Bring your knowledge and expertise while creating blogs and podcasts
Recently active
Air-gapping your backups sounds simple in theory:“Just isolate them so nothing can touch them.”But in practice?That’s where things get tricky.Because the moment you start locking things down too aggressively, you risk:Breaking backup jobs Slowing down restores Creating operational headaches Or worse—making recovery harder when you actually need itI’ve seen environments go too far:Backups fully isolated… but unusable Processes so manual they never get tested Security so tight it blocks recovery workflowsThat’s not resilience. That’s friction.So let’s talk about how to air-gap Veeam the right way—without breaking operations. First: What “Air-Gap” Actually MeansAir-gap doesn’t have to mean physically unplugged (although it can).In modern environments, it usually means:Logical isolation Controlled access Separation from production riskThe goal isn’t to make backups unreachable.The goal is to make them untouchable by attackers—while still usable by you. The Core PrincipleBackups should be e
TL,DRIf a VMware VM has Virtualization Based Security (VBS) enabled, SureBackup can fail with “Invalid change tracker error code” during snapshot creation. The underlying cause is that SureBackup, by default, modifies the VMX and disables Virtual Hardware Assisted Virtualization (VHV) by setting vhv.enable to false, but VBS requires VHV. The fix is documented in KB4003: SureBackup for VM With VBS Enabled Fails With “Invalid change tracker error code” and boils down to creating a registry value on the Veeam Backup Server so SureBackup stops flipping vhv.enable. The symptomA SureBackup job in one of our customer environments tests multiple VMs, and suddenly one VM consistently fails with:An error occurred while taking a snapshot: Invalid change tracker error code:[25.02.2026 16:47:34.391] <17> Info (3) [SureBackup] [SQL 2022] [RegisterVm] > VmRef = vm-469403[25.02.2026 16:47:34.391] <17> Error (3) [SVmWareCtkHelper] Failed to disable CTK on VM, Ref: VmRef
Veeam Community Hackathon banner. Alfred is sitting in the middle of a desk. He is about to press the run button with his paw. Binary code and a slider are shown on the left of Alfred. In the middle, the word Hackathon is shown with arrowed lines pointing to icons and text describing several aspects of the Hackathon: Development, Brainstorm, Time, Presenting, Goal, Teamwork, and Community.🚀 Join the 4th Annual Veeam Community Hackathon (2026)!We’re excited to announce that the Veeam Community Hackathon 2026 kicks off on October 7, 2026 at 15:00 CEST / 9:00 AM EST — and registrations are now open! 👉 Sign up here: https://my.veeamhackathon.com⏳ Sign-ups close on September 30, 23:59 CEST / 5:59 PM EST 🌍 What is it about?This is a global, community-driven event where teams of 12–18 participants collaborate to build innovative solutions that enhance and complement existing Veeam products.💡 Your mission:Create something that makes life easier for end users — whether that’s a dashboard, t
With this post I want to highlight the community again as we held our 1st in-person Veeam User Group event in Cologne yesterday. This was a curious one for us, because it was the first time we rotated and went way north in Germany and leave our sweet South and Southwest spot. However, it turned out we almost had 60 in-person attendees and only 4 no show attendees which is a huge success and the biggest success in our eyes. This means the Veeam community is really working, people love to attend the VUGs and get together. We couldn’t be more proud !A HUGE THANK YOU to our sponsor Scality who made sure we can have such an amazing venue, food, catering, a barista (!) and drinks throughout the day. A simple amazing effort which we highly appreciate ! Furthermore a huge thank you to Veeam, especially to everyone who supports the Veeam Usergroup behind the scenes. We also had a massive representation from the german Veeam100 people which is always a blessing to see !Special thanks also go out
Greetings friends! Today I want to share something that has been on my mind for a while, and I finally decided to tackle it head-on. If you're running Veeam Backup for Microsoft 365 with object storage (Wasabi, AWS S3, Azure Blob, or any S3-compatible provider), you've probably asked yourself:"How much space is each user actually consuming in my VB365 backup repository?"And if you're like me, exploring the Object Storage, you've also asked:"Wait... who is that GUID? And why is there data from an organization I deleted months ago still sitting there?"Spoiler alert: I found several GB of orphaned backup data that I could safely delete. But more on that little adventure later. Let's go!The Challenge: Understanding What's Really in Your Object StorageHere's the thing. Veeam Backup for Microsoft 365 stores backup data in object storage using a folder structure based on GUIDs. If you've ever opened your S3 bucket or Azure container and looked inside, you'll see something like this:Veeam/Back
