News
Choosing a backup storage target: S3, Azure, Backblaze B2, SFTP, or your own NAS?
Every backup target will happily take your data; the differences show up when you need it back - in what a full restore costs, how fast it arrives, and whether a compromised server can wipe it first. We compare S3, Azure, Backblaze B2, SFTP, and your own NAS on cost, egress, immutability, and recovery speed, and show how to scope your Duplicati credentials so ransomware can't reach the backups.
Duplicati will happily write encrypted backups to any of these. Which one you pick matters far more than most people expect, though, because the destination determines three things you'll only discover under pressure: what you pay to get your data back, how fast that happens, and whether an attacker who compromises your backup machine can also wipe the backup.
Here's how the five most common targets compare on cost, egress, immutability, and recovery speed, with some opinionated guidance at the end.
Note: costs collected September 2026 based on public sources.
The short version
Target | Storage cost (per TB/month) | Egress on restore | Immutability / ransomware protection | Recovery speed |
|---|---|---|---|---|
Amazon S3 | ~$23 (Standard), ~$12.50 (IA), ~$4 (Glacier Instant) | ~$0.09/GB after 100 GB free | Excellent: Object Lock, versioning, fine-grained IAM | Fast, bounded by your bandwidth |
Azure Blob | ~$18 (Hot), ~$10 (Cool), ~$4.50 (Cold) | ~$0.087/GB after 100 GB free | Excellent: immutable policies, soft delete, RBAC + SAS tokens | Fast, bounded by bandwidth |
Backblaze B2 | ~$7 | Free up to 3× stored volume, then $0.01/GB | Good: Object Lock, versioning, scoped application keys | Fast, bounded by bandwidth |
SFTP | Whatever the host costs | Usually none | Only what the host OS gives you (chroot, append-only users) | Depends on host and link |
Your own NAS | Hardware amortised; near-zero marginal | None | Snapshots and separate credentials, if you set them up | Fastest for local restores; useless if the site is gone |
Now the details.
Cost: the storage line is the easy part
Object storage has converged at the top end. Storing a gigabyte of hot data costs about $0.023 on AWS S3 Standard, $0.018 to $0.023 on Azure Blob Hot, and $0.020 on Google Cloud Storage Standard as of July 2026. Backblaze is the outlier: as of July 2026, Backblaze lists B2 Cloud Storage starting at $6.95 per TB per month, free transactions, and free egress up to 3x average monthly storage.
The hyperscalers claw some of that back with colder tiers. Azure's Hot tier is 22% cheaper than S3 Standard: $0.018 vs. $0.023 per GB. Drop further and you get Azure Cool at roughly $0.010/GB and S3 Standard-IA at $0.0125/GB, with Cold and Glacier Instant tiers around $0.004–0.0045.
The catch for backup workloads is that the cheap tiers assume you rarely touch the data, and Duplicati does touch it. Retention pruning and compaction read and rewrite older volumes. On Standard-IA that triggers a $0.01-per-GB retrieval fee and charges requests at roughly double the Standard rate. Minimum storage durations bite too: Standard-IA is 30 days. Glacier Flexible is 90. Deep Archive is 180. Delete early and you pay as if you hadn't. A Duplicati job with a short retention window and frequent compaction can end up paying more on a "cheaper" tier than on Standard.
Practical rule: keep your working backup set on a hot or cool tier with no retrieval fee. If you want archival tiers, let the provider's lifecycle rules move old data there and turn off compaction for that job, so Duplicati isn't fighting the tier's economics.
For SFTP and NAS, the storage line is whatever the box costs. A NAS is cheap per TB once bought; a rented SFTP host is priced like a VPS plus disk. Neither has surprise line items.
Egress: the bill you only see on your worst day
Egress is what you pay to download your own data. You'll pay it exactly once for a small file restore and exactly once, at full scale, when you rebuild a server from scratch.
Amazon generally charges $0.09 per GB for data transferred from S3 to the public internet in the first major pricing tier, although the first 100 GB of internet data transfer out per month is free. Azure is nearly identical at $0.087/GB. Restoring 5 TB after a ransomware event costs about $450 on either, on top of the outage itself.
