News, guidelines and various community projects
Recently active
The ultimate test of cyber resilience: recovering when all you have left are your backup files Most organizations spend significant time and effort protecting their backup data.They implement:Immutable repositories Air-gapped storage Tape archives Object storage with Object Lock The 3-2-1-1-0 or 3-2-1-2-0 ruleAs a result, they feel confident that their data is safe.But let me ask a different question:What if your Veeam Backup & Replication server no longer exists?What if ransomware, a hardware failure, human error, or even a disaster destroys:The Veeam Backup Server The configuration database Enterprise Manager Credentials Documentation Recovery runbooksAnd all that remains are your protected backup copies?Could you still recover your business?If you cannot confidently answer "yes", then you may have discovered the biggest gap in your disaster recovery strategy.Backup Data vs. Recovery CapabilityMany organizations focus on protecting backup files.That is important.However, cyber r
In today’s threat landscape, backup and management platforms have become prime targets for cyberattacks, particularly in multi-tenant service provider environments. Ensuring the security and integrity of these systems is no longer optional—it is a critical operational requirement.Recently, a critical vulnerability (CVE-2026-32998) with a CVSS v3.1 score of 9.4 has been identified in Veeam Service Provider Console (VSPC) version 9 builds. This vulnerability can potentially allow remote code execution (RCE) through specific features such as alarm script execution, exposing service providers to severe risks including unauthorized access, system compromise, and lateral movement across managed infrastructures. [community.veeam.com]All versions prior to VSPC 9.2.1.33875, including 9.0.0.29860, are affected, making it imperative for organizations to take immediate action. [community.veeam.com]This guide is designed to provide a clear and practical walkthrough on how to safely upgrade Veeam Se
When IT professionals discuss availability, business continuity, and data protection, the conversation usually focuses on backup software, immutable storage, disaster recovery plans, and cybersecurity.Those technologies are critical.However, some of the most dangerous Data Center Risks have nothing to do with software, storage arrays, or backup systems.Sometimes, the real threat is much closer than we think.Recently, I was called onsite to investigate an issue involving a tape library. One of the drives had grabbed a tape cartridge and failed to release it properly. The task seemed simple: remove the tape, validate the drive, and confirm everything was operating normally.A routine service call.At least, that's what I thought.What I discovered that day had very little to do with backup infrastructure and everything to do with governance, operational discipline, and the hidden risks that can quietly develop inside critical environments.The First Sign Something Was WrongAs soon as I enter
This week, @Madi.Cristil is out on some well-deserved time off. Once again I have no supervision so I broke the rule of 3 featured content - such a rule-breaker! I went solo this time and you can watch the episode here: Featured Contentvia @Madi.Cristil via @Dynamic via @kciolek via @Michael Melter EmpowHER VMCEWe have an extra-special announcement from @Federica - the EmpowHER VMCE+ Acceleration program is taking nominations, please give this a look for both experienced practitioners and early-stage career individuals! EmpowHer VMCE+ Accelerator | Women in Tech Program - But hurry, registration is open only for a limited time! The accelerator focuses on the first of four courses in the VMCE+ training bundle—Veeam Backup & Replication—equipping participants with the skills to install, configure, and manage the Veeam Data Platform. Upon completion, participants earn a badge, build confidence, and gain access to the remaining courses to continue their path toward the VMCE+ cer
Hi community! I’m working on an architecture to implement VRO with a Clean Room. I ll be in this kind of topology : I notice in the prerequisites, this point : “The current release of Veeam Recovery Orchestrator (v 13.0.1) requires at minimum an initial connection to the production vCenter to gather inventory and create restore plans using vSphere tags.Connection to the production VBR is optional and only required to create restore plans based on backup jobs.”The principle of a clean room is to have an environment that is completely decoupled from production, acting as a safe place to store and test backups, and as a trusted source for a clean recovery of workloads, even if the production environments are infected or compromised.Opening network flows to production, even temporarily, seems to go against that principle in my opinion, even if those flows are limited. In my architecture, I have a production vCenter and most likely a dedicated vCenter for the clean room, since standalone E
Hello Community, I'm experiencing an issue when trying to use VM Intelligence in Veeam version 13.0.2.29, both when deployed as a VSA Appliance and when installed on Windows.When accessing the feature, I receive the following error message:"Cannot verify the product license." both Backup servers are connect to the internet. What I find strange is that I am using a valid NFR Premium license with more than 300 days remaining before expiration.I have already verified that the license is correctly installed, and the issue occurs on both deployment types, which makes me think it could be related to a VM Intelligence licensing requirement, online license validation, or possibly a bug in version 13.0.2.29.Has anyone experienced this issue before or knows of any troubleshooting steps or solutions?Any help would be greatly appreciated. Thank you!