When running self-hosted applications in a homelab or on-premises environment, HTTPS is often the first thing to fall through the cracks. Self-signed certificates trigger browser warnings, and public certificate authorities like Let's Encrypt require your services to be internet-accessible. The solution? Run your own internal Certificate Authority.However, this is not a difficult problem to solve. Just setup an internal PKI using Step CA running as a rootless Podman container, then extend it to issue certificates for services on your network. In this first part, we'll focus entirely on getting Step CA up and running — initializing the CA, configuring automated certificate issuance, and setting up a systemd timer to handle renewals without any manual intervention.Create a new podman network for step-capodman network create ca-servicespodman network lsCreate a CA volume and Quadlet (quadlets are the preferred method for starting Podman containers:podman volume create step-camkdir -p ~/.c
With the High Availability feature in Veeam Software Appliance 13.0.1, Veeam provides a neat way to make the backup server highly available. In this blog post I’ll briefly show how to configure HA, which prerequisites must be met, and what alternatives exist if HA cannot be used. Intro - The Basics The feature itself reduces downtime of the backup server in the Veeam Software Appliance. In general, two nodes are required; they can synchronize even across relatively high latencies. A manual switchover is possible, and a major advantage is automatic updates for both nodes. The goal is to offer fast disaster recovery without the need to keep a dedicated standby backup server, and then finally to restore the configuration backup. (https://helpcenter.veeam.com/docs/vbr/userguide/high_availability_hiw.html?ver=13) Requirements The following components are required for this feature: Two Veeam Software Appliances At minimum, Veeam Data Platform — Premium licensing (the package that includes
In the final article of this three-part series, we’ll explore how proactive operations with Veeam can help organizations reduce downtime and enhance data protection.By the time you reach this point, things feel different.You’re no longer chasing failures.You’re no longer guessing recovery times.You’re not constantly reacting to alerts.Instead, your Veeam environment starts to feel… predictable.That’s the goal.But scaling proactive operations isn’t just doing the same things on a bigger environment.It’s about operating with intention, consistency, and confidence—no matter how large things get.This is what that actually looks like in practice. 1. Health Is Measured, Not AssumedAt scale, you don’t rely on “it looks fine.”You rely on metrics and trends.What you know at any given time:Job success and warning rates Backup window utilization Repository performance and latency Growth trends across all storage tiersThe difference:You’re not asking:“Are backups okay?”You already know.Because you
Microsoft BitLocker Administration and Monitoring (MBAM) and Advanced Group Policy Management (AGPM), both part of the Microsoft Desktop Optimization Pack (MDOP), have officially reached end of support as of 14 April 2026 (today). From this point forward, Microsoft will no longer provide security updates, bug fixes, or compatibility assurances for these tools, similar to the lifecycle outcome observed with Microsoft Deployment Toolkit (MDT).Organizations that continue to rely on MBAM and AGPM must now assess risk exposure, validate operational dependencies, and define a transition strategy toward supported alternatives to maintain security, compliance, and long-term manageability.To help you transition away from MBAM and AGPM, I have outlined practical and supported alternatives in the following guides. These articles provide a deeper dive into modern solutions and implementation approaches you can adopt moving forward.https://techdirectarchive.com/2026/04/14/agmp-extended-support-ends
IntroductionTo enable monitoring of your Veeam Software Appliance (VSA) with VeeamONE, the Veeam Analytics Service needs to be deployed on the VSA.The Veeam Analytics service not only enables communication with Veeam Backup & Replication servers to collect data but also allows to send remediation commands.Since the VSA is secure by design (hardened Linux-based OS, DISA STIG compliance, automated patching…) and that it enforces Zero Trust principles with role-based access control, SAML SSO, and certificate-based pairing, it is important to know what are the available options to connect VeeamONE securely. In this article, we will cover 2 methods of connection and highlight their pros and cons:Via the Veeam Analytics Service Offline BundleORManaged by VeeamONE via the Data Source Wizard Connecting to the VSA with the Offline BundleThe advantage of using the offline bundle is that you don’t need to store VSA credentials anywhere. Simply hand off the bundle to your Veeam Backup and Repl
