HPE Zerto 10.9: All Features Explained

HPE Zerto 10.9 is a transformative release that redefines enterprise resilience by combining continuous data protection, cyber recovery, and AI-driven operations into a unified platform.
Released on May 29, this version also delivers powerful new capabilities, including cross-hypervisor VMware and HPE VM Essentials replication, application and workload migration from VMware to HPE VM Essentials, and improvements for public cloud environments.
From eliminating hypervisor lock-in with cross-platform replication to enabling intelligent automation through Agentic AI, it empowers organizations to recover faster, operate smarter, and reduce risk.
In this topic, each key innovation in the release notes is explained, with additional technical details, practical cases, and links to the official HPE Zerto guides.
Content/Index:
HPE VM Essentials (HVM) Cross-Hypervisor Support
- Cross-Replication: VMware vCenter ↔ HVM
- Move Operation (VMware → HVM)
- Pre-Seed Support for Reverse Protect with HVM VMs
AI & Intelligent Operations
- Zerto AI Assistant (RAG-Based Chat Agent)
- Agentic-AI with Zerto Model Context Protocol (MCP) Server
- Zerto Analytics MCP Server
Cyber Resilience & Security
- Cyber Recovery VPG (Virtual Protection Groups)
- Microsoft Defender for Endpoint (XDR) Integration
- Improved Encryption Detection Alert Accuracy
- External Secrets Vault Integration (HashiCorp Vault)
Disaster Recovery & Recovery Orchestration
- Recovery Plans (VPG Run Books)
- Preserve vGPU Consistency upon Recovery
- Enhanced Log Collection
VMware Platform Enhancements
- Seamless Upgrade from VCF 5.2 to VCF 9.0
- Multiple License Packages
- Non-SSH VRA Operations for VAIO Environments
- Database Reconfiguration Support for ZVM Appliance
Public Cloud Enhancements
- Updated Default ZCA and Scale Set VM Sizes (Azure)
- Expanded Guest OS Support for AWS
- VRA Public Cloud Performance and Reliability Enhancements
- Azure ZCA Support for GPv2 Storage Accounts
Azure VMware Solution (AVS) Enhancements
- AVS Gen 2 (AV64) Support
- AVS Automatic Host Replacement (AHR) Support (VAIO)
Zerto Analytics Updates
- Analytics License View Update
API Enhancements
- Multi-License Management APIs
- VPG Type Filter API
- External Secrets Vault API
- ZVM Appliance Network Configuration API
- ZVM Appliance Proxy & Reboot Configuration APIs
Conclusion
Link to the release note: Release Notes for Zerto 10.9
HPE VM Essentials (HVM) Cross-Hypervisor Operations

Zerto 10.9 enables cross-platform Continuous Data Protection (CDP) replication between VMware vCenter and HPE Morpheus VM Essentials (HVM) in both directions, with RPO of seconds and RTO of minutes.
What’s really interesting here is the flexibility this brings to recover to whichever stack best fits cost, licensing, or hardware availability.
It also helps to eliminate hypervisor lock-in and simplify DR design across heterogeneous sites.
This capability also reduces risk during vendor transitions by keeping RPOs low on both sides and streamlining consolidation by replicating between mixed VMware and HPE environments.
From a technical perspective, it enables pairing VMware vCenter and HVM sites for continuous replication (CDP) with full support for Failover Test and Failover Live (FOL) operations.
Bidirectional replication between hypervisors is guaranteed, enabling heterogeneous DR strategies across VMware and HVM environments.
In practice, this opens the door to a VMware exit strategy, gradually moving off VMware while reducing licensing costs, and turning HPE HVM into both your DR platform today and your production platform over time.
Link to the procedure: Creating a Virtual Protection Group (VPG)
Move Operation (VMware to HPE HVM)

