Enterprise Application and Database Protection

Application backup repository

The Veeam Infrastructure Appliance operating in Hardened Repository mode now introduces Application Backup Repository (ABR), a capability that transforms local storage into a managed pool of virtual volumes, each exposed as an individual NFS target. External applications and services write directly to their assigned NFS targets without requiring awareness of the underlying Veeam infrastructure, while Veeam automatically manages snapshots, backup copies, immutability, and access control. This provides a secure-by-design foundation for application-generated backup, export, and dump data.

Application Backup Repository supports a broad range of workloads that can write data to NFS. For structured applications such as Oracle RMAN Incremental Merge, it provides live-access NFS targets with fast snapshot reverts that integrate naturally into database protection workflows requiring frequent recovery points. For less structured environments, including network devices, IoT systems, and standalone databases, Application Backup Repository offers a simple and immutable destination for backup and configuration data that might otherwise reside on unprotected storage. This functionality is available when a Veeam Universal License is installed on the backup server. The following features are available with the initial release:

Full Application Backup Repository management in the Veeam Host Management – Application Backup Repository is managed directly through the Host Management Console with disk provisioning and pool configuration, keeping the configuration footprint within the existing Hardened Repository management experience. The feature is opt-in by design. Application Backup Repository must be explicitly enabled on newly installed Hardened Repositories and is NOT activated on existing deployments through updates. This ensures that no changes are made to production hardened repository infrastructure without deliberate administrative action. The Application Backup Repository wizard allows the definition of virtual volume, NFS export and schedules.

Instant restore - Snapshot-based restore points with configurable retention give Application Backup Repository the ability to revert an entire NFS share to any selected point in time instantly. External backup processes can pick up from an older restore point and continue building new backup chains from there, without manual intervention or data reconstruction.

Instant export - For scenarios requiring access without disruption to the most actual data stored, a temporary snapshot export to an alternative NFS path provides read-only access to the backed-up data. This allows inspection, validation, or cross-system restores to run in parallel against the exported snapshot in a secure and protected way, while the live share continues operating uninterrupted.

Immutable backups - Snapshot lock enables restore points’ immutability at the filesystem level.

Backup copy and tape offload - Backups stored in the Application Backup Repository can be further incrementally copied to a standard forever-forward incremental VBK/VIB chain to any generic Veeam Backup & Replication Repository and then offloaded to tape, enabling air-gapped long-term retention for application data.

Veeam Snap Scale Backup for Enterprise Applications

Large-scale database backup - Enterprise databases at the 100+ TB scale demand a fundamentally different approach to backup. This new backup policy is purpose-built for exactly that; delivering massive parallelization across both backup processing and target infrastructure to protect ultra-large databases within an optimized backup window.

At the start of each backup, applications are brought into a consistent state, and storage snapshots are created directly through the Veeam Universal Storage API (USAPI), with broad support for iSCSI and Fibre-Channel enterprise storage systems. From there, Veeam takes one of two paths: snapshots are either maintained in a retention chain through snapshot orchestration, or backups are created directly from the snapshots. During backup processing, snapshots are mounted to multiple Veeam Linux Proxies and read in high parallelization, leveraging Veeam’s unstructured data backup engine under the hood. On the target side, Scale-Out Backup Repositories span multiple servers and storage systems to match the throughput capability of the backup source storage, ensuring optimized processing at peak performance of the underlaying hardware capabilities.

Backup efficiency follows the same source-side deduplication principle proven in image-level backup: in this case large database files are compared area by area against the last existing backup, and only changed data is transported to the target; keeping backup sizes lean without sacrificing recovery fidelity.

The first workload to leverage this policy is Epic EHR system protection, covered below.

