Before You Begin

Before you configure network settings for VMs, make sure that your Azure environment meets the requirements listed in the following table. Some of the requirements, such as peering connections between VNets, change the network topology of your Azure subscription. Plan these changes in advance, as organization security policies may restrict them.

Before You Begin

Requirement

When Required

Purpose

Private DNS zones

Always

The privatelink.blob.core.windows.net and privatelink.queue.core.windows.net zones hold the DNS records of the private endpoints. Veeam Backup for Microsoft Azure components use these records to resolve the endpoint names to private IP addresses. You can create the zones manually or instruct Veeam Backup for Microsoft Azure to create and manage them automatically.

Worker configuration

Always

The worker configuration defines the Azure region and the VNet in which Veeam Backup for Microsoft Azure launches worker instances. Create the configuration in the same region where the protected VM resides and select a VNet for the worker instances.

Virtual network links in private DNS zones

Only if you create and manage the private DNS zones manually

A virtual network link allows the resources of a VNet to resolve the records stored in a private DNS zone. Link both DNS zones to the VNet of the backup appliance and to the VNet selected for the worker instances. For application-aware processing, also link the VNets of the protected Azure VMs.

Peering connections between VNets

  • Between the backup appliance VNet and the worker instance VNet — always
  • Between the backup appliance VNet and the protected VM VNet — only if you plan to enable application-aware processing or to perform file-level recovery to the original location
  • Between the backup appliance VNet and the repository private endpoint VNet — only if you plan to back up Azure VMs to a repository

Peering connections allow the backup appliance and the worker instances to resolve the private endpoints that reside in other VNets. Without peering connections, you must create a separate set of private endpoints and private DNS zones in each VNet. Veeam Backup for Microsoft Azure does not use the peering connections to transfer backup data — the components exchange control messages through Azure Queue Storage.

Private endpoints for Azure Blob Storage and Azure Queue Storage

Always

Veeam Backup for Microsoft Azure transfers backup data through the private endpoint for Azure Blob Storage and exchanges control messages through the private endpoint for Azure Queue Storage. The backup appliance has no direct connection to the worker instances, so Azure Queue Storage acts as a proxy that delivers worker readiness messages, job progress updates and VSS agent statuses. Veeam Backup for Microsoft Azure creates the endpoints automatically at the first run of a backup policy, but you must configure DNS settings for them manually.

Disk access resources

Only if you create and manage the private DNS zones manually

Disk access resources allow worker instances to export VM snapshots to a repository through a private connection. Veeam Backup for Microsoft Azure creates the resources automatically, but you must add their private endpoints to the privatelink.blob.core.windows.net DNS zone.

Considerations and Limitations

Before you start the deployment, review the following dependencies and limitations:

  • Veeam Backup for Microsoft Azure does not create peering connections between VNets automatically — you must create each connection manually in the Microsoft Azure portal.
  • Due to Microsoft Azure limitations, you must create the worker configuration in the same Azure subscription where the private DNS zones reside, if you plan to protect Azure VMs that have Ultra Disks or Premium SSD v2 disks attached and you create the private DNS zones manually.
  • To allow Veeam Backup for Microsoft Azure to update worker instances, the worker instances must have public access to the online Ubuntu repositories listed in section Ports.
  • To store backups of Azure VMs in repositories, you must also configure network settings for storage accounts as described in section Configuring Network Settings for Storage Accounts.

Page updated 2026-10-09

Page content applies to build 13.1.1.18