You are troubleshooting a failover group for Azure SQL Database. The automatic failover is not triggering as expected during a regional outage. You verify that the grace period for data loss is set to 3600 seconds. The outage lasts 30 minutes. What is the most likely reason the automatic failover did not occur?
Trap 1: The failover policy is set to manual.
A manual failover policy means Azure SQL Database never initiates automatic failover, regardless of grace period or outage duration, so the 3600-second setting is irrelevant here. It is tempting because manual policy is a legitimate configuration, used deliberately when administrators want controlled, planned failovers rather than automatic ones.
Trap 2: The grace period for data loss is too short.
The grace period is the maximum data loss tolerated before automatic failover proceeds; 3600 seconds exceeds the 30-minute outage, so it is not too short. It is tempting because grace period governs failover timing, and it would be the correct suspect if the outage had exceeded the configured value.
Trap 3: The secondary region is also experiencing an outage.
A simultaneous secondary-region outage would block failover, but nothing in the scenario indicates the secondary is down; the stated 3600-second grace period versus 30-minute outage is the relevant mismatch. It is tempting because regional outages can affect both regions, which would genuinely prevent failover.
- A
The failover policy is set to manual.
Why it fails: A manual failover policy means Azure SQL Database never initiates automatic failover, regardless of grace period or outage duration, so the 3600-second setting is irrelevant here. It is tempting because manual policy is a legitimate configuration, used deliberately when administrators want controlled, planned failovers rather than automatic ones.
- B
The outage duration is less than the grace period for data loss.
Automatic failover only triggers once the grace period elapses, and 3600 seconds equals 60 minutes. The 30-minute outage falls short of that threshold, so Azure SQL Database withholds failover to avoid potential data loss, satisfying the stem's grace-period constraint.
- C
The grace period for data loss is too short.
Why it fails: The grace period is the maximum data loss tolerated before automatic failover proceeds; 3600 seconds exceeds the 30-minute outage, so it is not too short. It is tempting because grace period governs failover timing, and it would be the correct suspect if the outage had exceeded the configured value.
- D
The secondary region is also experiencing an outage.
Why it fails: A simultaneous secondary-region outage would block failover, but nothing in the scenario indicates the secondary is down; the stated 3600-second grace period versus 30-minute outage is the relevant mismatch. It is tempting because regional outages can affect both regions, which would genuinely prevent failover.