Bring your knowledge and expertise while creating blogs and podcasts
Recently active
How NTP Architecture Impacts MFA in Veeam Software Appliances — And What Happens When Clocks DriftMulti‑Factor Authentication (MFA) in Veeam’s software appliances relies heavily on accurate system time. This is because MFA one‑time passwords (TOTPs) are time‑based. If the appliance clock drifts even slightly, MFA will break — often in confusing ways.In this post, we break down:What NTP is doing inside the Veeam Software Appliance Why MFA fails when clocks drift How time desynchronization can escalate Worst‑case recovery when you’re completely locked outWhat NTP Architecture Is Doing Inside Veeam Software AppliancesVeeam Software Appliances use chrony (the NTP client on Rocky Linux) to synchronize system time with configured NTP servers. This ensures that all time‑dependent security functions — including MFA and OTP generation — remain accurate.Veeam imports NTP configuration through:Veeam Host Management Console (UI) where admins can set NTP servers Veeam Live OS ISO environment, whi
Applicability and efficiency of each transport mode primarily depends on the type of datastore used by the source host — local or shared, and on the backup proxy type — physical or virtual. The table below shows recommendations for installing the backup proxy, depending on the storage type and desired transport mode.which one do you use?
I just had a situation in a customer environment where the customer complained that a restored VM had more disks than the one that was backed up before (6 instead of 5 for a SQL Server VM).The recovery was done using Entire VM Restore - User Guide for VMware vSphere (veeam.com).When restoring to the original location, Veeam prompts you that the original VM will be deleted first:At first, I though this was related to the user that Veeam uses to access vCenter no having the appropriate rights. For example, the user does not have permissions to delete the VM.But then I noticed that the additional disk to be 200GB in size. The old state the we wanted to restore only had 2x100, 2x300 and 1x500. So where did the 200GB disk come from?It turns out that the size of this disk was adjusted by the VMware team a few weeks ago (100 → 200). We wanted to restore from an older state with the 100GB still there. Could this be the reason? Does VBR leave resized disks being alone while recovering and adds
Greetings friends! Today I want to share something that has been on my mind for a while, and I finally decided to tackle it head-on. If you're running Veeam Backup for Microsoft 365 with object storage (Wasabi, AWS S3, Azure Blob, or any S3-compatible provider), you've probably asked yourself:"How much space is each user actually consuming in my VB365 backup repository?"And if you're like me, exploring the Object Storage, you've also asked:"Wait... who is that GUID? And why is there data from an organization I deleted months ago still sitting there?"Spoiler alert: I found several GB of orphaned backup data that I could safely delete. But more on that little adventure later. Let's go!The Challenge: Understanding What's Really in Your Object StorageHere's the thing. Veeam Backup for Microsoft 365 stores backup data in object storage using a folder structure based on GUIDs. If you've ever opened your S3 bucket or Azure container and looked inside, you'll see something like this:Veeam/Back
HiIn the 2 days during VEEAMON 2021, there was often the question from new members why to choose Veeam over other competitors…Therefore my own top-15. There will be more reasons, but I think it will cover a lot of the reasons and I don’t think someone has to hesitate anymore ;-) PortabilitySomething I like very hard! All necessary information is built into the backup-file.You are not dependent of your backup-server to restore something. In case of emergency of disaster it’s just sufficient to install VBR Community Edition (free), import your backup-file and restore. You can even extract your backup-file (without VBR) to the .VMDK or .VHDX files.Next to that : the format is interchangeable : you can for example restore a VM (backup taken from vSphere on-premises) to Azure or to HyperV, or restore a backup taken with a Veeam Agent to Amazon EC2 or HyperV, … and so on, the list is very long! Not always possible with other backup vendors in my experience. Universal licensesIf you use univ
