Bring your knowledge and expertise while creating blogs and podcasts
Recently active
We recently had a customer environment running Veeam Backup & Replication (VBR) 12 on a Windows server that was approaching end-of-life. The existing setup also included a local Windows repository for short-term retention and an HPE StoreOnce repository used for long-term retention.With both the VBR server and the StoreOnce platform approaching their lifecycle limits, we needed to plan a migration that would:Replace the aging VBR server Maintain the existing Veeam configuration and backup jobs Preserve all existing backup data Replace the legacy short-term repository Move the long-term backup data away from StoreOnce Improve the security posture with immutable backup storage Continue using the customer's existing socket-based Veeam licensingThe goal was not simply to build a new Veeam server, but to move the customer to a more modern and secure backup platform without losing access to the existing backup history. The Existing EnvironmentThe starting point consisted of:Veeam Backup
This week we are on to blog #8 in my v13 series. Check out the link below on my blog site and the blog article.Blog - v13 HA in One Lab Session v13 HA in One Lab Session Introduction High availability only matters when something fails. In a backup platform, that means the design should preserve management access and backup service continuity well enough that the environment remains useful during a component outage.Veeam v13 places new attention on HA as part of broader platform resilience. For production teams, a short lab session should focus on one practical question: when a node or service becomes unavailable, what keeps working, what pauses, and what dependencies become the real bottleneck? Identify the Dependency Chain Before any failover test begins, the environment should be mapped in simple terms. Storage, identity, networking, DNS, certificates, and any shared services all influence whether the backup platform is truly resilient or just appears redundant on a diagram.This is
Secure backups have always been important. But over the last few years, the requirements have shifted from “Yes, we should have backups — and ideally a second backup copy in another location and on another medium” to “Hopefully the backup still exists, is reachable, and really cannot be deleted.”Ransomware, compromised admin accounts, supply-chain attacks, and targeted attacks against backup infrastructures have made one thing very clear: a backup is only truly useful if, in the worst-case scenario, it is reliably available, usable, and uncompromised.Terms like WORM, immutability, Hardened Repository, Linux Repository, Veeam Infrastructure Appliance, single-use credentials, certificate-based authentication, Governance Mode, Single Disk, and Multi-Disk installation appear very quickly. But what is actually behind these terms, and what do I need for my use case?With Veeam Backup & Replication 13.1, the topic and the available options have been significantly improved and expanded. Bu
This one was a bit odd and the timing with my 13.1 upgrades didn’t help.https://nathanoldfield.tech/blog/veeam-cloud-connect-certificate-validation-after-13-1-upgrade/
Hi everyone! Hope this will be helpful. The idea of the scheme was to imagine everything that could require troubleshooting and put that on the scheme. v13.1 with lots of improvements and new workloads is in progress. Attached you can find both .jpg and .pdf formats, in second one you can put any word in search and find it on the scheme if it exists there. Created in Miro, handmade with lots of user guide research :)
One of the things I enjoy about designing Veeam environments is that the best architecture on paper is not always the best architecture for the people who have to operate it every day.This project was a smaller Veeam Backup & Replication v13 environment. The system administrators were very comfortable with Windows Server. Linux was another story. They had limited Linux experience and were hesitant to own a Linux-based system after implementation.That became part of the architecture decision. We could have introduced Linux simply because it gives us attractive security options, but doing that would also introduce another operating system the team would need to patch, monitor, troubleshoot, and secure. In a larger organization with dedicated Linux resources, that conversation is different. Here, operational capability mattered.So the question became: how secure can we make a Windows-based Veeam v13 deployment while keeping it manageable for the administrators who will own it?Figure 1
I took advantage of my holidays to step away from screens for a while. Unfortunately, the contest has now come to an end but I still wanted to share my experience with the community.So, what will you find in my toolbox? Well, before answering that, I think it's essential to cover a few other points first because being ready for a disaster is about more than just technology. Experience Is Your Best AllyI fully agree with what others have already mentioned: experience is your ally. The more you dig into topics and use your tools on a regular basis, the more comfortable you become and the day a problem hits, you'll be far more confident in how you approach it.Take the different restore options Veeam provides as an example: it is absolutely essential to test each of them so you understand *when* to use them. Knowing how and when to leverage Instant Recovery, for instance, can save you precious minutes when every second counts.You Need a Big-Picture View of the InfrastructureYou need a holi
