Cloud Workload Protection
For organizations that require full control over their cloud backup policies, data sovereignty, and infrastructure decisions, Veeam Backup for Azure, AWS, and Google Cloud delivers customer-managed protection for cloud workloads; complementing the fully managed Backup-as-a-Service coverage available through Veeam Data Cloud for those who prefer to offload that responsibility entirely.
Amazon AWS
Veeam Data Cloud Vault support — V13.1 lets you now connect Veeam Data Cloud Vault directly into Veeam Backup & Replication through the Veeam AWS appliances that manage it. Connect a Vault-backed appliance to the Veeam Backup & Replication console, or provision the repository on the appliance from within Veeam Backup & Replication itself. Either way, the repository registers in Veeam Backup & Replication as an external repository, no shared keys required, and becomes immediately available for restores, backup copy jobs, and other secondary workflows. Access is governed by federated, role-based authentication rather than long-lived credentials, keeping the integration both operationally clean and secure.
AWS China Region Support — The backup appliance can now be deployed in AWS China regions, deployed and managed from Veeam Backup & Replication; which must be running in the China region, either on-premises or on an EC2 instance in an AWS China region.
S3 Standard-Infrequent Access for Backup Repositories — Backups can now be stored in S3 Standard-Infrequent Access as the storage class for backup repositories within the backup appliance.
Microsoft Azure
Veeam Data Cloud Vault support — V13.1 lets you now connect Veeam Data Cloud Vault directly into Veeam Backup & Replication through the Veeam Microsoft Azure appliances that manage it. Connect a Vault-backed appliance to the Veeam Backup & Replication console or provision the repository on the appliance from within Veeam Backup & Replication itself. Either way, the repository registers in Veeam Backup & Replication as an external repository, no shared keys required, and becomes immediately available for restores, backup copy jobs, and other secondary workflows. Access is governed by federated, role-based authentication rather than long-lived credentials, keeping the integration both operationally clean and secure.
Microsoft Entra ID Authentication Support for Azure SQL — Backup policies protecting Azure SQL databases can now authenticate using a Microsoft Entra ID (formerly Azure AD) application instead of SQL credentials. This aligns Azure SQL backup with modern identity standards and enables customers to enforce Entra ID-based access controls consistently across their Azure SQL environments - eliminating the need to manage SQL logins for backup service accounts.
Malware Detection for Azure VM Backups — Azure VM backups support malware detection using guest indexing analytics and entropy analysis in addition to already available signature-based analysis and YARA rule scanning. This capability enables organizations to detect suspicious activity directly within Azure VM backups, improving threat visibility and strengthening ransomware protection for cloud workloads.
Disk Exclusion in VM Backup Policies — Exclude specific VM disks from backup policies using either a disk ID or Azure resource tags.
Auto-Approval of Private Endpoints for Azure SQL — In private network deployment configurations, the backup appliance can now automatically approve private endpoint connection requests for Azure SQL workloads by enabling the feature for the specific service account.
Direct Restore to Microsoft Azure
Network Security Groups — A new “Do not assign (use subnet settings)” option lets restored workloads inherit Network Security Groups pre-attached to the chosen subnet, so security admins can enforce their own hardened inbound rules instead of the loose default 0.0.0.0 source. “Empty” option has also been changed to “Create New” as it better reflects the underlying action. Applies to the Azure restore proxy along with VMs processed in scope of Instant and Direct Restore to Azure.
NVMe Disks — VMs processed in scope of Direct Restore to Azure and Azure Restore Proxies now support setting v6 and v7 VM sizes with NVMe disks.
Instant Restore to Microsoft Azure
Scalability — For a single Instant Recovery to Azure session, the maximum recommended number of processed VMs is now set to 250. This value is provided as guidance to help ensure stable and predictable performance during large restore operations. To reduce the possibility of Azure-side throttling and related slowdowns, VMs are now processed in parallel in batches of 80.
Google Cloud
Immutable repositories support — Veeam Backup for Google Cloud can now use immutable Google storage as a backup repository. This prevents backup files from being deleted, modified, or encrypted by malicious actors or accidental admin actions for a predefined retention period. This feature requires the Veeam Plug-in for Google Cloud v8 release.