Zerto 10.9 now supports one-way migration from VMware vCenter to HPE Morpheus VM Essentials (HVM).
This is a meaningful addition for organizations looking to move away from VMware. It provides a clear, controlled path for existing VMWare licensing, without the pressure of a major cutover in the environment.
Instead, workloads can be migrated gradually, reducing risk while maintaining business continuity and minimizing downtime.
It enables seamless migration from VMware vCenter to HPE VM Essentials, with full VM transfer and minimal disruption. The process is designed to support ongoing operations while workloads are being moved.
In practice, this allows teams to protect and validate workloads and validate recovery with a Failover Test (FOT) before the migration.
When ready, the Move is executed with a quick rollback if issues arise, with no protection gaps during the transition.
Link to the procedure: The Move Operation
Zerto U9 VMWare to HVM Migration demo: Zerto U9 VMWare to HVM Migration demo | HPE
Pre-Seed Support for Reverse Protect with HVM

When performing Reverse Protect after a failover, you can reuse the source volume disks as preseeded replica disks to reduce the amount of data transferred.
It uses delta synchronization to transfer just the changed blocks from the new source disk to the replica disk, which dramatically shortens the initial synchronization time.
Instead of reprocessing everything, pre-seeded volumes are compared using delta sync with MD5 block-level checks.
After failing over from VMware to HVM, you can reverse-protect without transferring the entire dataset again.
This feature also reduces bandwidth usage by sending only changed blocks and accelerates the time to full protection. It makes a big difference in bandwidth-constrained environments, helping maintain low RPOs even across limited WAN links.
For large environments, including TB- to PB-scale datasets like databases, this approach dramatically reduces recovery time. What could take weeks can often be completed in hours.
It also supports ransomware recovery scenarios. After restoring clean data in HVM, you can quickly reverse the protection to production, minimizing exposure and speeding the return to normal operations.
Finally, it simplifies environment consolidation. Data can be staged in advance, and when roles are reversed, only incremental changes need to be replicated across environments. Link to the procedure: Moving Protected Virtual Machines to a Remote Site
AI and Intelligent Operations
Zerto AI Assistant (RAG-Based Chat Agent)

Zerto 10.9 embeds a built-in AI chat agent directly into the ZVM user interface. Zerto AI Assistant combines AI reasoning with retrieval‑augmented generation (RAG) to answer product questions by dynamically retrieving information from official Zerto documentation.
What makes it particularly useful is that it connects securely to your environment via Zerto’s Model Context Protocol (MCP), enabling it to provide answers based on both product knowledge and real-time context.
In practice, this helps speed up troubleshooting without leaving the ZVM console. Admins can get immediate, reliable answers, reducing the need to open support tickets and shortening the time to resolution.
It also makes onboarding easier and helps teams stay consistent in day-to-day operations while keeping sensitive data local to meet compliance requirements.
From a technical perspective, the assistant retrieves answers directly from the official Zerto documentation via RAG and also accesses live environment data, such as VPG status, site configuration, and alert states.
It supports natural-language queries, making it easier to gain insights into configuration, troubleshooting, and operational status without switching between multiple tools.
In practice, this enables real-time troubleshooting, provides contextual guidance based on the current environment, and helps reduce time to resolution for common operational issues.
Link to the feature description and how to use it: How the Zerto AI Assistant Works
Agentic-AI with Zerto Model Context Protocol (MCP) Server

Zerto 10.9 introduces a Model Context Protocol (MCP) server that exposes ZVM management and monitoring capabilities to external AI clients through natural-language queries.
What makes this powerful is how it simplifies automation. It translates intent into actions, reducing the need for custom scripting while enabling faster troubleshooting and status checks without even opening the ZVM UI.
At the same time, it uses standard security controls such as OAuth and TLS, enabling teams to safely adopt AI while maintaining proper access control and auditability.
Technically, the MCP server runs locally and securely connects to supported AI clients, such as Claude Desktop or VS Code Copilot.
It exposes key ZVM capabilities, including VPGs, VMs, VRAs, sites, alerts, and failover operations, accessible via natural-language queries.
It effectively acts as a bridge between AI tools and the Zerto platform, supporting both interactive use and automated workflows. All operations are authenticated and encrypted end-to-end.
In practice, this brings several useful scenarios. Operations teams can ask simple questions about the environment’s status, trigger actions such as failover tests, or quickly summarize alerts without having to build or deal with API calls.
It speeds up troubleshooting, automates repetitive tasks, and makes it easy to generate compliance or status reports on demand
Link about the feature and how to use it: Zerto Virtual Manager (ZVM) Model Context Protocol (MCP) Server
Agentic AI with HPE Zerto Software MCP support demo: Agentic AI with HPE Zerto Software MCP support | HPE
Zerto Analytics (MCP) Server