Backblaze's model is built for backup: all Backblaze B2 Cloud Storage users enjoy free data egress (also known as download) up to 3x their average monthly storage amount, and beyond that it's $0.01/GB. A full restore of everything you store is free by definition.
SFTP and NAS: no egress charge, though a NAS across a VPN or a budget SFTP host may be slower than the cloud providers in practice.
Immutability: can the attacker delete your backups?
This is the criterion that should override the others. Modern ransomware reliably looks for backup software on the machine it lands on, reads the stored credentials, and deletes the backup target before encrypting anything. Duplicati's encryption doesn't help here: an attacker doesn't need to read your backups, only to delete them.
There are two layers of defense, and you want both.
Layer one: limited-permission credentials. The credential Duplicati uses to write backups should be the least capable credential that still works. On S3, that means an IAM user or role scoped to a single bucket prefix. On Azure, a SAS token scoped to one container with an expiry. On B2, an application key restricted to one bucket. On SFTP, a dedicated user chrooted to its backup directory. On a NAS, a separate share with its own account rather than your admin login.
Duplicati needs list, read, write, and delete on its own files to run retention and compaction. The mistake is granting it more than that: account-wide access, the ability to change bucket policy, or the same admin credential you use for everything else. A credential that can only touch s3://backups/server-07/* limits the blast radius to one server's backup set.
Layer two: make deletion reversible. Even a correctly scoped credential can delete the files it wrote. So keep a copy the credential can't reach:
S3 and B2: enable bucket versioning, so a delete creates a marker rather than removing data, and a lifecycle rule expires old versions after your recovery window (say, 30 days). Object Lock in compliance mode goes further and makes deletion impossible for a set period.
Azure: soft delete for blobs and containers gives you the same undo window; time-based immutability policies are the Object Lock equivalent.
SFTP: the host's filesystem snapshots (ZFS, btrfs, LVM) are your undo. Take them on a schedule the SFTP user can't touch.
NAS: snapshots again, on a schedule, with the snapshot admin account separate from the backup share account. If the NAS is domain-joined, remember that an attacker with domain admin has it too.
The right mental model: Duplicati's credential can add and remove its files; something Duplicati doesn't control keeps a copy for long enough that you notice.
Recovery speed: bandwidth beats provider
For cloud targets, restore speed is almost entirely your downlink. All four cloud options will saturate a 1 Gbps line on a large restore; none will save you if the office is on 100 Mbps and you need 8 TB back. Do the arithmetic before an incident: 8 TB at 100 Mbps is about a week.
A NAS on the local network restores at wire speed, which is why it's the best first target for the common cases: a deleted folder, a corrupted database, a laptop rebuild. It's also the target most likely to be encrypted or physically lost alongside the primary data, which is why it shouldn't be the only one.
Archive tiers deserve a special warning. Glacier Deep Archive and Azure Archive charge $0.00099 per GB per month, but retrieval takes hours and costs extra per GB. That's fine for compliance copies you hope never to touch. It is not a place to put the backup you'll need at 2 a.m.
Which one should you pick?
Small business, one site, budget-sensitive: Backblaze B2 with versioning and a bucket-scoped application key. Lowest cost, free egress on restore, and an immutability story that's good enough for most.
Already on AWS or Azure: use it. The egress premium is real but predictable, and IAM/RBAC scoping plus versioning or soft delete is the most mature control set available. Keep the backup bucket in a separate account or subscription from production so compromised production credentials can't reach it.
MSP managing many clients: object storage with one bucket (or prefix) and one scoped credential per client. Per-client credentials mean one compromised endpoint exposes one backup set, not your whole book of business. This is where centralized management pays off: the Duplicati Console lets you see every job across every client from one place and spot the ones that have silently stopped.
You have a NAS: use it as the fast local tier and pair it with one of the cloud options above. Two targets, two credentials, two failure domains.
SFTP: a fine choice when you control the host and can snapshot it. A weak choice when it's a shared host you can't harden, because then you're trusting the host's security instead of a provider's.
Whatever you choose, test a restore. Not a single file: a full rebuild of one representative machine, timed, with the egress bill noted afterwards. The number you get is the real cost of your backup target.