I was wondering if someone could help with an issue I’m having in Veeam agent for windows, I get the following error when trying to restore files from a volume backup stored on a network share. I’m using the agent in free mode.Backup sync failed[computer_name] Failed to connect to installer service[computer_name] Failed to connect to installer service[computer_name] Failed to discover installer serviceA security package specific error occurredConnect failed (RpcBindingSetAuthInfoExW)Please can you help me resolve this?
Recently, a customer asked me:“Hey — is it possible that VMware tag backup isn’t working?”The reason: After a Full VM Restore (Restore to original location), the VM’s VMware tags were suddenly gone. In the restore log it basically said:“These tags were not present at the time of backup — so I’m removing them.” And that’s despite the fact that the tags were definitely set in production (otherwise the customer wouldn’t have been able to pick up the VM in their jobs using tag-based selection in the first place). A test with another VM showed the same behavior. At that point it was clear: this wasn’t a one-off. So how does Veeam get the idea that a VM has “no tags” — even though it does? What is a VMware Tag (and why is it relevant for backups)? VMware tags are metadata in vCenter that can be assigned to objects (for example, VMs). Typical use cases include:Organizational mapping (customer, environment, cost center) Technical classification (OS, SLA, app) Automation (backup scopes, policie
NetApp ONTAP S3 with Immutability (ONTAP 9.14 and higher) is currently not (or no longer) supported by Veeam. This means that Veeam backups on a NetApp ONTAP S3 bucket with activated Object Lock (Immutability) are currently not considered “immutable” in the sense of Veeam functionality. The main reason is that ONTAP S3 with activated Object Lock no longer fulfills all the requirements that Veeam needs for immutability. Veeam currently only lists ONTAP S3 as “not immutable” in its own compatibility directory. The use of Immutability is therefore not officially approved NetApp is working on a solution with the support of Veeam (you may be able to get information via the NetApp Partner Manager). --> This is ONTAP S3 (on ONTAP machines (FAS/AFF), not a NetApp Storage GRID)! Links to this:NetApp ONTAP S3 with immutability - R&D ForumsNetApp ONTAP S3
Hello Veeam Community!Since Madalina is away this week, I have the pleasure to announce the Blog of the Month winner for the month of May. With 11 votes, the winner is @PeteSteven! Congrats on the win, Peter! 🎉🎉 Read his winning blog, Swap-VeeamSOBRUser below! If anyone is interested in reading the other nominations from May, find them here!: We’ll be back in a few weeks with the Blog of the Month poll for June! 😊
Yesterday, I published an article on #CloudCity about my FinOps journey.Check here: FinOps in Practice: Optimizing Cloud Value with AWS, CloudCheckr, and VeeamI'd like to highlight some key initiatives that helped my team strengthen data protection while improving cost control and reducing expenses associated with backup infrastructure assets. Resilience, Backup & High Availability - by CLOUDCHECKRCloudCheckr identifies risks related to data protection and business continuity, ensuring workloads are prepared for failures, accidental deletions, and downtime.Examples of recommendations:• EBS volumes without snapshots (direct data loss risk)• EBS volumes without recent snapshots (outdated backup)• EC2 instances without termination protection enabled• Environments without multi-AZ deployment• Lack of automated backup and retention strategy• Critical resources without defined recovery (DR) policies• Low maturity in business continuity (BCP)• Workloads not prepared for availability zone
I recently worked on another project with a major customer where we unfortunately reached the limits of Veeam Backup & Replication’s out-of-the-box features for Scale-Out-Repositories and had to find a workaround. Our ChallengeOur challenge: The customer has over 100 scale-out repositories, each with different permissions depending on the application and operating system. We had to migrate the VBR server to a new Windows Server. However, this also meant that the users created locally on the old server were no longer available. In principle, this wasn’t a problem—we simply recreated the same users on the new server.However, this is where the problem comes in. The SOBR permissions include the old user as “OLDSERVERNAME\USERNAME,” which we then have to replace with “NEWSERVERNAME\USERNAME.” If we didn’t replace these, our Enterprise Plugins would no longer have permissions to write their backups.Unfortunately, there is no function to change permission settings across multiple reposito