Hi AllLong time lurker, first time poster, I have collated a bunch of info from my home lab setup with Veeam Data Platform to create a full upgrade/patching guide for all the products to try and help people plan upgrades and keep on top of patchingIt includes the upgrade paths and guides forVeeam ONE, Veeam Enterprise Manager, Veeam Backup And Replication and Veeam Recovery OrchestratorHope this helps some peopleAny feedback is always welcome <3https://blog.leaha.co.uk/2025/04/10/veeam-data-platform-12-3-upgrade-guide/
Veeam includes many great options for protecting databases. Here, I will outline the configuration for using Veeam plug-in for Oracle through the managed interface to create a database backup. We will use the Veeam Backup and Replication console to create a backup job that will manage your Oracle database as any DBA would prefer.Create a protection groupThe managed backup feature utilizes protection groups to identify the servers to be protected and create a deployment job which will manage the deployment of the Veeam Oracle Plug-in. Select the ‘Inventory’ tab on the left, then right click the ‘Physical Infrastructure’ option in the inventory list in the upper left area of the VBR console and ‘Add protection group’. The ‘New Protection Group’ dialog will open. New Protection GroupProvide a name for the group, click next and you will select the option ‘individual computers’ within the ‘Type’ section, hit next and then ‘Add’.This will open the dialog where you can select the Oracle serve
Nutanix introduced AOS 6.8 and it is causing some API issues with Veeam Backup for Nutanix. This can result in restore failures and other issues. We are recommending Veeam customers not to upgrade until an updated version is available from Nutanix. The timeline we received for the update is later toward the end of the year. Please see the links below for the latest details😀.Veeam Forums link https://forums.veeam.com/nutanix-ahv-f51/aos-6-8-veeam-ahv-support-interoperability-validation-t93415.htmlVeeam Backup for Nutanix User Guide (Supported Versions)https://helpcenter.veeam.com/docs/vbahv/userguide/system_requirements.html?ver=50Thanks,Pete
An advantage of software-defined Veeam products is that they can be installed in many different ways and on any hardware your company owns and uses. They can be installed on-premises, or in any hyper-scale public cloud, you choose. To help customers architect, size, and secure the various Veeam products and features, the Veeam Solutions Architect team has created Veeam Security Blueprints (SBP) and they are publicly accessible. Veeam Security Blueprints can be found at https://www.veeam.com/security-blueprints.html Veeam Security Blueprints (SBP) are short (3 – 4 pages) scenario-based reference architectures covering common scenarios seen in the field. Types of scenarios include:On-premises environment using multiple different vendor storage targets (HPE, Cisco, Pure, Exagrid, Cloudian, Lenovo, Zadara, Hitachi Vantara). Veeam cloud backup products (Veeam Backup for Azure, GCP, AWS) VMC on AWS and hybrid environments Veeam Plugins for Enterprise Applications (Oracle and Microsoft SQL)
Agent For MAC Deployment always via catch-all protection groups•.pkg file for installation•Install with double-click or 3rd party software management solution*•Full Disk Access (FDA) must be allowed in both cases Full Disk Access: Manual ConfigurationGo to “Settings –Security & Privacy –Full Disk Access” Check Profile On MacOS 3 Ways To Connect Agent To VBR 1) Command line (same as Veeam Agent for Linux) 2) Import a Catch-Allconfiguration file; can be done via UI: 3) Use mobile device management to distribute a configuration profile Visibility On VBR Side Appears in VBR after import of Catch-All configuration Assign backup policies in VBR console IMPORTANT VAM does NOT back up volumesperform bare metal recoveryperform any sort of application aware backupsave applications settings (unless you specifically select the required files)allow non-admin users to access other users’ datahave local UI to create jobs
Hi all!!! I’m here to let you know that the Veeam Cookbook is here and available for all of you in https://veeamcookbook.com/. This cookbook is a collection of recipes to accomplish one task each, the idea is based on a recipe that you read for instructions not for explanations.This book is intended for many people: New to Veeam and just want a simple next, next, next, approach, not to learn about Veeam but how to do something. People who already know Veeam well but sometimes we only do tasks once on an odd occasion, we know the technology just cannot remeber the how! People who just want a quick refresh These recipes for now are based in Veeam Backup & Replication operations Version 11. The cookbook is the creation of the EMEA Veeam Solutions Architects, and we’d really appreciate your feedback for future releases. More to come soon!!!
