on local SQL servers
- Copied each .BAK to local NAS/HDD cold storage, keeping the .BACPAC as the portable archive alongside it
- Deployed the automation inside the client's own Azure tenant
TECHNICAL ENHANCEMENTS
- A physical .BAK alongside the logical .BACPAC: two formats from one cycle
- No additional virtual machine management beyond the single Staging Bridge
Two formats, two jobs: a .BACPAC is portable across SQL versions and suits long-term archiving, while a native .BAK is a physical copy that restores far faster on a local SQL Server, giving the shortest Recovery Time Objective.
Outcome: The client gained a fast-restoring native backup, not just a portable archive.
-
Scheduling, Production Go-Live & Restore Validation
SOLUTION HIGHLIGHTS
- Scheduled the pipeline with an Azure Logic App recurrence trigger, configurable to run every 12 or 24 hours
- Deployed the solution to the production environment, with a demo and go-live formally signed off by the client
- Demonstrated successful scheduled runs in production
- Completed a successful restore of a generated .BAK on a local SQL Server, the acceptance gate for the engagement
- Agreed a communication channel (Teams or email) for run status and issue tracking
- Delivered documentation and knowledge transfer, followed by formal access revocation at close
BUSINESS ENABLEMENT
- A scheduled offline archive that runs without manual effort
- A recovery path that needs only local media and a SQL Server
- Clear evidence for stakeholders that backups are restorable
- A foundation for extending backup coverage to Power Platform and Power BI assets
Together, the three tasks took the client from manual exports to a proven, automated offline archive (Figure 1).
Architecture & Governance
From the client's standpoint, the architecture delivered (Figure 2):
-
Runs in your tenant
Automation that lives in the client's own Azure tenant, with no third-party tools or licensing
-
Native SQL backup
A Staging Bridge that turns a portable cloud export into a native SQL backup
-
Independent of the cloud
A cold-storage archive on local NAS/HDD, independent of the Microsoft cloud
-
On your schedule
A schedule the client controls, configurable to 12 or 24 hours
-
Proven by restore
Restore-based acceptance, so the backup is proven usable rather than assumed
This architecture delivered offline resilience without adding operational overhead.
Technology and Controls
CORE TECHNOLOGIES
- Microsoft Dynamics 365 Finance & Operations v10.0.45 and Supply Chain Management
- Lifecycle Services (LCS) API and Asset Library, and the Power Platform API
- Azure Logic Apps (recurrence trigger), Power Automate and PowerShell
- SqlPackage utility, .BACPAC and native SQL Server .BAK
- Tier-2 Sandbox and Tier-1 developer instance (Staging Bridge)
- Local NAS/HDD cold storage
- Azure DevOps or GitHub as an artifact repository option
OPERATIONAL CONTROLS
- Restore-based acceptance: successful scheduled runs in production plus one successful restore
- Client sign-off at the demo and the production go-live
- Client-approved security practices, NDAs and secure remote access
- Daily stand-ups and shared collaboration channels, with maintained risk and issue logs
- Written change control: any scope change handled through a formal change request
- Formal offboarding with knowledge transfer and access revocation
Business Impact & ROI
Quantifiable Outcomes
Measured against the engagement’s own yardsticks:
-
2
Backup formats produced from every cycle: a portable .BACPAC and a native .BAK
-
12/24 hr
Backup cadence, configurable to the client's schedule
-
1
Successful restore of a generated .BAK on a local SQL Server, completed as the acceptance gate
-
Live
Successful scheduled runs demonstrated in the production environment
-
Zero
Third-party tools or licences required by the solution
Strategic Value Delivered
This initiative shows how a cloud-hosted ERP customer can hold its own recoverable copy of critical data without depending on manual effort or on the cloud it is protecting against.
By combining automated cloud extraction, a Staging Bridge and restore-based acceptance, the client now benefits from:
- Data sovereignty backed by a proven restore
- The fastest practical recovery from a native SQL backup
- A hands-off process with no dependence on individuals
- A portable archive alongside the native copy
- Lower long-term operational and continuity risk
Looking Ahead
With the database pipeline in place, the organization is now positioned to:
- Extend the archive to Power Apps and Power Automate solution packages and to Power BI reports
- Adopt regular restore drills to keep confidence in recovery high
- Add retention and tiering policies for the cold-storage archive
- Adjust the backup cadence as data volumes and risk appetite change
- Strengthen business continuity incrementally without disruption
The direction is clear: help them move from manual backup dependency to an automated, owned and restore-tested recovery framework. Automate the backup. Own the copy. Prove the restore.