Zerto Analytics can now be accessed using conversational AI, making it much easier to get insights without navigating dashboards or writing API calls.
What stands out here is how simple it becomes to explore analytics. Instead of digging through multiple tasks, you can ask questions in plain language and get quick answers.
It also keeps things safe with read-only access, making it suitable for a wider audience, from operations teams to compliance and leadership. At the same time, it brings together data across sites and audit-ready snapshots, improving visibility, planning, and auditing processes.
From a technical standpoint, a dedicated MCP server provides secure, read-only access to analytics data through natural-language queries.
It supports a wide range of information, including VPGs, protected VMs, sites, alerts, events, tasks, storage, and licensing.
It also covers areas such as RPO compliance, journal health, SLA tracking, and cross-site performance, all via a locally running, securely connected service.
Capacity planning trends can be visualized like protection coverage, storage, and journal health.
Link: Zerto Analytics Model Context Protocol (MCP) Server
Cyber Resilience & Security
Cyber Recovery VPG (Virtual Protection Groups)
Zerto 10.9 introduces a new VPG type designed specifically for cyber recovery, built to address ransomware and other advanced cyber threats.
What’s interesting here is that these Cyber Recovery VPGs focus on making post-incident recovery safer and more structured.
They help guide operators to known clean checkpoints, automate threat-based tagging, and isolate recovery steps to reduce the risk of reinfection.
In practice, this speeds up recovery while reducing uncertainty during high-pressure situations. It also provides a more consistent and auditable process, with repeatable runbooks that align recovery actions with security events.
The Cyber Recovery VPG is similar to the traditional Remote DR and Continuous Backup VPGs, with the addition of the following key features:
- Integration Hub: enables integration with third-party cybersecurity platforms to enhance threat detection and recovery.
- Recovery Plans: A recovery plan is a predefined, automated workflow for orchestrating the recovery of multiple Virtual Protection Groups (VPGs). Standard and Cyber Recovery Plans are supported.
- Offline recovery: Zerto’s offline recovery mode is designed for fast offline recovery, significantly reducing recovery time (RTO).
These capabilities go beyond traditional DR by supporting full post-incident cyber recovery workflows.
It integrates with offline recovery from storage snapshots and works with security platforms like CrowdStrike and Microsoft Defender for Endpoint to automatically tag checkpoints based on detected threats.
It also leverages Cyber Recovery Plans to create event-driven recovery points, helping guide the process in a structured way. This capability is available with the Advanced Resilience Edition (ARE) and for MSP environments.
In terms of how it works, when a threat is detected through integrated security tools, the system automatically creates tagged checkpoints.
Recovery plans can then target known clean points from before the attack. If needed, recovery can be performed in isolation using storage snapshots, keeping the process fully separated from compromised environments.
In practice, this supports several real-world scenarios. Teams can recover from ransomware using verified clean checkpoints, thereby reducing the risk of reinfection.
Cybersecurity workflows can trigger recovery actions directly from XDR or EDR tools.
It also enables isolated restores for forensic and testing before systems are brought back online.
For compliance, it supports repeatable recovery drills aligned with frameworks like DORA or NIST, and for larger environments, it helps guide the rapid recovery of multiple applications.
Link to the feature and how to use it: Cyber Recovery VPG – Introduction to Protecting Virtual Machines
Microsoft Defender for Endpoint (XDR) Integration

Zerto Integration Hub now supports Microsoft Defender for Endpoint (XDR) to automate checkpoint tagging when threats are detected on protected VMs.
What makes this valuable is how it turns security alerts into something actionable.
Instead of sorting through noisy signals, Defender events are used to tag both suspected-compromise and last-known-clean checkpoints, helping teams quickly identify safe recovery points.
In practice, this makes recovery more precise and efficient.
Teams can quickly identify safe checkpoints, align recovery decisions with security insights, and avoid manual selection during high-pressure situations.
It also helps correlate security alerts with Zerto journals, automate parts of the recovery workflow, and provide clear, auditable evidence for compliance.
It works across vSphere, Azure, and AWS, and new environments are in the roadmap. It requires the Advanced Resilience Edition (ARE) or a Cloud license. Link to the Integration Hub procedures: Microsoft Defender XDR Integration
Improved Encryption Detection Alert Accuracy