Choosing the right object storage for backup and ransomware protection is not just about capacity — it’s about immutability, compliance, operational simplicity, and cost predictability.Here’s a clear comparison of three common approaches when using Veeam Backup & Replication: ✅ Veeam Vault (AWS/Azure)Designed as a managed STaaS offering, Veeam Vault delivers always‑on immutability, built‑in encryption, and a logical air‑gap by design. It integrates natively with SOBR and Capacity Tier, offers predictable per‑TB pricing, and removes infrastructure management overhead from the customer. ✅ Native AWS S3 / Azure BlobProvides strong integration and scalability, including Object Lock / immutable containers and support for compliance mode. However, immutability and air‑gap depend heavily on correct configuration, IAM design, and governance. Pricing is consumption‑based, which can introduce cost variability (“bill shock”). ⚠️ OCI Object Storage (S3‑compatible)While usable as an S3‑compatib
Backups without notifications are like monitoring without alerting: you can live with it—until the day you can’t.Veeam Backup & Replication (VBR) and Veeam Backup Enterprise Manager (VEM) can send automated emails, for example when an event is triggered, like:Job success/warning/failure Infrastructure warnings Licensing/support notificationsThe goal: you find out about problems as soon as they happen.(And yes: “no news” are also news—but only if you’re sure your email delivery is actually working.) Veeam Doku: E-Mail-Settings & Notifications (VBR v13)https://helpcenter.veeam.com/docs/vbr/userguide/pve_email_settings.html?ver=13VEM Doku: Email-Settings & Notification (v13)https://helpcenter.veeam.com/docs/vbr/em/notifications_ms365.html?ver=13 “Can’t I just enter an SMTP server + username/password and be done with it?” For several years, that was actually the only way—and of course it can still work today. This classic approach is called SMTP server (basic authentication).V
In Part 1, we talked about the difference between reactive and proactive Veeam operations.But knowing the difference is the easy part. The real question is:How do you actually make the transition—without overhauling everything at once?Because most environments can’t just stop and rebuild.They have to evolve.This is how you do it—step by step, without creating more chaos in the process. Step 1: Get Visibility (You Can’t Fix What You Can’t See)Before you change anything, you need a clear picture of where you are.Start with:Job success vs warning vs failure rates Backup job durations (are they increasing?) Repository capacity and growth rate Restore success history (if any exists)The goal:Understand your baseline.Not what you think is happening—what’s actually happening.Proactive operations start with awareness. Step 2: Clean Up the NoiseMost reactive environments have one thing in common:Too many alerts. Too many warnings. Too much noise.Do this next:Review all current warnings Fix what
Introduction: A Journey That Started with 3-2-1-1-0Five years ago, I published my first Veeam community post about the 3-2-1-1-0 golden backup rule. That post marked the beginning of my journey as a Veeam Legend.Back then, the rule was already considered best practice. Today, it is still relevant — but no longer sufficient on its own.The threat landscape has evolved. So our backup strategies need to follow.The Foundation Still MattersThe 3-2-1-1-0 rule remains the baseline:3 copies of your data 2 different media types 1 offsite copy 1 immutable or air-gapped copy 0 errors (verified recoverability)✔️ This model protects against hardware failure✔️ It addresses human error✔️ It covers traditional disaster scenariosBut here’s the reality:⚠️ Attackers now design their operations specifically to break this model.What Changed? (And Why It Matters)1. Backups Are the First TargetModern ransomware attacks:Target backup servers first Delete or corrupt backup chains Exploit APIs and credentialsBa
In a recent customer project, I was allowed to perform a new installation of the Veeam Recovery Orchestrator (VRO). The installation itself was initially completely inconspicuous – but on a German-language Windows Server operating system, which later turned out to be a decisive factor.Immediately after the installation, we authorized the local administrator group within the Onboarding-Wizard to access the VRO system. So far, so good. Or so we thought! The result: No user who was a member of the local administrators group was able to log on to the VRO system. Error: Access denied for the user 'User-within-local-Administrators-Group': the provided credentials are invalid or the user has insufficient privileges.This meant that we were locked out immediately after installation. Troubleshooting: A look behind the scenesAfter a short analysis, it was clear: We won't get anywhere with the web UI at this point. So we decided without further ado to take a targeted look at VRO's SQL database
