Guide
A practical 3-2-1 Mac backup strategy
A useful backup strategy is simple enough to run, redundant enough to survive real failures, and tested enough that restore is not a guess.
Start with the files that matter
Identify the folders you would most need after a loss: documents, projects, photos, finance records, exports, and work folders. Azivault is plan-oriented, so each plan protects one selected source folder.
Use at least two destination types
Keep one local recovery path for speed and one offsite recovery path for resilience. An external drive or network drive is useful locally. S3-compatible storage is useful when you want encrypted offsite backup with provider choice.
Use the 3-2-1 backup strategy
The 3-2-1 rule is a useful way to check for correlated failures: keep three copies of important data, across two kinds of storage, with one copy offsite. The original working files count as one copy; the other two must be independently recoverable rather than two synchronized views of the same account.
| Copy | Mac example | Primary recovery job |
|---|---|---|
| 1. Working data | Files on the Mac | Current everyday work |
| 2. Local backup | Time Machine on an external disk or supported NAS | Fast file recovery and Mac migration |
| 3. Offsite backup | Encrypted Azivault repository on S3-compatible storage | Recovery after theft, fire, or loss of nearby storage |
“Two kinds of storage” is less important than avoiding one failure boundary. A Mac and an external disk in the same bag are two copies but one theft event. A synced folder on two devices may still share one deletion or compromised account. Keep the offsite repository, provider credentials, and recovery password reachable when the Mac and local backup are unavailable.
The rule is a baseline, not proof of recovery. After setting up all three copies, restore one file from the local backup and one from the offsite path. See backup vs sync on Mac and how to back up a Mac to the cloud for the boundaries between those layers.
Use Time Machine and Azivault together
Time Machine for local Mac recovery. Azivault for encrypted offsite repositories. That is the clean split for many Macs: keep Apple's built-in backup layer for broad local restore, then add Azivault for the folders that need portable, encrypted recovery away from the Mac.
Keep recovery material separate
Do not store the only copy of the recovery password inside the folder being backed up. Keep provider account recovery and repository recovery material somewhere you can reach if the Mac is gone.
Test the actual restore path
- Create the plan and run the first backup.
- Open Restore in Azivault.
- Reveal a completed run in Finder.
- Copy one file to a temporary folder.
- Open it and confirm it is the version you expected.
Where Azivault fits
Azivault is strongest where you want encrypted repositories, folder or S3-compatible destinations, Finder restore browsing, and recovery that remains available for existing backups even if backup access later expires.
For whole-Mac migration, keep using the operating system tools designed for that job. For controlled folder backup and offsite encrypted recovery, use Azivault as a dedicated layer.
See also Azivault vs Time Machine, offsite backup for macOS, and S3-compatible backup.
FAQs
What is a good Mac backup strategy?
Use at least one fast local backup, one offsite backup, encrypted storage for sensitive data, and regular restore tests.
What is the 3-2-1 backup rule for a Mac?
Keep three copies of important data across two kinds of storage, with one copy offsite. A practical Mac setup is the working files, Time Machine locally, and an encrypted offsite repository.
Should I use Time Machine with Azivault?
Many users should. Time Machine is useful for local Mac recovery, while Azivault is useful for portable encrypted offsite repositories.
How often should I test backups?
Test after creating a plan, after changing destinations, and periodically for folders that contain important work.