Real-time ransomware detection is critical because it reduces dwell time and helps catch encryption activity early before the impact spreads. Instead of reacting hours later, it gives operators a chance to act while the incident is still unfolding.
HPE Zerto takes a different approach by analyzing the live I/O stream as data is written. This allows ransomware behavior to be detected within seconds, rather than relying on delayed scans of backup copies, which can take hours.
It´s the same proven and resilient detection mechanism used in the HPE Alletra storage systems.
What stands out in this release is the improvement in detection accuracy. It better distinguishes between normal encryption activity and malicious behavior, reducing false positives while quickly highlighting suspicious disk-write patterns.
Alerts are directly tied to recoverable checkpoints, making it easier to move from detection to action.
Technically, this means fewer false alerts to investigate and more reliable identification of real threats.
The system can accurately distinguish legitimate processes such as backups or encryption tools from ransomware, reducing unnecessary noise and operational overhead.
In practice, this helps teams respond faster and with more confidence.
It also helps prioritize recovery for VPGs showing confirmed encryption patterns to minimize business impact. Also, supports audit and compliance evidence by linking accurate alerts to recoverable, time-stamped checkpoints.
It can also help lower escalation rates and manual correlation by enabling higher-confidence detections.
Link to the feature: Encryption Detection
Technical white paper: Understanding real-time encryption detection with HPE Zerto Software
External Secrets Vault Integration (HashiCorp Vault)

Using HashiCorp Vault for Zerto secrets helps centralize credential management while improving both security and day-to-day operations.
It eliminates the need to store secrets locally, supports safe key rotation without downtime, and makes it easier to enforce consistent security policies across environments.
Starting with Zerto 10.9, support for HashiCorp Vault allows credentials to be securely stored and managed outside the ZVM.
Technically, Zerto can now store sensitive information in Vault rather than in the local database. Authentication is handled through LDAP, and secrets are managed centrally through the settings service.
This approach enables key and credential rotation without requiring reconfiguration, helping maintain continuity during updates.
In practice, this simplifies several common scenarios. Teams can centralize credentials across ZVM, vCenter, and cloud platforms, reducing audit scope and eliminating plaintext storage.
Keys and passwords can be rotated without downtime, while multi-site environments benefit from consistent policy enforcement.
It also strengthens security in regulated or hardened environments and allows credentials to be revoked quickly in response to an incident without requiring Zerto to be reconfigured.
Link for more information: External Secrets Vault
Disaster Recovery & Recovery Orchestration
Recovery Plans (VPG Run Books)

