Fix it now
A standby server is a server. It needs its own licence unless Software Assurance disaster recovery rights cover it, and those rights are narrower than most designs assume. Count cores and instances on the recovery host before you build it.
- Licence the recovery host in full unless Software Assurance is in place. Windows Server 2025 needs at least 8 core licences per physical processor and 16 per server.
- Check the standby only does what the disaster recovery right permits: brief testing within one week every 90 days, running during a disaster while the production server is down, and a brief transfer period around one.
- Skip a second full licence set only if the arithmetic on your own quote says so: compare adding Software Assurance to the primary licences against buying the standby outright.
- Keep a SQL secondary genuinely passive. Software Assurance gives one passive replica for high availability, one for disaster recovery and one on Azure – passive meaning not serving data to clients.
- Licence the backup server itself. It runs when nothing else does, so it needs its own Windows Server licence and server-class endpoint protection – one Defender for Business servers licence per instance.
- Check portability before assuming licences travel. Azure Hybrid Benefit needs active Software Assurance or a subscription licence, and at least 8 core licences per VM.
If the standby is fully licensed in its own right, the compliance question is already closed. Below are the exact conditions on the disaster recovery right, what passive means for SQL Server, and how antivirus interacts with a backup repository.
Why it happens
Four things get licensed in any recovery design and they behave differently. The operating system on each host is licensed by physical core, with a published minimum and an allowance for how many instances that licence permits. The database engine is licensed per core, or per server with client access licences, depending on edition. Client access licences attach to users or devices rather than to servers. Endpoint protection is licensed per protected machine, and servers are a different product line from workstations on every vendor’s price list including Microsoft’s.
The one that surprises people is the standby, because a licence permits a number of running instances on the hardware it is assigned to and a second physical host is a second set of hardware. Windows Server 2025 requires a minimum of 8 core licences per physical processor and 16 per server, and Standard permits two operating system environments. For each additional pair of operating system environments, Microsoft’s rule is exact: the server must be relicensed for the same number of core licences. Datacenter permits any number on the licensed host. Apply that to the recovery host before you buy it – a plan that brings up eight virtual machines on a host licensed for two fails at the licence level even though it works technically.
Software Assurance is what converts a standby from a second full purchase into a covered one, and the conditions are the part that decides most designs. Microsoft publishes when a backup instance may run: for brief periods of disaster recovery testing within one week every 90 days; during a disaster, while the production server being recovered is down; and around the time of a disaster, for a brief period, to assist the transfer between the primary and the recovery server. It also publishes what that server may do – run hardware virtualisation software, provide virtualisation services, run agents to manage it, serve as a destination for replication, receive replicated virtual instances, test failover, and await failover. Nothing else. And the right ends when the Software Assurance coverage ends.
SQL Server has its own version of the same idea with its own count. With Software Assurance or a subscription licence you may run one passive failover replica for high availability in a separate operating system environment, one passive replica for disaster recovery in a separate environment, and one passive replica for disaster recovery in a single virtual machine or instance on Azure. Microsoft defines passive precisely: a replica that is not serving SQL Server data to clients or running active SQL Server workloads. The licence count on the passive side cannot exceed what the primary requires. Point a reporting workload at it and it stops being passive.
There is a third route that is neither a second licence set nor Software Assurance, and it is worth knowing before you buy hardware for a machine that runs four days a year. Microsoft offers pay-as-you-go Windows Server licensing through Azure Arc, positioned for customers without unlimited virtualisation who need to add virtual machines for capacity bursts or temporary needs. A recovery host that only exists during a test is exactly that shape.