When I first heard of the new Application Backup Repository that was just released in 13.1, my mind was full of ideas! I firstly documented what the Application Backup Repository (ABR) was and how to get up and running. https://vzilla.co.uk/vzilla-blog/the-veeam-application-backup-repository-13-1One of the first use cases, was based on us being asked by the Homelab community about Proxmox LXC container backup, we have accelerated how we protect and recovery Proxmox VMs but the business requests for LXC has been mild, so I thought how could we use this new feature to help. https://vzilla.co.uk/vzilla-blog/veeam-application-backup-repository-proxmox-lxcThe other idea I had was a much bigger problem to solve, Veeam have been great at protecting databases over the years, we have enterprise plug ins for most of the common databases we see across your estates as well as the public cloud managed databases and services. But what about all those others…. What about databases running in containe
Hey all,Back from a bit of a blogging hiatus to remind people of two things:That Entra ID got new capabilities in v13 & v13.1 That you have to reauthorise the application to enable them.It’s a really simple process, so I thought I’d just quickly show everyone how it’s done!Alt Text: Screenshot of the inventory view within VBR, selecting my Entra ID Organisation.Step 1: Within the Veeam Backup & Replication Console, go to Inventory, and then ‘Microsoft Entra ID’. Select your organisation, then choose Edit Tenant.Alt Text: View of the protected object types, with the new object types missing.Step 2: Proceed to the ‘Protection Scope’ section, you’ll see here every ‘Essential’ type of object protected (as the type name suggests, these cannot be removed). You may also see some ‘Optional’ type of objects protected here. This depends on which VBR version you onboarded your tenant, and whether you’ve remembered/known to do this in the past.Alt Text: Showing the menu presenting the obje
As many of us know, there is a migration path from Windows to VSA Appliance for VBR. Recently, this week I migrated another of our sites, but due to forgetting to remove the Windows VBK server from Enterprise Manager after I did the migration I could not enable some licensing checkboxes in the VSA. I opened a support ticket and worked with them to use PowerShell on the VSA to remove the link to VEM.CAVEAT - Please ensure to have a configuration backup and snapshots of your Veeam infrastructure for rollback, just in case.After doing this, I thought it would make for an interesting blog post to help others with this type of issue, so see the link below to my blog and the blog post itself. Enjoy.Blog - How to Remove Enterprise Manager Link after VSA Migration from Windows How to Remove Enterprise Manager Link after VSA Migration from Windows Introduction Veeam has a migration strategy for moving your Windows deployment to the new VSA Appliance by following KB4800. During this process w
I have upgrade myLab with last v13.1 of Veeam ONE and I share the procedure to add VSA 13.1 and some issues or problems that may occur. If you try to add the VSA to Veeam ONE you can receive this error message: This happens because you need to enable ‘Data Collection’ in the VSA’s ‘Host Management Console’ (HMC is on port 10443) by clicking on ‘Submit Request’:Ref.: https://helpcenter.veeam.com/docs/vbr/userguide/hmc_configure_infrastructure.html?ver=13#enabling-remote-data-collection At this point, by logging into the HMC using the Security Officer’s credentials, we can approve the request: Returning to Veeam ONE, I can continue with the process of adding the Veeam Backup & Replication Server; we have 60 minutes from the time of the request to complete the task: Need use user with admin right credential on “Veeam Analytics Service”, not “Security Officier”: VSA added: Enjoy Veeam ONE monitoring !
Managing user access through Microsoft Entra ID has become a standard requirement in many environments. With Veeam ONE 13.1, it is now possible to integrate SAML-based authentication and use Entra ID or any other SAML IDP as an external Identity Provider. This step-by-step guide shows the process on how to add Entra ID as an IDP in VeeamOne 13.1. First, we need to create an enterprise application in Entra IDNavigate to https://entra.microsoft.com/ --> Enterprise applications and add a new application Select "create your own application" and specify a name, I chose "VeeamOne SAML" Specify SAML as the single-sign on method Now switch to VeeamOne and go to configuration --> access management and add an identity provider In the Identity Provider Settings: Display name: specify some name for your IDPIDP URL: copy the "App Federation Metadata Url"Entity ID: copy the "Microsoft Entra Identifier" In the Veeam ONE Settings, you need to specify a Client ID, for example "VeeamOne"The S
Welcome to My First Technical Blog PostOver the past several years, I have had the opportunity to work with a wide range of Veeam technologies, including Veeam Backup & Replication, Veeam Backup for Microsoft 365, Veeam ONE, and the Veeam Service Provider Console (VSPC). Throughout these projects, I repeatedly encountered features that are incredibly powerful, yet often overlooked in day-to-day operations.One such feature is API Proxying via Veeam Service Provider Console (VSPC).In this article, I would like to share practical experience, technical insights, and real-world use cases around this capability. My goal is to demonstrate how service providers can simplify automation, reduce complexity, and leverage existing infrastructure more efficiently.If you have worked with VSPC API Proxying yourself, I would be happy to exchange ideas and experiences.Let's dive in! 👉What is VSPC API Proxying?Most Veeam users know the Veeam Service Provider Console as a centralized management platf