Zerto 10.9 introduces Recovery Plans, enabling teams to orchestrate failover operations across multiple VPGs in a structured, predictable way. Instead of handling each application group individually, failovers can now be executed as part of a coordinated sequence.
Recovery Plans play a key role in simplifying complex disaster recovery scenarios. They allow multiple VPGs to be failed over with a single action, while enforcing a predefined order and timing between each step.
This makes multi-application recoveries far more predictable and easier to audit.
From a practical view, this reduces the risk of human error during incidents and speeds up both Failover Test (FOT) and Failover Live (FOL) operations, providing repeatable and consistent execution.
Technically, Recovery Plans allow VPGs to be grouped into ordered blocks, with configurable delays between each stage. Each block can be formed by VPGs or specific scripts.
In real-world scenarios, this capability is particularly useful for multi-tier applications, where components need to be brought online with recovery priority and in the correct order. For example, database first, then middleware, followed by the frontend.
It also helps coordinate periodic disaster recovery testing across multiple workload groups without production disruptions. Compliance-driven processes will be supported by ensuring recovery steps are documented, executable, and validated.
Link to the feature and operational procedures: Recovery Plans
Preserve vGPU Consistency upon Recovery
Zerto now supports consistent recovery of vGPU-enabled virtual machines at the DR site, ensuring that GPU-accelerated workloads can be restored without configuration drift.
This avoids common issues such as driver or profile mismatches, performance degradation, and the need for manual reconfiguration during an outage. It also minimizes the operational risk typically associated with GPU-dependent failovers.
From an operational perspective, this capability helps reduce recovery time objectives (RTOs) while maintaining application performance and SLA compliance.
Zerto maintains the vGPU configuration of protected virtual machines throughout the failover process within vSphere environments. This ensures that workloads are recovered with consistent GPU allocation, provided that identical GPU hardware is available on both the protected and recovery hosts.
This approach is particularly relevant for environments running GPU-intensive applications, including AI/ML, VDI, and 3D/CAD infrastructures that rely on hardware acceleration.
Enhanced Log Collection
The log collection process has been enhanced to improve reliability and precision across different operational scenarios. These improvements ensure that diagnostic data is collected more consistently, while minimizing residual artifacts from prior operations.
From an operational perspective, the process now includes automatic cleanup of temporary folders left behind by previous or failed log collection attempts, reducing the risk of inconsistencies and storage clutter.
In addition, only a single log bundle is retained per site, whether local or peer, which helps maintain a more controlled and manageable storage footprint.
The enhancements also introduce support for emergency log collection when database connectivity is unavailable, ensuring critical diagnostic information can still be captured under degraded conditions.
Furthermore, log collection from Virtual Replication Appliances (VRAs) is now strictly aligned with the user-defined time range.
VMware Platform Enhancements
Seamless Upgrade from VCF 5.2 to VCF 9.0

Zerto 10.9 enables seamless upgrades from VMware Cloud Foundation 5.2 to VCF 9.0, ensuring uninterrupted protection continuity.
It preserves replication integrity and journal consistency as hosts transition through Maintenance Mode, eliminating protection gaps typically associated with SDDC Manager–driven rolling upgrades. By automatically applying the required compute policies and tags, the process removes the need for manual reconfiguration and reduces the risk of operational errors.
From an operational perspective, this allows organizations to adopt VCF 9.0 without introducing downtime, enforcing change freezes, or increasing disaster recovery risk.
Protection remains active and consistent even as infrastructure components are incrementally upgraded, which is especially critical in environments with strict availability or compliance requirements.
Zerto automatically provisions the necessary compute policies and tagging structures within vCenter to ensure correct VRA placement during and after the upgrade.
Virtual Replication Appliances follow a “best effort evacuation” behavior when hosts enter Maintenance Mode, allowing workloads to continue being protected with minimal disruption.
As part of the VCF lifecycle operations, VRAs running on hosts entering Maintenance Mode are gracefully powered off and automatically restarted once those hosts exit Maintenance Mode, maintaining continuity of protection services.
This capability is particularly valuable in large-scale environments where clusters may include dozens or hundreds of hosts, as it enables predictable, repeatable upgrade execution.
It also supports scenarios involving mixed-version states, where parts of the environment run VCF 5.2 while others transition to VCF 9.0, without compromising journal consistency.
Additionally, it facilitates zero-downtime SDDC lifecycle management, simplifies policy enforcement through automated tagging, and ensures that upgrades can be performed within compliance windows without introducing operational risk.
Link to the procedure and FAQs: Deploying Zerto 10.9 on VMware Cloud Foundation (VCF) 9.0
Multiple License Packages