Full reference
The licences a recovery plan touches
| Component | How it is licensed | What changes at failover | The common mistake |
|---|---|---|---|
| Windows Server on the primary | Per physical core: minimum 8 per processor, 16 per server | Nothing | Counting sockets instead of cores |
| Windows Server on the standby | The same, unless Software Assurance disaster recovery rights apply | The instance starts running | Assuming a replica that is powered off needs nothing |
| SQL Server | Per core, minimum 4 per physical processor, or per server plus CALs on Standard | Passive becomes active | Using the secondary for reporting or backups |
| Windows Server CALs | Per user or per device | Nothing; they follow the user | Buying a second set for the recovery site |
| RDS CALs | Per user or per device, issued by a licence server | The licence server must itself be recoverable | Backing up session hosts but not the licence server |
| Backup server operating system | Per core, like any server | It must run when nothing else does | Treating it as an appliance rather than a server |
| Endpoint protection on servers | Per server instance, server-class product | The standby comes online unprotected | Assuming client licences reach servers |
Standard, Datacenter and the instance ceiling
| Dimension | Windows Server 2025 Standard | Windows Server 2025 Datacenter |
|---|---|---|
| Licensing unit | Every physical core in the server | Every physical core in the server |
| Core minimums | 8 per physical processor, 16 per server | 8 per physical processor, 16 per server |
| Pack sizes | 2-core and 16-core packs | 2-core and 16-core packs |
| Operating system environments | Two per fully licensed server | Any number on the licensed server |
| Adding more instances | Relicense the whole server for each additional pair | Nothing to do |
| Hyper-V isolated containers | Two; they count against the limit | Unlimited |
| Client Access Licences | Required per user or device | Required, on identical terms |
Windows Server 2025 Essentials is a different purchase rather than a cheaper Standard: Microsoft positions it for up to 25 users and 50 devices, and a single server licence covers up to 10 cores and one virtual machine. If the recovery host is small enough for that, check the user and device limits against your actual headcount before assuming it fits.
Passive is a licensing word, not a description
A secondary that serves any workload stops being passive. Microsoft defines a passive SQL Server replica as one that is not serving SQL Server data to clients or running active SQL Server workloads, so running reports against it, taking backups from it or letting an application read from it puts it outside the failover right and requires it to be licensed in its own right.
The same discipline applies on the Windows Server side. The disaster recovery instance is permitted to run hardware virtualisation software, provide virtualisation services, run management agents for that software, serve as a destination for replication, receive replicated virtual instances, test failover and await failover. A standby that has quietly become a file server, a print queue or a monitoring host is not covered by the disaster recovery right, and the testing allowance is specific: brief periods within one week every 90 days. Design the test schedule around that rather than discovering it afterwards.
Without Software Assurance the position is simple: the standby is a server running the software and is licensed as one. That is the usual reason disaster recovery projects come in over budget, and it is the point at which Software Assurance on the primary licences starts to compete with buying a second full set. Run that comparison on your own quote – the ratio between adding Software Assurance and buying the standby outright is the only thing that decides it, and it moves with what you are offered rather than with any rule of thumb.
When licences need to follow the workload
Ordinary core licences are sticky. Microsoft’s terms prevent a licence returning to a previous server for 90 days unless an exception applies, and the published exceptions are permanent hardware failure or loss, termination of a user’s employment or contract, and temporary reallocation to cover an absence or an out-of-service device. That is why the usual approach in a cluster is to license every node for the worst case it might carry. The alternative is licensing by virtual machine, which requires Software Assurance or a subscription licence and a minimum of 8 core licences per virtual machine for Windows Server, and which does allow the licences to move to another server in the same farm at any time. If your recovery design depends on workloads landing wherever there is capacity, that is the mechanism to buy rather than a bigger spreadsheet.
Recovery into Azure has its own rules and they differ by edition. Azure Hybrid Benefit requires active Software Assurance or a qualifying subscription licence, and a minimum of 8 core licences per virtual machine. Standard edition licences can be used on-premises or in Azure but not both at once, with a one-time 180-day migration window as the exception; Datacenter allows simultaneous use during a migration. Check which of those you hold before assuming a recovery plan can burst into Azure on existing licences.
Antivirus, backups and the machines that hold them
Server endpoint protection is a different licence from the workstation seats your staff use, and on the Microsoft side the rule is published: Defender for Business client licences do not cover servers, and the Microsoft Defender for Business servers add-on is one licence for each instance of Windows Server or Linux, to a maximum of 60 per subscription. Licence the standby and the backup server at build time, not when the replica comes online during an incident as your least protected machine.