What is this about?Recently I ran into a subtle but classic Windows networking trap while wiring up an Ootbi appliance with two nodes and a common IP behind a corporate proxy. The symptom was familiar: everything looked correct in the Windows proxy dialog, yet the backup traffic originating from the Windows based gateway server still tried to crawl partly through the proxy instead of talking to the appliance directly. If you have ever set a proxy bypass in the GUI and wondered why a service ignores it completely, this one is for you.One note up front: I hit this with an Ootbi, but nothing here is Ootbi specific. This will bite you the same way with any S3 based / object storage target that you reach through an HTTP(S) endpoint behind a proxy, whether that is another on prem object appliance, a MinIO cluster, or a public S3 compatible service. The mechanism is Windows proxy handling, not the storage brand. The misleading symptom: it "connected", then the backup diedHere is the part tha
One of the things I enjoy most about every Veeam release is seeing how it continues to simplify day-to-day administration. While the headline features often get the most attention, it's usually the enhancements that streamline deployments, improve integrations, and reduce operational complexity that deliver the greatest value to customers.As someone who spends much of my time in the SHI Customer Innovation Center (CIC) building proof-of-concepts, validating solutions, and demonstrating real-world recovery scenarios, I wanted to take a closer look at two areas of the newly released Veeam Backup & Replication 13.1:The Veeam Software Appliance Storage integrations with enterprise backup repositoriesThese capabilities help organizations deploy Veeam more quickly, simplify ongoing management, and provide the flexibility to leverage the storage platform that best aligns with their performance, security, and business requirements. Throughout this article, I'll share what I found while tes
Hello, Veeam Community! I am pretty late to the party with the June newsletter, but I´ve been on a long PTO and didn´t want this content being forgotten as there are so many great articles I wanted to share them with you rather later than never! 🤓 The June Vanguard Newsletter brings together a broad set of community-created content focused on Veeam v13 readiness, cyber resilience, immutable storage, AI-driven operations, service provider enablement, and practical recovery workflows. Across blogs and videos, Vanguards emphasize hands-on guidance: how to deploy and validate new capabilities, harden environments, troubleshoot upgrade issues, and modernize data protection strategies across virtual, cloud, Kubernetes, Microsoft 365, and service provider scenarios.A major theme of June´s edition was secure, immutable backup storage, especially around Object First / Ootbi integrations with Veeam. Several posts walk through deploying Object First appliances, creating S3 keys and buckets, enab
other possible Topic-name: When a PostgreSQL Shows Up That Isn't Yours - A field report on a new AAP warning after the upgrade to 13.1 — including the workaround Veeam Support cleared me to publish. The symptomAfter upgrading a customers environment (doesn’t matter if VBR on Windows or VSA) to 13.1, a previously clean job started completing with a warning: a VM backup of (in this example) an Exchange server with Application-Aware Processing (AAP) enabled. Exchange processing itself was fine. The warning referred to a PostgreSQL instance that isn't really in access of the customer: an embedded component of (in this case) Trellix/McAfee Email Security running on the same guest OS.The customer told me: Vendor-managed, no credentials, no supported way to administer it.So Veeam can't authenticate against it — and flags that with a warning. The same job ran clean on the previous version. What changedSupport's original answer was (and i have the confirmation to do this post about it): With
Hi everyone! This is my first post on Veeam Community Hub, and I’m really excited to share with you all a little bit about my summer. Since starting with Veeam this past June for my Product Strategy internship, I’ve been working through all Securiti AI’s public certifications including AI Security & Governance and Data Security Posture Management (DSPM) while also digging into Veeam’s products. One surprising part is how much those two things line up. But once I started looking at Veeam Intelligence through the perspective of what those certifications teach, I kept noticing a pattern showing up again and again.What My Certifications Actually Taught Me The AI Security and Governance certification covers how organizations manage the risk that follows when placing AI into real workflows, including data visibility, access control, and being able to build trust in your data that you can rely on what an AI system does with it. The core lesson is that an AI system is only as trustworthy a
Honk Honk everyone! V13.1 is here, and with it the time-honoured sysadmin tradition: a lifecycle page in one tab, release notes in the next, then security advisories, upgrade documentation, and an ever-growing pile of KB articles. All fueled by copious amounts of coffee.I've spent more time on that routine than I care to admit, so I did the only reasonable thing and built a website.Upgrade Brief is an easy place to start researching a Veeam upgrade: https://upgradebrief.comI'm posting this one of a kind idea because I hope it makes upgrade research easier for everyone here. It exists to answer one question: "What do I need to know to upgrade?". It pulls from publicly available Veeam sources to help you find:Support and lifecycle information Documented upgrade routes, with links to the official instructions Relevant security advisories What changed in the version you're consideringIt can also generate a short PDF summary if you need something easier to share with a manager or change-app