Zerto 10.9 introduces support for managing multiple license packages within a single ZVM cluster, enabling more flexible and granular control over how protection capabilities are applied across workloads.
This allows organizations to align licensing with workload requirements by combining Advanced Resilience Edition (ARE), Enterprise Cloud Edition (ECE), and Migration licenses within the same environment.
This capability reduces both cost and complexity by eliminating the need to deploy and maintain separate ZVM clusters for different licensing tiers. It enables more efficient resource utilization while enforcing per-VM access to features, ensuring that advanced capabilities are available only where required and aligned with compliance and service level requirements.
License management can be performed directly through the ZVM user interface or via dedicated REST API endpoints, providing flexibility for both manual and automated administration. This approach ensures that protection levels can be precisely matched to workload characteristics and business priorities without impacting overall cluster operations.
In practical use, critical systems can be assigned ARE licenses to leverage advanced resilience features, while standard applications can remain on ECE for traditional disaster recovery, and migration licenses can be used for temporary or one-time workload moves.
This model supports cost optimization by reserving advanced features only for workloads that require them, reducing unnecessary over-licensing across the estate.
This new capability also facilitates clearer separation among business units, projects, or environments by allowing distinct licensing packages to be allocated according to specific service-level agreements, operational priorities, or budget constraints.
Furthermore, it enables phased adoption of advanced capabilities, allowing organizations to pilot ARE features on a subset of virtual machines before expanding usage more broadly, all without requiring additional infrastructure or cluster segmentation.
ECE and ARE licensing comparison: Zerto VM-based License Packages
New multi-licensing procedure: Adding a license key
Non-SSH VRA Operations for VAIO Environments
Zerto now supports full VRA lifecycle management in VAIO environments without SSH connections or ESXi host credentials. His enhancement enables organizations to manage VRAs through secure, controlled interfaces that align with modern security and compliance requirements.
Eliminating the need for SSH access simplifies administration in environments where direct host access is restricted or disabled, such as those adhering to DISA/STIG hardening guidelines. It also reduces operational overhead by removing the need to manage and securely store ESXi host root credentials.
This approach significantly reduces the attack surface by eliminating SSH exposure and limiting the use of privileged access methods. All lifecycle operations are executed through standardized, auditable control paths, improving traceability and reinforcing the overall security posture within hardened environments.
Technically, Zerto enables installation, upgrade, uninstallation, monitoring, and log collection of VRAs without reliance on SSH-based mechanisms.
Database Reconfiguration Support for ZVM Appliance