Hello, veeamazing community,I am back with another Veeam Vanguard Newsletter packed with tons of great content! Go and check yourself what articles published our veeamazing Vanguards during the month of March! Across these articles and videos, the authors cover a broad set of Veeam platform operations, security, and community themes: from urgent Veeam Backup & Replication (VBR) patching and remediation of critical CVEs (including guidance to update promptly) to platform upgrade and maintenance tasks such as upgrading embedded PostgreSQL and step-by-step Veeam v13 suite upgrades (Veeam ONE, Enterprise Manager, Recovery Orchestrator, and VBR). Several posts dive into v13 architecture and hardening, including Veeam Software Appliance / VSA customization via config files (instead of Windows registry), port customization concepts, and High Availability with VSA HA cluster setup plus Veeam ONE monitoring using alarms/dashboards and REST API automation. The list also includes practical h
You might have missed it but this week Mr. Cloud Connect published a blog about setting up a test KMS server! Exactly a Month ago I was thinking the same thing and found it to be a world of pain. At the time I tried PyKMIP and Cosmian but had major issues. Then I tried vibe coding a KMS DIY server with my buddy Claude (well at times buddy at others arch enemy!!). I got to the point where Veeam accepted the KMS server but then the job would fail. @LDelloca did what folks at his level simply do, forked the old PyKMIP and added the bits and pieces needed! He is not known as Mr. Cloud Connect for nothing, see his blog here: https://www.virtualtothecore.com/fixing-pykmip-for-veeam-integration/My home lab is not big so I try to do everything in containers and for this I looked at his forked github repo and with the help of claude containerized it. THIS IS NOT MEANT FOR PRODUCTION! Just for Lab Learning! Clone Luca’s repo on your podman host: git clone https://github.com/dellock6/pykmip-veea
1. Two Backup Methods, One Recovery Console Veeam provides two distinct methods for backing up Oracle databases. The first is image-level backup with application-aware processing, where VBR takes a VM-level or agent-level backup and handles Oracle archived redo logs as a guest processing subtask. The second is the Veeam Plug-in for Oracle RMAN, which integrates directly with Oracle's native Recovery Manager and sends backup data to a Veeam repository through the RMAN SBT (System Backup to Tape) interface.Both methods feed into the same recovery tool: Veeam Explorer for Oracle. Explorer can restore databases from either backup type through a single interface. The key difference is what each method captures and what recovery options each enables. Capability Image-Level Backup RMAN Plug-in Backup scope Entire VM or volume (includes OS, Oracle binaries, database) Database only (data files, control files, archived logs) Point-in-time restore
It was Christmas Eve. Most people were wrapping gifts, winding down, and logging off early. But for one of our clients a construction company with decades of project data, intellectual property, and live customer records, that night would become one of the most terrifying in the company's history. A double-encryption ransomware attack had just taken down every system. Completely dark. Several other construction companies across the region were affected by the same attack that night. What made this attack different wasn't just its timing. The attackers were sophisticated. They didn't just encrypt the production environment they deleted the on-site Veeam Backup & Replication server, wiped the local backup copies, and went after the cloud backup repository too. I was a deliberate, calculated attempt to leave no recovery path. They almost succeeded. When the Call Came InAs a managed service provider, we know that data emergencies don't respect holidays. The moment we received the aler
Recently a customer asked me: “Is it actually a problem if I add a branch office with ESXi hosts that are managed by a vCenter to Veeam as standalone hosts instead of adding the vCenter? What impact does that have?” The short answer: Yes, it can have noticeable impact — functionally, operationally, and also in terms of backup consistency when VMs are moving (with vMotion). Best practice in general is to add the vCenter as the management instance in Veeam, not the individual ESXi hosts. Okay, but why? What is vCenter — and why is it more than “just” a GUI? vCenter Server is the central management instance for VMware vSphere environments. It centrally manages objects such as clusters, hosts, VMs, folders, resource pools, tags, roles/permissions, HA/DRS, and many automation features. For backup solutions, vCenter is important because it provides a stable, always up-to-date inventory and object referencing ID (keyword: MoRef). Moe? Like that bartender from The Simpsons? Äh no — tha
