Creating Protection Groups

You must add computers that you plan to protect with Veeam Agents to the inventory in the Veeam Backup & Replication console. In Veeam Backup & Replication, protected computers are organized into protection groups. You can create one or more protection groups that contain computers of different types or offer different discovery and deployment options.

NOTE

Before you create a protection group, consider the following:

  • We recommend that you include each computer in one protection group only. For example, if you have added an Active Directory container to a protection group, it is not recommended to add a computer that exists in this container to another protection group. Adding computers to multiple protection groups with different computer discovery and Veeam Agent deployment settings will result in additional load on the backup server.

You cannot add a computer from a protection group for pre-installed Veeam Agents to any other protection group.

  • Each time you add a Veeam Agent computer to the protection group, Veeam Backup & Replication considers this Veeam Agent computer as a new object. For example, if you add a Veeam Agent computer to the protection group, then remove this Veeam Agent computer from the protection group and add to the same protection group again, Veeam Backup & Replication will consider this Veeam Agent computer as two different objects. As a result, Veeam Agent will start a new backup chain each time you add the Veeam Agent computer to the protection group.
  • In the Veeam Backup & Replication web UI, you can create and edit protection groups of the Individual computers and Microsoft Active Directory objects types only. Other protection group types are read-only in the web UI. For details, see Veeam Agent Web UI Features.

You can create protection groups of the following types:

IMPORTANT

The current section does not cover subjects related to protection groups that include applications. To learn about this protection group type, see MongoDB Backup.

For a full description of each type and support by operating system, see Protection Group Types.

Deploying Pre-Installed Backup Agents

A protection group for pre-installed can include any number of computers that use a certain temporary certificate to connect to the Veeam backup server. A temporary certificate is a unique identification number generated for each protection group that is available among other connection settings in a configuration file. You will obtain the configuration file along with Veeam Agent setup files after the protection group is created. Using these setup files, you must deploy Veeam Agent and apply connection settings from the configuration file on the Veeam Agent computer. After that, Veeam Agent connects to the Veeam backup server, and Veeam Backup & Replication includes the Veeam Agent computer in the protection group.

IMPORTANT

Make sure that the setup and configuration files are stored in a secure location. If a third party gains access to these files, they can use any host to connect to the protection group, obtain the configuration options, create backups and perform other actions.

To learn more about Veeam Agents deployment, see Deploy Veeam Agents.

Page updated 2026-09-02

Page content applies to build 13.1.1.18