Before You Begin

Configure the network settings described in this section only if you want Veeam Backup for Microsoft Azure to access Azure storage accounts without public IPv4 addresses. By default, Veeam Backup for Microsoft Azure uses public access to communicate with storage accounts.

You can grant access to a storage account either through firewall rules or through private endpoints. The following table lists the requirements for both approaches. Some of the requirements, such as peering connections between VNets, change the network topology of your Azure subscription. Plan these changes in advance, as organization security policies may restrict them.

Before You Begin

Requirement

When Required

Purpose

Firewall rules on storage account

Only if you grant access through firewall rules

Firewall rules grant the selected VNets access to the storage account. To manage backup repositories and to back up Azure VMs, select the VNets of the backup appliance and the worker instances. To back up Azure file shares, select the VNet of the backup appliance.

Virtual network service endpoints

Only if you grant access through firewall rules

Microsoft Azure grants VNets access to storage accounts through virtual network service endpoints. Every VNet that you add to the firewall rules must have the service endpoint enabled for Microsoft.Storage.Global. If a VNet does not have it enabled, Microsoft Azure raises a warning when you add the VNet.

Private endpoints for storage account

Only if you grant access through private endpoints

A private endpoint connects the storage account to a VNet without a public IPv4 address. Create a separate endpoint for every VNet to which the backup appliance or worker instances are connected. Select blob as the target sub-resource to manage backup repositories and to back up Azure VMs, or file to back up Azure file shares.

Private DNS zone for private endpoints

Only if you grant access through private endpoints

The private DNS zone overrides the DNS resolution of the storage account name from the public endpoint to the private one. Microsoft Azure creates the zone when you integrate the private endpoint with a private DNS zone.

Peering connection between backup appliance VNet and private endpoint VNet

Only if you grant access through private endpoints

The peering connection allows the backup appliance to resolve and reach the private endpoint that resides in another VNet. Without the peering connection, you must create a separate private endpoint in the VNet of the backup appliance.

Considerations and Limitations

Before you start the deployment, review the following dependencies and limitations:

  • Create private endpoints instead of firewall rules if the backup appliance resides in a region other than the resources that you want to back up, or if you do not want to add firewall rules to the storage account.
  • Configure the firewall rules and private endpoints in the storage account where your repositories or protected resources reside. The storage accounts that Veeam Backup for Microsoft Azure creates automatically are configured as described in sections Configuring Network Settings for VMs and Configuring Network Settings for SQL Servers.
  • Veeam Backup for Microsoft Azure does not create peering connections between VNets automatically — you must create each connection manually in the Microsoft Azure portal.

Page updated 2026-10-09

Page content applies to build 13.1.1.18