1. This Is Not Troubleshooting Troubleshooting is what you do when a job fails and you want to fix it. Forensics is what you do when a job has been failing for three weeks and nobody noticed, a VM dropped out of protection and nobody caught it, or a ransomware event hit and you need to prove your last clean restore point. The question is not "how do I fix this job." The question is "what exactly happened, when did it start, what was affected, and can I prove it."Forensics requires a different mindset than break-fix. You are not looking for the current error. You are reconstructing a timeline. You need session history, task-level detail, bottleneck data, and alarm records across a window of days or weeks. VBR stores all of this. The trick is knowing where to look and how to correlate it. 2. Where the Logs Live VBR keeps two categories of evidence: the configuration database (PostgreSQL in v13, formerly SQL Server Express) and the file system logs. Database (Session and Task Records) Eve
When a full restore is the wrong move When SQL breaks, the first request is usually narrower than “restore the VM.” More often it is “get this database back to before the bad change” or “show me what was in last night’s backup.” That is the sort of job Veeam Explorer for Microsoft SQL Server handles well.It opens a SQL-aware view into a Veeam Backup & Replication restore point and lets you pick the recovery method that fits the problem in front of you: restore a database, recover to a specific time, roll back to just before a bad transaction, publish a database from backup, run instant recovery, or export schema and data without rebuilding an entire machine.If the backup captured SQL correctly, the workflow is familiar whether the source came from a VM backup, Veeam Agent for Windows, or the Veeam Plug-in for Microsoft SQL Server. You can launch the Explorer from the VBR console, from the Windows Start menu, or through PowerShell. Opening the tool is easy. The part that matters is
This is the first article in a multi-part series on From Reactive to Proactive: Running Veeam Like a Platform. In the next article, we'll look at the step-by-step process for completing this. Most Veeam environments don’t start out broken.They start out reactive.Something fails → you fix it.A job warns → you investigate it.Storage fills up → you scramble to add more.And for a while, that works.Until it doesn’t.Because as your environment grows, reactive operations turn into:Constant firefighting Unpredictable performance Unclear recovery expectationsAt some point, you realize:You’re not running a backup tool anymore.You’re running a data protection platform.And platforms need to be operated differently. What “Reactive” Actually Looks LikeMost teams don’t realize they’re reactive—it just feels normal.You check failures after they happen You deal with warnings when they pile up You only look at performance when it’s slow You test restores when someone asksNothing is technically “wrong.”B
Recently, I was involved in a production support case where a Veeam software appliance deployed on physical hardware failed to boot after an unexpected power interruption.The system dropped directly into:“You are in emergency mode. Cannot open access to console, the root account is locked.”At this point, many administrators assume the appliance is corrupted or that Veeam needs to be reinstalled. In this case, the backup administrator had already reinstalled VBR once, and the issue happened again. This is not a Veeam software issue. The problem occurs at the Linux storage layer, specifically with LVM and XFS.The Veeam appliance is built on LVM logical volumes formatted with XFS. During boot, Linux must detect storage, activate LVM volume groups, and mount all filesystems defined in /etc/fstab before any services start.If any of these steps fail, the system enters emergency mode to protect itself. This is a safety mechanism, not a catastrophic failure.Understanding this boot sequence ma
Veeam participated in HPE Tech Jam Orlando 2026 as a Silver Sponsor, reinforcing its strategic alliance with HPE and underscoring its joint commitment to advancing innovation in cyber resilience and data protection.The Veeam team delivered a special breakout session titled “Securing Your Hybrid Cloud with Veeam and HPE”. The session demonstrated how the Veeam Data Platform integrates seamlessly with HPE Private Cloud and storage solutions to protect hybrid environments, covering virtual, physical, and containerized workloads.Attendees of this session explored the expanding HPE and Veeam partnership, which included new support for HPE Morpheus VM Essentials Software and V13 enhancements across backup, recovery, and management.The session also emphasized advanced threat detection, secure recovery, and intelligence-driven insights, enabling organizations to respond to cyberattacks with greater confidence. In addition, the recent acquisition of Securiti AI accelerated the integration of
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.