Technical guide
How to back up iCloud Photos on a Mac
To create an independent iCloud Photos backup with Azivault, add a plan with Photo Library as the source, choose the whole library or selected albums, choose storage, save the recovery password, and run the first backup. Azivault asks PhotoKit to retrieve selected resources, including originals stored only in iCloud.
Published and technically reviewed: .
Scope and disclosure. iCloud Photos and backup solve different problems. Azivault protects portable resources, supported metadata, and user-created album organization. It can’t recreate every Apple-managed Photos feature.
Why keep a backup when you use iCloud Photos?
iCloud Photos keeps one photo library synchronized across your Apple devices. A deletion or edit can become the intended state everywhere. Apple provides Recently Deleted and other recovery features, but those remain inside the same Apple Account and product rules.
Apple recommends keeping a local backup of your Photos library even when you use iCloud Photos. An independent repository adds a separate storage and recovery boundary. It can also preserve completed snapshots after later changes appear in the synchronized library.
For the broader distinction, see Backup versus sync on a Mac.
Choose the Photos source
- Open Azivault and choose Create New Plan.
- Enter a plan name that identifies the library and destination.
- In Source type, select Photo Library.
- Continue to Albums, then include the whole System Photo Library or choose user-created albums.
Azivault uses PhotoKit instead of treating the .photoslibrary package as a folder. Don’t add the library package to a normal folder plan. Its internal database, resources, and iCloud state require the Photos-specific pipeline.
When you select albums, the plan backs up the union of their assets. An asset that appears in several selected albums keeps the relevant memberships without duplicating its encrypted resource bytes.
Choose independent storage
Store the repository somewhere outside the Photos library and preferably outside the Mac’s primary failure domain. Azivault supports the following destination types:
- A local folder or external disk for a nearby copy.
- A mounted NAS or network drive for shared local storage.
- S3-compatible object storage for an offsite copy.
Azivault doesn’t bundle storage. You provide the destination and retain the provider account. The app encrypts resource bytes and sensitive manifest data before writing them.
For a large library, estimate the selected resources, destination capacity, upload time, retrieval cost, and first full-restore time before you depend on the plan.
Save the recovery material
Create the recovery password during plan setup and store it somewhere that survives loss of the Mac. You can also store the repository key in iCloud Keychain for convenience, but the recovery password remains the portable unlock route.
If you lose every copy of the repository key and recovery password, Azivault can’t reset the client-side encryption.
Approve Photos and Automation access
Azivault needs full Photos access to read the selected assets, resources, and albums. macOS asks separately for Automation access when Azivault reads titles, captions, and keywords from Photos.
If you deny Automation access, the resource backup can still complete. The snapshot records a coverage warning instead of claiming that descriptive metadata was preserved.
Scheduled Photos backups run through the Azivault Scheduler helper. Because it is a separate process, macOS can ask it for its own Photos and Automation permissions during the first scheduled run.
Handle optimized storage
Optimize Mac Storage can leave full-resolution resources in iCloud rather than on the Mac. Azivault enables network access when it asks PhotoKit for those resources. You don’t need to switch Photos to Download Originals to this Mac before the backup.
The Mac still needs the correct Apple Account, a working internet connection, enough temporary and destination capacity, and time to retrieve the selected data. A first backup of a large optimized library can take much longer than a later incremental run.
Keep the Mac awake and on a suitable network for the first run. If Photos can’t provide one selected resource, Azivault doesn’t commit a partial snapshot as a restore point.
Run and check the first backup
- Finish the storage, schedule, encryption, and review steps, then choose Add Plan.
- Select the plan and choose Run Now.
- Keep Photos and network access available while iCloud-only resources download.
- Confirm that the run reports a committed Photos snapshot.
- Open the snapshot details and review included metadata and fidelity warnings.
Manual backups and restores are free. The configured schedule runs during the trial or with monthly, yearly, or lifetime automatic-backup access.
Verify more than the item count
A useful check covers repository integrity and recovery behavior:
- Compare the snapshot’s asset and resource counts with the intended plan scope.
- Review warnings for titles, captions, keywords, and Apple-managed exclusions.
- Restore a small test album into Apple Photos.
- Confirm that the restored resources, metadata, and album organization match the snapshot coverage.
Counts alone don’t prove that a resource decrypts or that album relationships can be reconstructed.
Add a second failure domain
An external disk beside the Mac helps with fast recovery, but one theft or physical incident can remove both. A single S3 account can also fail through credentials, billing, or accidental deletion.
For irreplaceable photos, keep more than one recovery path. For example, use Time Machine for local Mac recovery and an encrypted Azivault repository on offsite storage. Store the recovery password separately, and repeat the restore test after changing destinations or permissions.
Related technical reading
- Apple: Back up the library in Photos on Mac
- Apple Photos backup feature and fidelity
- Restore an Apple Photos backup
- Build a practical Mac backup strategy
FAQs
Is iCloud Photos a backup?
iCloud Photos synchronizes a photo library across devices and includes recovery features, but Apple still recommends keeping a separate backup copy of the library.
Do I need to download all originals before using Azivault?
No. Azivault asks PhotoKit to retrieve selected iCloud-only resources during the backup. The Mac must be online and able to download them, so the first run can take time and bandwidth.
Can I back up only certain Photos albums?
Yes. A Photos plan can cover the whole System Photo Library or the assets in selected user-created albums.
Can I back up Photos to an external drive or S3-compatible storage?
Yes. Photos plans can use local folders, external disks, mounted network storage, or S3-compatible object storage.