Well, back this week with Blog #7 in the v13 series, and this one talks about Direct to Object Storage.Blog - Direct-to-Object Storage in v13: One Practical Lab Test Direct-to-Object Storage in v13: One Practical Lab Test Introduction Object storage has become a serious part of modern backup design because it changes how teams think about retention, off-site protection, and ransomware resilience. In Veeam v13, any direct-to-object workflow deserves a practical test that goes beyond whether the job can write data successfully.The production question is broader: can the environment store data efficiently, preserve it immutably where required, and still restore it inside acceptable recovery windows? A short lab test should answer all three before the design is promoted into daily use. Validate Ingest and Policy Behavior The first step is to confirm that the backup job writes to object storage consistently and that retention behaves the way the design expects. Production teams should pay a
I believe database restoration is one of the worst types of restores to perform.Not because it is a difficult or complicated restore to carry on.But normally, there's a lot other things tagle with the business when this type of server are involved with. So, there's a lot of pressure to restore those servers. The SLA with this kind of appliation are agressive and its really common the necessitty to restore it as soon as possible. The ProblemVery often, databases servers are connected to different networks/VLANs than the backup server. Database restoration involves a specific set of ports used during the process. All of these are listed in the Help Center, but if you haven't yet mapped and opened these ports between the networks, you will likely hit connectivity error similar to this one: The SituationNow you need to hurry to open those TCP/UDP ports with the network team to finish and complete the backup restore. In the meantime, the bussiness needs to wait until everything is cleared s
As a Managed service provider BCDR offering mean you can provide via Cloud Connect offsite storage into your MSP Datacentre. The lab design I build for reference. The use caseBack up customer(s) workloads from VMware or other hypervisors and restore them to the MSP's Hyper-V environment.The Testing use case validity under Veeam Data Platform (VDP) Version 13.01.In V13.01 it was my understanding was that Instant Recovery is supported to a Hyper-V host.However, after doing some due diligence, it appears this is only supported with standard backup scenarios and not when leveraging Cloud Connect service as an MSP.After reviewing the Considerations and Limitations section of the documentation, I found that the following capabilities are not supported on the tenant side:Instant VM Recovery to Hyper-V Multi-OS file-level restore Restore to Proxmox VE / oVirt KVM Restore to Microsoft Azure and Amazon EC2 from cloud repository backupsTo validate this in practice, I set up a small POC in my
Short Look at what’s new in Veeam v13.1 for MorpheusPlugin is Already part of the installation so no separate add-ons needs to be installed. Moprheus backup got supported with v13.0 but lacked the guest processing for SQL, AD and so on. it’s back as well as Guest indexing. Automatic Driver injection of the Virtio driver during restore.So this is the mostly missing features from v13.0 that we missed, but as you can now see Veeam do have fully support for Morpheus and the Automatic driver injection will be a great add-on to assist us with migration from other Hypervisor-platforms.
Why True Cyber Resilience Requires More Than One Immutable Repository "You wouldn't protect your house with just one lock. So why protect your last line of defense with just one immutable technology?"For years, the 3-2-1-1-0 rule has been the benchmark for designing resilient backup environments. It has helped thousands of organizations improve their backup strategy and defend themselves against ransomware.But cyber threats continue to evolve.Attackers are no longer just encrypting production workloads—they are actively targeting backup infrastructures because they know that if they can destroy your backups, they control your recovery.That made me think...Is one immutable repository really enough?Or should we apply the same security principles that we use everywhere else? Protecting Your HomeImagine you're leaving your house for a two-week vacation.Before you leave, what do you do?Certainly not just this:✔ Close the front door.Instead, you probably do something like this: 🔐 Lock the
Veeam continues to add feature improvements to make Veeam plugin for Nutanix AHV a strong option for hypervisor migration. The features listed below are highlighted in our “What New VBR 13.1” document. Please see details below. One Web UI for Every HypervisorYou can now add Nutanix AHV from the Veeam Web GUI. This allows for quicker deployment and simplified operations. Additional enhancements will continue to be added to the Web GUI in future. Add Nutanix AHV in Web GUIRole-Based Access Control, Scoped Your WayDefining custom roles with scoped access to specific VMs, jobs, categories, or infrastructure objects. Role-based access control (RBAC) this granular option means people see exactly what their responsibilities require, and nothing else. That's a tighter security posture, fewer accidental changes, and audits that don't turn into archaeology. This has been a highly requested feature for large customers. Also, this is what Veeam Cloud Server Providers need to provide better managem
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.