Exclusions need care and the mechanism is worth understanding rather than copying a list. Microsoft Defender Antivirus applies automatic exclusions on Windows Server based on the roles installed – Active Directory, DHCP, DNS, file services, Hyper-V, print services, IIS, WSUS and others – and Microsoft warns that opting out of them can adversely affect performance or result in data corruption. The important detail for a backup repository is that automatic exclusions apply only to real-time protection: they do not apply to quick, full or custom scans, or to network inspection and behaviour monitoring. So a path excluded from real-time scanning is still visited by a scheduled scan unless you add a custom exclusion, which is usually what you want for a repository. Apply the exclusion list your backup vendor publishes, then compensate with scheduled scanning and with immutable or offline copies that malware cannot alter.
One more thing worth knowing if the backup product is Microsoft’s own. Microsoft 365 Backup restores SharePoint, OneDrive and Exchange content quickly, but Microsoft states that the data never leaves the Microsoft 365 data trust boundary and honours existing data residency. If the recovery plan assumed a copy held outside the platform, that is not what it provides.
What to buy, by recovery target
- Backup only, restoring to the same hardware: no extra server licence for a standby, but the backup server needs its own Windows Server licence and its own server endpoint licence.
- Warm standby brought up in hours: Software Assurance on the primary licences, or a full second set. Decide before you build, and check the standby will only do what the disaster recovery right permits.
- SQL Server with a failover replica: Software Assurance or a subscription licence is the mechanism, and the secondary must stay passive to qualify – no reporting, no backups taken from it.
- Several virtual machines onto one recovery host: count instances against Standard’s two per fully licensed server and price the relicensing against Datacenter on your own quote.
- A recovery host that only exists during a test: look at pay-as-you-go licensing through Azure Arc before buying hardware and licences for four days a year.
- Remote Desktop Services in scope: back up the licence server and record the CAL details. Reinstating lost CALs is slower than restoring a virtual machine.
- Recovery into Azure: confirm you hold Software Assurance or a subscription licence, and check whether your edition allows on-premises and Azure use at the same time.
When a licence is the actual fix
If the standby host is not covered by Software Assurance disaster recovery rights it needs licensing in its own right, and Windows Server 2025 Standard is the usual choice for a recovery host running one or two virtual machines. Arco can work through your core counts, your instance list and your Software Assurance position, and price adding Software Assurance to the primary licences against buying a second full set on your own numbers rather than a rule of thumb – and quote Datacenter instead where the host is dense enough that relicensing Standard in pairs stops making sense. Two things to check before you order anything. Your existing Windows Server CALs already cover access to the recovery server, so there is no second set to buy. And if the recovery host only runs during a test, ask us about pay-as-you-go licensing through Azure Arc before you buy licences for a machine that is switched off most of the year.
Questions people ask about this
Do I need extra CALs for the disaster recovery server?
No. Windows Server client access licences are assigned to users or devices and permit access to your licensed Windows Servers generally, so an already-licensed user can reach the recovery server without a second CAL. The server operating system licence is the part accounted for separately, and it is the part people forget.
Does a powered-off standby need a licence?
It depends on whether Software Assurance disaster recovery rights apply. With them, a backup instance may run for brief disaster recovery testing within one week every 90 days, during a disaster while the production server is down, and for a brief transfer period around one – and it may only do virtualisation, replication and failover work while it does. Without them, a server you intend to run the workload on is a server you licence. Remember that testing the failover is running it.
Can I run reports against my SQL Server passive secondary?
No, not while it stays passive. Microsoft defines a passive replica as one that is not serving SQL Server data to clients or running active SQL Server workloads, and the failover rights depend on that. With Software Assurance or a subscription you get one passive replica for high availability, one for disaster recovery and one for disaster recovery on Azure; point a reporting workload at any of them and it needs licensing in its own right.
How many cores do I have to licence on the recovery host?
Every physical core in the server, with a minimum of 8 core licences per physical processor and 16 per server, sold in 2-core and 16-core packs. Windows Server 2025 Standard then permits two operating system environments, and for each additional pair the whole server has to be relicensed for the same number of core licences. Count the virtual machines you would actually bring up before you decide between Standard and Datacenter.
Can I restore a server onto completely different hardware?
Technically often yes; the licensing depends on the licence type. OEM server licences are tied to the hardware they shipped with and do not move. Volume licences can be reassigned, but not sooner than 90 days after the last reassignment unless an exception applies – and permanent hardware failure or loss is one of the published exceptions. That exception is exactly why volume licensing suits anything you plan to recover onto replacement hardware.