Hello community, I have a new Vanguard Newsletter full of veeamazing content created by Veeam Vanguards last month to share with you! 🤓 The May edition focuses on hands-on Veeam operations and platform maintenance, including troubleshooting and hardening core backup components (such as tape/LTO diagnostics, repository/SOBR administration and infra naming changes from IP to DNS), as well as a strong emphasis on version management and security patching across Veeam Backup & Replication and Veeam ONE, in order to address vulnerabilities and implement updates. The newsletter also highlights topics related to cloud/object storage and repository architecture (notably Azure Blob integration, S3 repository abstraction and repository decision frameworks), as well as v13-era capabilities such as Veeam High Availability Cluster and environment visualisation via Interactive Maps. It also covers security and identity best practices, including the Security Officer role and gMSA for guest proce
Some days your job is just plain fun! No ifs or buts!This morning I had the immense pleasure to talk with 3 pillars of the Veeam Community, Senior Community Manager Nikola Pejkova @NikolaPejkova , Mr. Community himself Rick Vanover @Rick Vanover and of course Vanguard/Legend/Object First Ace, author of Mastering Veeam Backup & Replication Chris Childerhose @Chris.Childerhose !This is a conversation that could have lasted all morning, never a dull moment.Also courtesy of a fresh of the press Rickatron quote a potentially fantastic new title for a DR horror movie! I can see it now: coming soon to a theater near you: “Agents gone wild”! Tune in to find out what it is like to write a book and the fun these three folks had collaborating together on this new edition! https://www.buzzsprout.com/2545760/episodes/19293879 The Book is out, don’t you miss out!
I finally had some time to wire in the Veeam Ports MCP server into GPT. It works but has a number of steps in the process. If you are like me you watch the token burn in Claude for projects like these. This started with EdxH’s post on the Veeam Ports MCP server introducing the project & GitHub repo.The repo is @ https://github.com/shapedthought/veeam-ports-mcp. I wanted to see what it took to make that same idea work /w GPT.Claude Desktop can launch a local MCP server /w STDIO. The Veeam Ports MCP repo already shows that path well. GPT expects an MCP endpoint instead. On my end that meant I had to put a bridge and a tunnel in the middle before GPT could make use of the tool correctly.Once that was running, I could describe a VBR v13 layout in plain language and get back firewall rules, topology output, and a Magic Ports import file (yea).The painful part was useful as well. I learned that a topology JSON and a Magic Ports import JSON are not the same thing. They look close enough
Throughout this tape series, I explored installation, troubleshooting, tape cleaning procedures, advanced diagnostics, and real-world operational scenarios involving Veeam tape environments.But there is another side of tape infrastructure that usually only receives attention when something starts going wrong: tape library administration.And many times, the problem is not directly related to the backup job itself.Issues often appear around: media movement firmware inconsistencies robotics communication tape-out operations media rotation hardware lifecycle operational mistakes In enterprise environments, tape infrastructure eventually becomes much more than just a backup target.It becomes an operational platform that requires maintenance, organization, validation, and process consistency. Understanding Control Path and Data PathOne of the first important concepts in enterprise tape environments is understanding the difference between control path and data path.The control pat
TL;DROn May 14, 2026, the PostgreSQL Global Development Group released security updates for all supported branches (18.4, 17.10, 16.14, 15.18, 14.23), fixing 11 CVEs, several rated CVSS 8.8. If you run VBR on Windows with PostgreSQL as your configuration database, you are affected. Veeam does not auto-update PostgreSQL. You have to do it yourself! Here is what you need to know and what to do about it. Why this matters for VBRSince VBR v12, PostgreSQL has been the default (and recommended) configuration database. VBR v13 GA ships with PostgreSQL 17.6, and the latest cumulative update (13.0.1.2067) bumps it to 17.9.1. Both versions are below the patched 17.10 and therefore vulnerable to all 11 CVEs disclosed on May 14 (PostgreSQL release announcement).If you are still on VBR v12.x, your PostgreSQL 15.x is equally affected and needs to be updated to at least 15.18 (PostgreSQL release announcement).The key takeaway: Veeam does not update the PostgreSQL instance between VBR cumulative updat
What is this type of issue ? Anyone, please explain.
