One of the most common questions Microsoft receives from customers and auditors is “Tell us how your datacenters failover in the event of catastrophic loss”. The question itself is dated because Microsoft does not use the concept of datacenter failover; instead, failover is relegated first to the individual services and catastrophic loss is relegated to paired regions for recovery.

This paper explains how Microsoft achieves service reliability and recoverability regardless of impact and scope of outage. It should serve to answer the question in modern terms of the service failover versus datacenter failover concepts. Specific failover information for individual services can be found under separate references.