Zerto now supports migrating the ZVM Appliance database from an external SQL Server to its built-in internal database, providing greater flexibility in terms of architecture and maintenance.
Consolidating the database within the ZVM Appliance simplifies the overall architecture, making environments more self-contained and easier to manage.
It reduces reliance on external SQL infrastructure, including associated licensing, maintenance, and operational overhead. This also improves resilience by shortening recovery times during database-related incidents, as the platform can be reconfigured without full redeployment.
Migration is supported directly through the ZVM Appliance configuration interface.
Link to the procedure: Reconfiguring the ZVM Database
Public Cloud Enhancements
Updated Default ZCA and Scale Set VM Sizes (Azure)
Default virtual machine sizes have been updated to align with Microsoft Azure’s current machine types, while maintaining compatibility with older series, such as Dv2/DSv2, as they are retired.
The default ZCA VM size is now Standard_D4s_v5, replacing Standard_DS3_v2, and the Scale Set VM size is now Standard_D2as_v5, replacing Standard_DS1_v2. These updates ensure new deployments use current-generation instances aligned with Azure’s performance and availability standards.
This change helps prevent issues related to deprecated SKUs, supports more consistent deployments across regions, and improves cost efficiency by leveraging newer VM series. Link to the Azure Zerto Cloud Appliances new specification: Component Types and Sizes
Expanded Guest OS Support for AWS
Zerto now extends its support to additional guest operating systems during failover to AWS.
With expanded OS compatibility, teams can protect newer distributions without needing custom images or manual adjustments, reducing the effort typically required during migrations or recovery.
It also increases the number of workloads that can be successfully failed over to AWS, helping organizations meet their disaster recovery objectives more consistently.
Newly supported versions include Debian 12, Ubuntu 24.02, and RHEL 9.x, covering many of the most commonly used modern Linux distributions.
Zerto automatically detects the operating system version during recovery and applies the appropriate settings, eliminating the need for manual configuration. This enables a smoother, more reliable failover process, especially in complex environments with diverse workloads.
In practice, this means teams can confidently extend their DR strategies to the cloud, knowing that a wider range of systems can be recovered seamlessly and with minimal intervention.
Improved Handling of Protected Workloads in AWS and Azure
Zerto now improves the way deleted protected workloads are handled in AWS and Azure, bringing cloud behavior more in line with on-premises environments. This change helps prevent situations in which recovery status appears healthy even though critical cloud-side resources have already been removed.
This is particularly important in real-world operations, where workloads may be deleted directly in the cloud, either accidentally or intentionally.
In earlier scenarios, this could create a false sense of recoverability.
With the updated behavior, Zerto provides a more accurate view of the actual state of protected resources, helping teams respond appropriately and avoid incorrect recovery assumptions.
The platform can now detect when a protected VM or its associated storage has been deleted in AWS or Azure, immediately reflecting that change in its status and alerts. At the same time, improvements in journal handling provide clearer and more actionable feedback to operators.
In practice, this leads to better visibility, more reliable decision-making during incidents, and a reduced risk of surprises during recovery operations.
VRA Public Cloud Performance and Reliability Enhancements
Zerto introduces improvements to VRA behavior in both Azure and AWS, focusing on reducing API throttling, speeding up volume and snapshot operations, and improving overall startup reliability.
These changes are especially valuable in cloud environments, where API limits and latency can impact performance.
By refining how the VRA handles retries, asynchronous operations, and metadata management, Zerto reduces replication slowdowns and minimizes noisy or unnecessary failures. The result is better throughput, increased stability, and more predictable recovery outcomes across both Azure and AWS.
Technically, Azure asynchronous operations now use calibrated delays combined with exponential backoff, with these settings persisting across sessions for more consistent behavior. Snapshot metadata is cached during startup, avoiding repeated enumeration and further reducing overhead.
In addition, HTTP retries and timeouts have been fine-tuned to recover more quickly from transient issues without triggering excessive retry attempts. As part of these enhancements, Azure SAS tokens are now masked in logs, providing an extra layer of security for sensitive information.
In practice, these updates lead to smoother day-to-day operations, fewer interruptions caused by cloud API limits, and a more reliable recovery experience.
Azure ZCA Support for GPv2 Storage Accounts
Azure ZCAs now support GPv2 storage accounts, using an optimized datapath designed to improve both performance and cost efficiency.
This update is important because GPv2 has become Microsoft’s default standard for storage, especially as newer features and pricing models continue to evolve around it.
By aligning with GPv2, Zerto ensures compatibility in regions where GPv1 is no longer available and helps organizations take advantage of more efficient, consolidated storage pricing.
The integration introduces an optimized datapath that leverages a Read-Modify-Write (RMW) approach during promotion. This improves the handling of data during failover, leading to more predictable performance and smoother recovery operations.
It also helps mitigate potential cost increases as Azure continues shifting toward GPv2-only offerings in newer regions, allowing organizations to modernize their environments without unexpected pricing impacts.
In practice, this means better alignment with Azure’s long-term storage strategy, improved recovery performance, and a more cost-effective foundation for cloud-based disaster recovery.
Azure VMware Solution (AVS) Enhancements
AVS Gen 2 (AV64) Support
Zerto now supports Azure VMware Solution (AVS) Gen 2 (AV64), ensuring compatibility with the latest generation of Microsoft’s AVS infrastructure.
This update is important as Microsoft continues to evolve the AVS platform, with AV64 becoming the standard for new deployments.
These environments offer improved CPU and memory configurations, broader regional availability, and long-term support.
By aligning with AV64, Zerto ensures customers can proceed with platform upgrades and new deployments without disrupting their disaster recovery strategies. It preserves compatibility while also allowing workloads to benefit from the performance improvements available in the newer infrastructure.
In practice, this means organizations can confidently adopt the latest AVS generation while maintaining continuous protection, stable recovery processes, and alignment with Microsoft’s long-term platform roadmap.
AVS Automatic Host Replacement (AHR) Support (VAIO)
Zerto now enhances its handling of Azure VMware Solution (AVS) Automatic Host Replacement (AHR) events, making background infrastructure changes far less disruptive to ongoing protection.
In AVS environments, Microsoft automatically replaces hosts that fail or are retired as part of normal platform operations. Without proper integration, these changes can introduce manual steps, increase the risk of errors, and potentially interrupt replication.
With this update, Zerto can respond intelligently to these events, maintaining protection continuity while minimizing operational effort.
When a host replacement occurs, Zerto detects the transition into maintenance mode and safely powers down the associated VRAs.
Workloads are then automatically redistributed across healthy hosts in the cluster, ensuring that protection remains intact throughout the process.
As the old host is removed, Zerto cleans up any orphaned VRAs and updates VPG mappings, accordingly, allowing replication to resume with minimal interruption.
This process integrates closely with AVS lifecycle operations. It accounts for changes in host inventory, affinity rules, and cluster state, ensuring that recovery configurations remain consistent even as the underlying infrastructure evolves.
Now, host replacements can happen transparently, without requiring manual VRA intervention or cleanup. It also simplifies planned maintenance activities, allowing clusters to cycle through maintenance mode at scale while preserving continuous protection.
It also improves overall operational hygiene by automatically handling cleanup and configuration updates as hosts are replaced or removed.
Zerto Analytics Updates
Analytics License View Update

