Access Permissions for Direct Connection to Object Storage

If you back up data using a direct connection between the Veeam Agent computer and the object storage, access to the object storage will be managed by an API provided by this object storage. Depending on the selected object storage, access permissions are distributed differently. As a result, you must consider different limitations for the following types of object storage:

NOTE

Backup policies cannot back up data to the Microsoft Azure Blob storage with immutability enabled and Veeam Data Cloud Vault storage added in the direct connection mode.

 

Amazon S3

On the Amazon S3 storage side, Veeam Agent backup is performed with the following steps:

  1. Depending on the backup job mode and the way you added the object storage to your infrastructure, Veeam Backup & Replication performs a certain operation to grant access to the repository in the object storage.

 

 

  1. If applicable, Veeam Backup & Replication assigns a policy to each created user. This policy contains access permissions and allows Veeam Agent access only those backups that were made only by this Veeam Agent.

Keep in mind the following limitations and prerequisites:

Google Cloud Storage

On the Google storage side, Veeam Agent backup is performed with the following steps:

  1. Depending on the backup job mode and the way you added the object storage to your infrastructure, Veeam Backup & Replication performs a certain operation to grant access to the repository in the object storage.

 

 

  1. If applicable, Veeam Backup & Replication assigns a policy to each bucket. This policy contains access permissions and allows Veeam Agent access only those backups that were made only by this Veeam Agent.

Keep in mind the following limitations and prerequisites:

  • Consider that user accounts that you use to connect to the Google Cloud storage have the required permissions. To learn more, see Permissions.

Microsoft Azure Blob Storage

Access permissions are granted to Veeam Agents using shared access signatures (SAS).

Veeam Data Cloud Vault

Necessary access permissions are granted by default and cannot be modified.

IBM Cloud, Wasabi Cloud or Other S3 Compatible Storage

Keep in mind the following limitations and prerequisites:

To learn more, see Managing Permissions for S3 Compatible Object Storage.

  • User accounts that you use to connect to the S3 compatible storage have the required permissions. To learn more, see Permissions.

Page updated 9/3/2025

Page content applies to build 13.0.0.4967