Backup Repositories

Linux based Hardened Repository

In addition the strict Veeam Hardened Repository Appliance, we are opening the same concept for less strict Linux Repository environments that want to benefit from Immutability while keeping the flexibility of deleting backup at the system administrator level with Immutability in governance-mode.

Governance-mode immutability — Standard Linux repositories now support governance-mode immutability using the same underlying immutability engine as we use with the Hardened Repository appliance to enable flexible, policy-driven data protection, allowing organizations to benefit from immutability while simplifying deployment and allowing additional roles which are not allowed on Hardened Repository.

Authorization for immutability changes — Reducing or disabling the immutability period on Hardened Repositories and governance-mode Linux repositories now requires approval from a second authorized user whenever four-eyes approval is enabled.

Configuration backup immutability — Veeam Backup & Replication configuration backups can be stored immutably on Hardened Repositories and governance-mode Linux repositories.

Object Storage

Object storage repository read-only mode — V13.1 adds an “Enable read-only access” option when connecting to an immutable object storage repository, letting a second backup server (such as a DR-site instance) attach to a repository already owned by your production server. In read-only mode the second server never writes to or modifies the data and performs restore operations only, so you can run restores, recoverability checks and Data Integration API based forensics/ransomware scans from a separate location without taking ownership away from production or disrupting running jobs. This turns regular restore testing, previously impractical because of the coordination overhead of transferring ownership, into a native, supported capability rather than a workaround.

Veeam Data Cloud Vault

Veeam Data Cloud Vault guided AWS onboarding — Azure-based Veeam Data Cloud Vault has always offered a dedicated, guided onboarding experience directly in the Veeam Backup & Replication console. For customers with specific use cases for AWS based processing, V13.1 brings the same experience to AWS-based Veeam Data Cloud Vault: instead of adding it as a generic Amazon S3 object storage repository and pasting shared keys, you simply select your Vault in the unified wizard and the repository is provisioned automatically, with immutability enabled by default.

Setup also moves away from long-lived shared keys to federated, role-based access, the same secure approach used for Azure Vault, so there are no static credentials to manage, rotate, or risk leaking. For customers already running Azure Vault, adding AWS is now an identical workflow, one wizard, both clouds covered.

Veeam Data Cloud Vault Archive — Veeam extends the fully managed Vault experience to archive-class cloud storage. With Azure Blob Archive tier, we are delivering the lowest-cost option for long-term retention without requiring you to manage your own cloud storage infrastructure. Vault Archive can serve as a primary backup target for unstructured data (NAS) backups, or as the Archive Tier of a scale-out backup repository, automatically moving or copying GFS restore points from Vault Standard to Archive Vault.

Unlike the standard Archive Tier, Vault Archive requires no archiver appliance. Backup data is consolidated natively in the cloud, so there is no extra compute to deploy, manage, or pay for. As with any archive-class storage, restores require a data retrieval step and are therefore not instant, making Vault Archive ideal for data retained for years and accessed very rarely; where lowest cost matters more than immediate availability.

Veeam Data Cloud Vault built-in cost guardrails — Veeam Data Cloud Vault is built around all-inclusive, predictable pricing, and we now introduce edition-aware guardrails that keep usage aligned with that model, so you are never surprised by cloud charges that fall outside of it. For Vault instances on the Foundation edition, the product now automatically prevents configurations that would generate unplanned egress or retrieval costs, keeping all scale-out repository tiers within the same cloud region, blocking offload or archiving to non-Vault storage that would incur egress, and disabling the higher-cost priority (Azure) retrieval options for Vault Archive. To honor the cloud providers’ minimum storage commitment periods, immutability is always on and enforced for at least 30 days on Standard Vault and 180 days on Vault Archive. Premium edition is unaffected, as its unlimited-egress commercial model carries no such restrictions.

Scale-Out Backup Repository

Archive Tier copy policy — This new Copy policy for the scale-out backup repository Archive Tier was added in addition to the existing Move policy. Instead of waiting for GFS restore points to age out of the archive window before they move to the Archive Tier, the Copy Policy archives the GFS points upon creation while keeping the local copy on the Performance Tier until it naturally expires. Copy and Move policies can also be combined to apply different retention per tier. For example, shorter on the Performance Tier and longer on the Archive Tier which enables to keep a local copy for fast restores during the archive window and an archive copy available for long-term retention, compliance, or ransomware resilience. The Copy policy applies to Direct Archival configurations only, a scale-out backup repository with a Performance Tier and an Archive Tier. Configurations that include a Capacity Tier (Capacity Tier → Archive Tier) do not support Copy mode.

Actual backup size reporting — Shows how much space your backups truly occupy on object storage, not just their logical size before optimizations such as block reuse. Both values are displayed side by side wherever you review backups, “Backup size” for the logical size and “Actual size” for the space consumed after optimizations. Wherever a backup resides, on a standalone repository or any tier of a scale-out backup repository, you can see the actual space its chain segment occupies on that specific tier, or the total consumed across all tiers at once. This takes the guesswork out of capacity planning across tiered storage.

Archive Tier minimum immutability period — Archive repositories can now be configured with a minimum immutability period. A fixed number of days during which data cannot be deleted or modified can be set as an alternative to keeping backups immutable for their entire retention period. . A minimum immutability window gives you protection where it matters most: the critical period right after a backup is created is protected from alteration or attacks, while leaving the flexibility to manage or delete archive data once that window has passed.