We’re evaluating replacing out Windows VBR-servers with VSA, and I have set up a pilot machine. We need AD authentication to work for this, and I have joined the VSA to our domain.The main issue we have is that authentication is extremely slow and even if I can get “connected” pretty quick when I log in from the VBR-console, it can then take several minutes just to get past the splash screen. Even once logged in, I can get kicked out with some authentication error and “too many retries”. Also adding the AD-group to the “Veeam Administrator” role took forever and several retries. My strong suspicion is that SSSD used for this, is doing forest-wide queries, and since we are a huge company with many domains and trusts this is what takes time and causes timeouts. We’ve worked around this in other self-managed linux systems by using ldap as provider instead of “ad”, and limiting scope with ldap_serarch_base and filters, but not sure this is an option here, and pretty sure it wouldn’t be sup
In my latest blog article part 2 of Integration Veeam with CrowStrike, I'll walk through the steps of a recent implementation & integration of CrowdStrike with Veeam backup servers. Cyberattacks continue to target backup infrastructure because attackers know backups are often the last line of defense. Traditional antivirus solutions are no longer enough to protect modern backup environments, especially when ransomware actors specifically target backup repositories, backup servers, and privileged accounts.That’s where integrating CrowdStrike with Veeam Software can significantly improve your security posture.By combining Veeam’s ransomware detection and secure recovery capabilities with CrowdStrike Falcon’s endpoint protection and threat intelligence, organizations can better detect, contain, and recover from cyber incidents.In this lab guide, I’ll walk through the steps to implement and configure CrowdStrike integration with Veeam and explain how the two platforms complement each
Hello Veeam Community,With all the great conversations and content shared this month, I almost forgot — it’s time to vote for the Blog of the Month! Here are the top 6 picks ( and honestly, it was not an easy choice, you guys getting better and better 😻) ! Community, help us choose this month’s winner and award the badge!@PeteSteven , @Michael Melter , @Stabz , @matheusgiovanini , @Mohamed Ali , @Nico Losschaert Best of luck! Madi
Hi all,I had a customer who needed a way to obtain Veeam Software Appliance (VAS) updates within a closed OT/dark site/closed environment.However, the challenge was that they lacked Linux experience and would prefer to do everything in native Windows, without using WSL (Windows Subsystem for Linux). If you have no idea what I am talking about, read this section of the Veeam help center: https://helpcenter.veeam.com/docs/vbr/userguide/update_appliance_configure_updates.html?ver=13#setting-up-custom-update-configurationSo my idea was to build/configure two components:1) A PowerShell script that can be run in Windows to download the necessary files from repository.veeam.com to a computer with internet access and then zip the files into a single large Zip file. 2) Create an IIS server website with all update files needed for the VSA. Then we can easily hand-carry the Zip files from the internet-connected Windows computer to the IIS server in the OT/dark site/closed environment with you pre
Instantly bucket size is increasing. What could be the issue? What is the best practice to follow here? My concern is GCP storage.
Dear Community, What could be the possible issue?
Every now and then you get customer requests that initially knock you off your feet — because you can tell right away: this isn’t described anywhere in the documentation. Then it’s time to truly understand the problem, clarify the requirements properly (does the problem even exist in that form, or can it be solved differently?), research internally, potentially review a feature request including the use case — and finally think about how to help the customer pragmatically in the short term: the good old “workaround” or “self-fix.”That was the case here as well. A customer is using the standalone Veeam Plug-in for Oracle RMAN and wants to install the Veeam plug-in — however, in the customer’s environment it is intentionally used as unmanaged. At the same time, the rollout should be automated, and no one should have to type or “expose” a password.Die Veeam documentation refers to the option of copying the “configuration file” to other servers; however, you then have to reset the passwor
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.