How Decryption Works
When you access backed-up data stored in an object storage repository with the encryption option enabled, Veeam Backup for Microsoft 365 automatically decrypts your data in the background. Decryption is performed by Veeam Backup for Microsoft 365 Proxy Service.
The decryption process includes the following steps:
- Veeam Backup for Microsoft 365 reads the data key cryptogram next to the encrypted data blobs that you access.
- Using the backup key ID stored in the data key, Veeam Backup for Microsoft 365 obtains the backup key.
- Veeam Backup for Microsoft 365 applies the secret key to decrypt the backup key. If needed, Veeam Backup for Microsoft 365 decrypts a chain of backup keys. For more information, see Encryption Password Change.
- The backup key unlocks underlying data keys.
- Data keys decrypt data blobs.