New-VBREncryptionOptions

Short Description

Defines encryption settings.

Product Edition: Standard, Enterprise, Enterprise Plus, Veeam Universal License

Syntax

This cmdlet provides the following parameter sets:

  • Disabled (Default)

    New-VBREncryptionOptions [-EnableEncryption] [<CommonParameters>]

  • PasswordDecryption

    New-VBREncryptionOptions [-EnableEncryption] -EncryptionKey <VBREncryptionKey> [<CommonParameters>]

  • KmsDecryption

    New-VBREncryptionOptions [-EnableEncryption] -KMSServer <VBRKMSServer> -KMSSourceName <String> [<CommonParameters>]

Detailed Description

This cmdlet creates the VBREncryptionOptions object that defines encryption options.

Parameters

Parameters

Parameter

Description

Type

Required

Position

Accept Pipeline Input

EnableEncryption

Enables encryption.

Default: False.

SwitchParameter

False

Named

True (ByPropertyName, ByValue)

EncryptionKey

Specifies an encryption key. Veeam Backup & Replication will use this key to encrypt backup files.

Accepts the VBREncryptionKey object. To get this object, run the Get-VBREncryptionKeyReturns encryption keys. cmdlet.

VBREncryptionKey

True

Named

True (ByPropertyName, ByValue)

KMSServer

Specifies the KMS server you want to use to encrypt the data.

Accepts the VBRKMSServer object. To get this object, run the Get-VBRKMSServerReturns KMS servers added to the Veeam Backup & Replication console. cmdlet.

VBRKMSServer

True

Named

True (ByPropertyName, ByValue)

KMSSourceName

Specifies the displayed name for the key. The cmdlet will create a key and include this name into the key name on the KMS server.

String

True

Named

True (ByPropertyName, ByValue)

<CommonParameters>

This cmdlet supports Microsoft PowerShell common parameters. For more information on common parameters, see Microsoft Docs.

Output Object

The cmdlet returns the VBREncryptionOptions object that defines encryption options.

Examples

New-VBREncryptionOptionsExample 1. Creating Encryption Options with Encryption Key

This example shows how to define encryption options with the encryption using an encryption key.

$encKey = Get-VBREncryptionKey -Description "For Entra ID encryption"

$encOptions = New-VBREncryptionOptions -EnableEncryption -EncryptionKey $encKey

Perform the following steps:

  1. Run the Get-VBREncryptionKeyReturns encryption keys. cmdlet. Specify the Description parameter value. Save the result to the $encKey variable.
  2. Run the New-VBREncryptionOptions cmdlet. Provide the EnableEncryption parameter. Set the $encKey variable as the EncryptionKey parameter value. Save the result to the $encOptions variable.

New-VBREncryptionOptionsExample 2. Creating Encryption Options with KMS

This example shows how to define encryption options with the encryption using a KMS server.

$kmsServer = Get-VBRKMSServer -Name "thales.tech.local"

$encOptions = New-VBREncryptionOptions -EnableEncryption -KMSSourceName "EntraIDKey" -KMSServer $kmsServer

Perform the following steps:

  1. Run the Get-VBRKMSServerReturns KMS servers added to the Veeam Backup & Replication console. cmdlet. Specify the Name parameter value. Save the result to the $kmsServer variable.
  2. Run the New-VBREncryptionOptions cmdlet. Specify the following settings:
    • Provide the EnableEncryption parameter.
    • Specify the KMSSourceName parameter.
    • Set the $kmsServer variable as the KMSServer parameter value.
    • Save the result to the $encOptions variable.

Page updated 2026-08-20

Page content applies to build 13.1.1.18