New-VBRDecryptionSet

Short Description

Defines data decryption settings.

Product Edition: Standard, Enterprise, Enterprise Plus, Veeam Universal License

Syntax

This cmdlet provides the following parameter sets:

  • PasswordDecryption (Default)

    New-VBRDecryptionSet -EncryptionKey <PSCryptoKey> -Password <String> [<CommonParameters>]

  • KmsDecryption

    New-VBRDecryptionSet -EncryptionKey <PSCryptoKey> [-KmsKeyId <String>] -KMSServer <VBRKMSServer> [<CommonParameters>]

Detailed Description

This cmdlet creates the VBRDecryptionSet object. This object defines the data decryption settings.

Parameters

Parameters

Parameter

Description

Type

Required

Position

Accept Pipeline Input

EncryptionKey

Specifies encryption keys managed by Veeam Backup & Replication.

Accepts the PSCryptoKey object. To get this object, run the Get-VBREncryptionKeyReturns encryption keys. cmdlet.

PSCryptoKey

True

Named

True (ByPropertyName, ByValue)

KmsKeyId

Specifies the ID of the private key stored on the KMS server. The cmdlet will use it to decrypt data.

String

False

Named

True (ByPropertyName, ByValue)

KMSServer

Specifies KMS servers added to the Veeam Backup & Replication console. The cmdlet will decrypt data encrypted by this server.

Accepts the VBRKMSServer object. To create this object, run the Get-VBRKMSServerReturns KMS servers added to the Veeam Backup & Replication console. cmdlet.

VBRKMSServer

True

Named

True (ByPropertyName, ByValue)

Password

Specifies a password. The cmdlet will use the password to decrypt data.

String

True

Named

True (ByPropertyName, ByValue)

<CommonParameters>

This cmdlet supports Microsoft PowerShell common parameters. For more information on common parameters, see Microsoft Docs.

Output Object

VBRDecryptionSet

Examples

New-VBRDecryptionSetExample 1. Defining Decryption Settings for Data Encrypted by KMS

This example shows how to define settings to decrypt data encrypted by KMS server.

$key = Get-VBREncryptionKey -Description "Veeam KMS"

$kmsserver = Get-VBRKMSServer -Name "thales.tech.local"

$decryption = New-VBRDecryptionSet -EncryptionKey $key -KMSServer $kmsserver -KmsKeyId "c302ebfd-821c-4372-bf46-beccca0516ec-pub"

Perform the following steps:

  1. Run the Get-VBREncryptionKeyReturns encryption keys. cmdlet. Specify the Description parameter value. Save the result to the $key variable.
  2. Run the Get-VBRKMSServerReturns KMS servers added to the Veeam Backup & Replication console. cmdlet. Specify the Name parameter value. Save the result to the $kmsserver variable.
  3. Run the New-VBRDecryptionSet cmdlet. Set the $key variable as the EncryptionKey parameter value. Set the $kmsserver variable as the KMSServer parameter value. Specify the KmsKeyId parameter value. Save the result to the $decryption variable to be used with other cmdlets.

New-VBRDecryptionSetExample 2. Defining Data Decryption Settings with Password

This example shows how to define settings to decrypt data using password.

$key = Get-VBREncryptionKey -Description "Veeam KMS"

$decryption = New-VBRDecryptionSet -EncryptionKey $key -Password "VeeamPassword"

Perform the following steps:

  1. Run the Get-VBREncryptionKeyReturns encryption keys. cmdlet. Specify the Description parameter value. Save the result to the $key variable.
  2. Run the New-VBRDecryptionSet cmdlet. Set the $key variable as the EncryptionKey parameter value. Specify the Password parameter value. Save the result to the $decryption variable to be used with other cmdlets.

Page updated 2026-08-19

Page content applies to build 13.1.1.18