Choosing the right object storage for backup and ransomware protection is not just about capacity — it’s about immutability, compliance, operational simplicity, and cost predictability.Here’s a clear comparison of three common approaches when using Veeam Backup & Replication: ✅ Veeam Vault (AWS/Azure)Designed as a managed STaaS offering, Veeam Vault delivers always‑on immutability, built‑in encryption, and a logical air‑gap by design. It integrates natively with SOBR and Capacity Tier, offers predictable per‑TB pricing, and removes infrastructure management overhead from the customer. ✅ Native AWS S3 / Azure BlobProvides strong integration and scalability, including Object Lock / immutable containers and support for compliance mode. However, immutability and air‑gap depend heavily on correct configuration, IAM design, and governance. Pricing is consumption‑based, which can introduce cost variability (“bill shock”). ⚠️ OCI Object Storage (S3‑compatible)While usable as an S3‑compatib
One of our customers is using Sophos Central with MDR (Managed Detection and Response) and recently added the "Back-up and Recovery" integration pack. This is an additional function that must be licensed accordingly!This means that it is now also possible to monitor and react to certain events within VBR using the Sophos Managed Service.Sean Simpson published the article Veeam Sophos Integration in the community in fall 2024. Among other things, this article deals with the advantages that are available with this solution.In this blog post, I will now look at the step-by-step deployment and show possible messages via email or from the Sophos Central Dashboard to give you an overview of the product.Under Veeam Backup & Replication integration, Sophos Central provides information on the scope and requirements. At Veeam, there is a corresponding white paper in the Resource Library under Sophos and Veeam Integration. Licensing & activation by https://central.sophos.com/manage/over
When designing a Hyper‑V backup architecture, one of the most important decisions you’ll make is how will backups be moved from a hypervisor and how are they processed. In Veeam Backup & Replication, Hyper‑V backups rely on backup proxies, and unlike vSphere, Hyper‑V proxy behavior comes with some unique considerations that require upfront planning.Hyper‑V supports two types of backup proxies:On‑host proxies Off‑host proxiesAt a high level, these operate similarly to VMware proxies—but the implementation details, limitations, and operational overhead are significantly different. Let’s break them down and discuss when (and when not) to use each. On‑Host Proxy: The Default and Recommended ChoiceFor most environments, the on‑host proxy is the simplest, most reliable, and recommended backup transport mode.When a Hyper‑V host is added as a managed server in Veeam Backup & Replication, the on‑host proxy is automatically deployed to it. Each Hyper‑V host runs its own proxy, leveraging
Title Image: ‘Veeam Backup & Replication - Linux Agent Deployment & Management with Active Directory’ against a colourful background.Veeam Backup & Replication has some nice out-of-the-box features for Veeam Agent management if you’re using Microsoft Windows or Linux Operating Systems. I don’t like talking about a possible solution though until I’ve tried it for myself. This way I can gauge the problems that’ll occur by how I’ve tripped up in testing.This brings me to the topic of today, Linux + Veeam Backup & Replication Agent Management.Nowhere within Veeam’s documentation could I find references to what was/wasn’t supported for creating an Agent Protection Group. I see this as a potential risk, without stating which operating systems you can target via the mechanisms such as Computers from CSV file or Microsoft Active Directory Objects etc, how do you know if it will actually work? I could add IBM AIX servers to a CSV file, but that won’t work in reality as I’d need
Hi all,I would like to share with you that it is possible to reset the IPMI password using a bootable USB drive and physical access. This works perfectly on an OOTBI. I haven't tested it on an Exagrid, but I believe it should work as well.In the event of a lost IPMI password or a bad copy/paste during installation (note that the password must not exceed 20 characters), it is possible to reset it to its default value.IPMI password can be reset to default by restoring the factory settings IPMI module using the tools available IPMICFG, IPMITOOL. Be careful it may happen that the network configuration is restored to the factory settings, so before performing this operation, note the current network configuration. IPMICFG is available for DOS, Linux and Windows.PREPARATION:Preparing a USB key with your favorite OS (eg. Use tool Rufus to create the livecd)Download the latest version IPMICFG:https://www.supermicro.com/wftp/utility/IPMICFG/Unpack and copy the DOS directory on the stickRESTART
1. Two Backup Methods, One Recovery Console Veeam provides two distinct methods for backing up Oracle databases. The first is image-level backup with application-aware processing, where VBR takes a VM-level or agent-level backup and handles Oracle archived redo logs as a guest processing subtask. The second is the Veeam Plug-in for Oracle RMAN, which integrates directly with Oracle's native Recovery Manager and sends backup data to a Veeam repository through the RMAN SBT (System Backup to Tape) interface.Both methods feed into the same recovery tool: Veeam Explorer for Oracle. Explorer can restore databases from either backup type through a single interface. The key difference is what each method captures and what recovery options each enables. Capability Image-Level Backup RMAN Plug-in Backup scope Entire VM or volume (includes OS, Oracle binaries, database) Database only (data files, control files, archived logs) Point-in-time restore
This article is intentionally for one specific scenario: upgrading an existing Windows-based Veeam Backup & Replication installation from v12.x to v13—including the issues that can come up in real-world upgrades.I already wrote a general blog post about patches/upgrades that serves as a guideline for practically all Veeam updates (pre-checks, order of operations, typical pitfalls, rollback strategy, change window, etc.). That guidance is still fully valid. What about the VSA (Veeam Software/Server Appliance)?If you can/want to move directly to the VSA, the best approach is usually a greenfield installation: deploy a new VSA and rebuild your jobs step by step according to current best practices. This is not only the cleanest migration path, but also a great opportunity to remove legacy baggage and review/update your configuration in detail — aligned with best practices and your specific use cases.There is also a migration path from Windows (e.g., 12.3) to VSA 13.0.1, but it comes