Zerto Analytics has been updated to support the new multi-license and multi-package licensing model, making it easier to manage and understand licensing across different environments.
As organizations transition to Zerto 10.9 and beyond, they often need to work with a mix of legacy and newer licensing structures.
This update addresses that challenge by providing a unified view of license usage and entitlements across all reporting sites, reducing confusion and simplifying administration.
Now, Zerto Analytics consolidates both legacy (pre-10.9) and multi-license (10.9 and later) data into a single and consistent view. A new /v3/licenses API endpoint has been introduced to expose this combined dataset, allowing for more streamlined integration and reporting across environments.
At the same time, the /v2/licenses endpoint remains available to ensure backward compatibility with existing tools and workflows, allowing organizations to transition at their own pace without disruption.
It means better visibility into licensing and smoother migrations between the license models.
Link to the Dashboard navigation: Navigating the Zerto Analytics Portal
API Enhancements
Multi-License Management APIs
New /v1/licenses endpoints for managing multi-licensed ZVM clusters.
| Endpoint | Method | Description |
| /v1/licenses | GET | Retrieve installed license keys in a ZVM cluster |
| /v1/licenses | POST | Add a license key to a ZVM cluster |
| /v1/licenses | DELETE | Delete all installed license packages |
Link: ZVM REST API Swagger for Zerto 10.9
VPG Type Filter API
Added the option to filter by VPG type in the /get/vms API call.
External Secrets Vault API
New secretsStore parameter in POST/PUT /management/configuration/v1/settings for HashiCorp Vault integration.
Link: External Secrets Vault API
ZVM Appliance Network Configuration API
New /management/api/configuration/network endpoints for configuring the appliance network via REST API.
| Endpoint | Method | Description |
| /management/api/configuration/network | GET | Retrieve current network configuration |
| /management/api/configuration/network | POST | Define new network config (static/DHCP, IP, gateway, DNS) |
| /management/api/configuration/network/{GUID} | POST | Apply a defined network configuration |
Link: Configuration Service REST API for Zerto 10.9
ZVM Appliance Proxy & Reboot Configuration APIs
New APIs for managing HTTP/HTTPS proxy settings on the ZVM appliance.
- Set and retrieve proxy definitions used by both host and Kubernetes services
- Dedicated API for triggering ZVM appliance reboot after configuration changes
Link: Defining Proxy Configuration
Conclusion
HPE Zerto 10.9 represents a significant evolution in the enterprise resilience strategy, bringing together continuous data protection, cyber recovery, and AI-driven operations into a unified platform.
Expanding support across VMware, HPE VM Essentials, and public cloud environments gives teams the flexibility to operate across different platforms without being locked into a single ecosystem.
With capabilities such as cross-hypervisor replication, intelligent automation, and built-in cyber resilience, this release simplifies day-to-day operations while reducing recovery times.
More importantly, it enables organizations to respond more effectively not only to infrastructure failures, but also to increasingly complex security threats.
In practical terms, Zerto 10.9 helps teams strike a better balance between resilience and operational efficiency. It reduces complexity, improves visibility, and ensures that critical workloads remain consistently protected and recoverable.
Reference links are presented inside the text.
Discover more from CloudnRoll
Subscribe to get the latest posts sent to your email.
