Agent-Based Protection

With this release, Veeam expands capabilities for scalable agent deployment, stronger security, improved data protection, and more flexible recovery options. You will find updates that simplify large-scale management, enhance ransomware resilience, improve backup reliability on modern endpoints, and extend platform support, along with new features that enable centralized control and consistent backup operations across diverse environments.

Agent Management

Direct Agent Backups to Veeam Data Cloud Vault and Microsoft Azure Blob Storage — Unmanaged Veeam Agents and managed by agent jobs can back up directly to Veeam Data Cloud Vault and Microsoft Azure Blob Storage. This capability provides ransomware-resilient, always-immutable storage for direct-to-object agent backups, enabling organizations to achieve the same level of data protection already available across the rest of the platform.

Access to historical backups — Previously, backups created by agent-managed machines were associated with the original device, making historical restore points inaccessible to end users after a machine was replaced, decommissioned, or reassigned. With Veeam Backup & Replication 13.1, administrators can grant managed agents access to historical backups, preserving self-service file-level recovery capabilities. As a result, users can recover data directly from the agent UI using backups created by previously used machines, without relying on the original device. For large-scale hardware refresh and migration projects, backup administrators can automate backup-to-device matching using PowerShell and the REST API.

Increased retention for agent backups — Agent-managed backup jobs were limited by a maximum retention value enforced in the UI. With this release, this limitation has been removed, allowing administrators to define retention periods without predefined limits. This enables organizations to meet compliance and data governance requirements while ensuring long-term data availability without workarounds.

Certificate-based authentication for Microsoft Active Directory protection groups — With this release, protection groups support certificate-based authentication, eliminating the need to store and manage privileged credentials. This capability improves security by reducing credential exposure and simplifies operations by removing the need for credential rotation and management.

Cluster Disk Transfer Optimization for Backup Copy Jobs — Although cluster shared disks are stored only once in backups, backup copy jobs previously performed consistency processing for each cluster node referencing the disk, generating additional transfer overhead. Backup copy jobs now recognize shared disks across cluster nodes and process them only once per job run, reducing redundant data transfer, improving efficiency, and accelerating copy operations for cluster-based environments.

Pre-built deployment script for pre-installed Windows Agents — A ready-to-use deployment script is included for Windows agents directly to a package export location. This capability simplifies large-scale agent deployment, reduces operational overhead, and ensures a consistent deployment approach across environments.

Independent Deployment Kits — Creating a new deployment kit no longer invalidates or deprecates existing deployment kits, enabling administrators to maintain separate deployment configurations for different environments, use cases, or rollout scenarios. This enhancement simplifies agent deployment management and provides greater flexibility when supporting multiple deployment strategies simultaneously.

Web UI support — Agent Management capabilities are expanded in the Web UI, including support for protection groups (both individual machines and Active Directory–based), Windows and Linux agent backup job management, and common recovery operations to simplify management of agent-based workloads, enabling administrators to configure, monitor, and recover systems directly from a single, browser-based interface.

Veeam Agent for Windows

Remote Bare Metal Recovery — Administrators can now initiate and manage Bare Metal Recovery (BMR) sessions for Windows machines directly from the Web UI. Recovery operations can be performed using pre-configured Recovery Media or a recovery partition available on the target machine. End users simply boot the affected machine into the pre-configured recovery environment, allowing administrators to perform the remainder of the recovery process remotely through the Web UI. Available in Advanced Edition and above, this capability reduces downtime, minimizes the need for hands-on IT intervention, and streamlines disaster recovery operations.

Virtual recovery partition — Backup server can create and store a recovery environment directly on the target machine to enable Remote Bare Metal Recovery without relying on PXE, providing greater deployment flexibility and ensuring recovery readiness across diverse environments.

Agent UI Branding and Customization — With this release, administrators can customize the branding of backup agents, including company logos, accent colors, and Support and Help Center links. This capability enables consistent, branded deployments that align with corporate identity standards across the organization. Available in Advanced Edition and above, these customization options can also be used by service providers to deliver white-labeled experiences tailored to their customers, helping create a more seamless and recognizable user experience.

Automated Bandwidth Throttling — Veeam Agent for Microsoft Windows running on workstation operating systems can now automatically adjust backup traffic based on current network conditions, eliminating the need for manually configured throttling rules. By dynamically adapting bandwidth consumption, backups can continue running transparently in the background while minimizing the impact on user activity and business applications. This capability helps maintain end-user productivity while ensuring backup operations complete efficiently, even on bandwidth-constrained connections.