Greetings to everyone here!😎 Following the Broadcom disruptions in the market, many customers told us they’re investigating alternatives. Those of you who closely follow Veeam might have heard about the work we’re doing to satisfy those needs. But have you heard about the Veeam and Scale Computing strategic announcement with the intent to bring our proven data protection capabilities to the Scale HyperCore hypervisor? We initially targeted Q4 ’25 for this project, but thanks to the incredible work of the R&D team, the Veeam Backup for Scale Computing plug-in is live and you can try it today. While the official announcement and related marketing activities are scheduled for October, let’s not hesitate and take a look right away. Over the last few weeks, I’ve been playing with the solution and with Scale HyperCore, and I’m going to share my findings so you can do the same and save some time fighting configs.A few words about Scale HyperCore. It’s a KVM-based hyperconverged platform
Cloud adoption continues to increase as organisations are either taking their first steps into the cloud, or progressing their IT strategies, whether it’s a full cloud migration, multi-cloud or delivering a hybrid architecture.A great workload to leverage the cloud has been as a backup repository. By using the cloud, we can meet multiple improvements to our 3-2-1-1-0 minimum strategy for backups. In case you aren’t familiar with the 3-2-1-1-0 strategy, it is:3 copies of data, across 2 different backup media types, 1 of which must be off-site to the production environment, 1 backup at least must be offline or “immutable”, with 0 backup validation errors. Security BoundariesOne threat that the 3-2-1-1-0 strategy doesn’t cover explicitly is the concept of security boundaries. It is entirely possible to achieve all 3-2-1-1-0 objectives purely within your own environment, or exclusively within a single cloud, but there are problems with either approach, as we’ll look into now. Internally Ma
WebLAPS is a web-based solution for managing Microsoft Local Administrator Password Solution (LAPS). Below are some articles that have been previously shared with the community on Windows LAPS. Also, @Michael Melter discussed LAPS as mentioned in the article below, and I recommend you take a look at it for added knowledge which is not covered in this article. WebLAPS could be used to implement just-in-time administration (JITA) approach recommended by MS when accounts of system administrators are added to privileged groups for defined period of time and automatically removed after. Please refer to the official documentation for more information. Also, here is how to configure Windows LAPS with Microsoft Intune as well. This article targets users that are still using the legacy Microsoft LAPS and not the Windows LAPS. Microsoft recommends that customers begin planning on how to migrate their Windows LAPS-capable systems from using legacy Microsoft LAPS. Microsoft LAPS product is depre
🚀 Exciting news for Service Providers!Veeam Service Provider Console (VSPC) v9 just dropped, and it comes packed with some really cool new features. Over the past few days, I’ve been digging into one in particular—REST API proxying—and wanted to share what I’ve discovered, plus a small demo script that shows just how powerful this feature can be. So, what’s REST API proxying?Simply put, VSPC can now use a single API token to authenticate itself and then proxy requests to all your remotely managed Veeam products. That means you can manage everything from one central console without juggling multiple keys or credentials. A note on securityBecause a single API key can reach all your servers, it’s super important to keep it safe. Treat it like gold. 😄 When you create an API key, you can also enable “read-only access.” This applies not only to calls against VSPC itself but also to all proxied requests to your Veeam servers. If you’re just pulling information (like in my demo), enabling re
Hi all, I wanted to share the new Veeam Ports MCP server with the community. This gives you the ability to interact with the Veeam Ports underlying database to create rich designs using LLM clients that support MCP, like Claude and VS Code.https://github.com/shapedthought/veeam-ports-mcpTo install in Claude:Install Python Install UV Run: claude mcp add veeam-ports -- uvx veeam-ports-mcp Update your Claude desktop configuration file: macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json { "mcpServers": { "veeam-ports": { "command": "uvx", "args": ["veeam-ports-mcp"] } }}I am still working to improve it to provide greater fidelity. Currently, the best way to work with it is to ask the AI to walk you through putting a design together; that way, it will guide you in selecting what you need in the correct order.There is also a tool called generate_app_import. When you're happy with the design, you can a
Hi, How can I add backup repository (Linux hardened) to Veeam office 365 backup?
Hi folks, as of today, V13.0.1 for Veeam Backup & Replication is generally available! This release also supports Windows Server versions of VBR.In addition, Veeam Recovery Orchestrator (VRO) v13.0.0 and some other products like Veeam ONE v13.0.1 and Veeam Service Provider Console v9.1 have also been released today. So I went into my lab and just started the upgrade procedure from my Veeam Recovery Orchestrator Environment / VRO 7.2.1 → 13.0.0.See the steps below and hopefully no issues… Download the binaries from: Discover the Latest Version of Veeam Solutions. And make sure you have a backup of your current installation 😀 Step-by-step in Screenshots: If nothing special mentioned, it’s in my case a Next, Next, Finish process... Goodbye old icons? oops, let’s see… I just copied the mentioned warning in the clipboard: Mostly deprecated features (within VBR), wh
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.