Modern Standby handling — Previously, on devices using Modern Standby (S0 low-power idle), backup jobs could fail or be skipped because the operating system throttles background services and ignores wake timers, preventing agents from executing scheduled operations reliably. With this release, Veeam Agent for Windows detects Modern Standby mode and handles it explicitly by adapting backup behavior, including preventing unreliable job starts and avoiding interruptions when the system transitions into low-power states.

Job retry after system restart — Veeam Agent for Windows backup jobs interrupted by a system restart are now automatically retried, helping prevent missed backup points in environments with scheduled maintenance reboots.

Veeam Agent for Microsoft Windows on Microsoft Store — Veeam Agent for Microsoft Windows is now available through the Microsoft Store, providing a simplified and familiar installation experience for Windows users. By leveraging Microsoft Store distribution, organizations and individual users can more easily discover, deploy, and update the agent through trusted Windows software delivery mechanisms. This helps streamline agent deployment and maintenance while reducing the operational overhead associated with manual software distribution.

Veeam Agent for Linux

Centralized management for nosnap Veeam Agent for Linux — Introducing centralized deployment and management for the nosnap version of Veeam Agent for Linux, which leverages native snapshot capabilities of supported Linux file systems (LVM & Btrfs) and does not depend on Veeam’s blksnap kernel module. Previously, this agent variant had to be manually installed on each machine. With v13.1, the nosnap Linux agent can now be deployed and managed centrally in the same way as the standard Linux agent. This functionality is available for x86_64 Linux systems.

Backup window support — Adding backup window enforcement for Veeam Agent for Linux when jobs are managed via Veeam Backup & Replication. Administrators can now define allowed and prohibited time intervals for agent backup jobs, preventing overlap with production hours and ensuring backup traffic does not impact business-critical operations.

Restore cross Backup & Replication Server management via CLI — V13.1 allows adding additional backup servers for Linux agents using CLI commands, enabling continued managed mode operation without resetting the agent state and avoiding backup chain disruption. The additional backup server is connected read-only and general backup processing can continue to run with the original configured backup server.

Active full backup scheduling enhancements — Active full backup scheduling in standalone mode now includes a monthly day-of-week option, consistent with synthetic full backup settings. You can configure active full backups to run on a specific day of the week on selected months or use the existing day-of-month schedule, providing greater flexibility for aligning backup schedules with operational calendars.

Linux distribution support — Added support for x86_64 distributions of Ubuntu 26.04 LTS; RHEL 9.8 and 10.2; Rocky Linux 9.8 and 10.2; AlmaLinux 9.8 and 10.2 and IBM Power distributions of RHEL 9.8 and 10.2. Support for the x86_64 distribution of RHEL 7.9 ELS has been added to restore compatibility with legacy RHEL environments.

Linux kernel support — Support was added for Linux kernel version 7.0.

Updated Veeam Recovery Media — V13.1 upgrades Veeam Recovery Media for Veeam Agent for Linux to Debian 13, ensuring alignment with the latest stable release and delivering broader hardware compatibility for reliable bare metal recovery operations.

Recovery Media patching on IBM Power (ppc64le) — Patching Recovery Media on the ppc64le architecture was added, enabling users to generate customized recovery ISO images that include the required drivers for IBM Power Systems.

Veeam Agents for Mac

Backup window support — Adding backup window enforcement for Veeam Agent for Mac when jobs are managed via Veeam Backup & Replication. Administrators can now define allowed and prohibited time intervals for agent backup jobs, preventing overlap with production hours and ensuring backup traffic does not impact business-critical operations.

Restore cross Backup & Replication Server management via CLI — V13.1 allows adding additional backup servers for Mac agents using CLI commands, enabling continued managed mode operation without resetting the agent state and avoiding backup chain disruption. The additional backup server is connected as read-only, and general backup processing can continue to run with the original configured backup server.

Network usage control — V13.1 adds network usage settings for Veeam Agent for Mac, allowing administrators to throttle backup job bandwidth and limit network consumption when creating protection groups with pre-installed agents.

Veeam Agents for Unix (AIX & Oracle Solaris)

Malware Detection for AIX and Solaris backups — With this release, malware detection capabilities such as including guest file analytics, Threat Hunter, YARA scans, and Veeam Incident API integration are fully supported for backups created with Veeam Agent for Unix (AIX and Solaris).

Certificate based authentication, Single-use credentials and Deployment Kit support for IBM AIX agents — V13.1 expands deployment and security options for Veeam Agent for IBM AIX in two key areas. First, single-use credentials are now supported when adding IBM AIX machines to individual protection groups, allowing SSH credentials to be used once for initial agent deployment only. As part of this, certificate-based authentication is now supported for IBM AIX agents, enabling more secure, passwordless communication between the agent and Veeam Backup & Replication after the initial deployment. Second, IBM AIX packages are now included in the Veeam Deployment Kit, enabling pre-installation of Veeam Deployer Service with a temporary certificate and bringing IBM AIX in line with the automated deployment capabilities already available for other platforms.

Managed by Server backup job mode for UNIX agents — Introducing support for the Managed by backup server job mode, allowing backup jobs for IBM AIX and Oracle Solaris to be configured, scheduled, and executed directly from Veeam Backup & Replication. Unlike agent-managed policies, server-managed jobs give backup administrators centralized control over job execution and scheduling, without relying on the agent to initiate sessions independently.

Backup window support — Adding backup window enforcement for Veeam Agents for IBM AIX and Oracle Solaris when jobs are managed via Veeam Backup & Replication. Administrators can now define allowed and prohibited time intervals for agent backup jobs, preventing overlap with production hours and ensuring backup traffic does not impact business-critical operations.

Intelligent data processing — File-level backup performance is improved through parallel data processing: data is transferred to the backup server using multiple parallel streams, with large and small files processed concurrently to better utilize available network bandwidth. The degree of parallelism is tuned dynamically based on observed performance from previous backups, improving progressively as statistics are collected.

Gateway mode for S3-compatible object storage — V13.1 adds support for Gateway mode when backing up Veeam Agents for IBM AIX and Oracle Solaris to S3-compatible object storage, complementing the existing Direct mode. In Gateway mode, all backup and restore traffic is routed through a gateway server assigned in the Veeam Backup & Replication console. This is better suited for environments with network restrictions for on-premises S3 storage or where direct internet access from endpoints to a cloud based S3 storage are not permitted.

Export skipped files as .csv file report — Users can now get a .csv-formatted list of files skipped during backup jobs for Veeam Agents for IBM AIX and Oracle Solaris directly from Veeam Backup & Replication when exporting backup job logs. This enables centralized review of skipped files from the backup server without inspecting logs on individual UNIX systems, improving compliance, and audit readiness. Alternatively, the .csv file can also be collected from each instance individually.

IBM AIX 6.1 support — Veeam Agent for IBM AIX reintroduces support for AIX version 6.1, restoring compatibility with legacy AIX environments in addition to existing AIX 7.x coverage.

Universal CDP

Universal Continuous Data Protection: Linux support — Following the introduction of agent-based Universal Continuous Data Protection (CDP) for Windows in V13, V13.1 extends near-zero RPO continuous replication to Linux workloads as well. You can now continuously replicate any Linux machine — physical, virtual, or cloud — to VMware vSphere or VMware Cloud Director (through Veeam Cloud Connect for Cloud Service Provider and Sovereign Cloud based DR) targets, protecting your entire mixed estate with a single CDP strategy instead of maintaining separate approaches for Windows and Linux.

The experience remains unchanged: Linux machines are organized through the same policy-driven Protection Groups and use the same building blocks as on Windows — the same lightweight I/O interception on the source and replication to your chosen target. As on Windows, the filter driver attaches to any block device without requiring a reboot, so replication can begin on a live production system immediately after installation, with full failover, undo failover, permanent failover, and failback to a new location all supported.

Improved long RPO support — CDP delivers the lowest possible RPO, but not every workload needs sub-second protection — and when a longer RPO (such as 30–60 minutes) is configured, you rightly expect it to reduce the load on your infrastructure, not increase it. V13.1 redesigns the CDP proxy cache and traffic queue to deliver exactly that. Overwrites occurring within the same RPO window are now coalesced before transfer, significantly reducing the amount of data sent from the source proxy to the target and shrinking the resulting replica writes. The cache also prioritizes already-confirmed replication traffic over not-yet-confirmed data and gracefully spills to disk during I/O bursts instead of slowing replication down. The net effect is intuitive at last: configuring a longer RPO now means less infrastructure load, exactly as it should.

Universal CDP: feature parity with standard CDP — When agent-based Universal CDP was introduced in V13, it focused on the core near-zero RPO replication workflow. V13.1 closes the gap with classic VMware-based CDP by bringing the day-2 operational capabilities customers rely on in real DR scenarios directly into Universal CDP policies. Veeam Explorers now enable application and item-level recovery from Universal CDP restore points; Re-IP rules automate IP address changes during failover; replica seeding accelerates initial replica creation while cutting the bandwidth required for the first sync; network mapping streamlines DR placement and configuration; and application-aware image processing delivers application-consistent long-term restore points. With the same near-zero RPO engine now backed by the operational flexibility expected from a production DR solution, Universal CDP is ready for real-world disaster recovery.