Enterprise Application Plug-ins Enhancements

GFS retention for managed plug-ins - Long-term GFS (Grandfather-Father-Son) retention with Weekly, Monthly and Yearly flags is now available as part of the backup policy for Oracle RMAN, SAP HANA and Microsoft SQL Server, preserving restore points for the most critical workloads over extended periods. The configuration experience is identical to GFS retention elsewhere in the product. Note that a single backup file can carry multiple GFS flags, which should be considered during capacity planning, and flags are unassigned during backup runs whenever expired flags are detected. As an additional benefit, each GFS restore point is created as a standalone full backup whose .vab backup file is closed immediately upon completion, enabling immediate immutability.

Backup to Tape Support for Enterprise Application Plug-ins - Plug-in backup restore points can now be processed by Backup to Tape jobs, providing an additional layer of protection through long-term, air-gapped storage for organizations that require tape-based retention. Support is available for all remaining enterprise application plug-ins, including Oracle RMAN, Microsoft SQL Server, SAP HANA, SAP on Oracle, SAP MaxDB, and IBM Db2, whether deployed in managed or standalone mode. Tape backup operates on repository contents: full tape backups process the entire repository backup chain as it exists at the time the job runs, while incremental (forever) tape backups process only newly created plug-in backup files. Restore is performed in two stages—first to the backup repository, with automatic backup import, and then through the application itself or a Veeam Explorer. This functionality is available when a Veeam Universal License is installed on the backup server, regardless of the licensing mode used by the protected application workloads.

Plug-in backup properties - You can now review which databases were backed up directly from the backup console, with backup properties implemented for all plug-ins, including the option to view the list of backup files stored on the repository. Depending on the application type, additional details such as backup catalog content may also be available.

Individual Application and Database Enhancements

Epic EHR System Protection

Electronic Health Record (EHR) systems are among the most mission-critical workloads in healthcare environments, requiring reliable and automated data protection. Veeam now delivers dedicated protection for Epic environments running on the InterSystems IRIS Data Platform through the new Veeam Snap Scale Backup for Enterprise Applications backup method. By integrating application-aware orchestration with storage snapshots, this capability simplifies protection workflows while enabling fast, scalable backup and recovery for large healthcare deployments. Available with Advanced Edition and above of Veeam Universal License, it helps healthcare organizations strengthen resilience and ensure the availability of critical patient data. The following features are available:

Protection Group support - A dedicated Protection Group for InterSystems IRIS rolls out the necessary components onto the database servers and rescans the application topology automatically, discovering instances and their associated storage volumes with no manual mapping required.

Backup policy for the InterSystems IRIS databases - Purpose-built for the scale and performance demands of these environments, can operate in two modes: snapshot-only mode, which creates and retains storage snapshots, or backup mode, which captures data into a Veeam repository. In both cases, the policy leverages the Universal Storage API (USAPI) to communicate with the underlying storage system and create the storage snapshot. To guarantee application consistency, the IRIS instance is frozen only for the brief moment required to create the storage snapshot, then unfrozen immediately afterward. In backup mode, the snapshot clone is then mounted to a Linux-based proxy and the data is read by the Unstructured Data Backup engine. Backup efficiency follows the same source-side deduplication principle proven in image-level backup: in this case large database files are compared area by area against the last existing backup, and only changed data is transported to the target; keeping backup sizes lean without sacrificing recovery fidelity.

Short and simple restore wizard - Enables recovery to the original or to a different location, offering a quick restore from a storage snapshot by exporting its clone to the target, or a restore from a backup through physical data transfer with massive parallelization. Please refer to our technical documentation for additional pre-restore and post-restore recommendations to optimize the restore experience depending on your specific scenario.

IBM Db2

IBM Db2 on Windows - A new Enterprise Application plug-in enables native backups of Windows-based Db2 workloads, delivering the same DBA-driven, native backup experience already available on Linux and AIX using standard tools and external schedulers.

Microsoft SQL

Separate SQL account and SA authentication - With Veeam Application-aware image processing it is now possible to specify a separate account per machine rather than a single account per job. It leverages SQL Server authentication (SA) that is not tied to any Windows user accounts. Available for VMware and Hyper-V backup jobs via a new account dropdown and SA authentication checkbox in the processing settings.

Restore Amazon RDS for SQL Server backups to on-premises — Veeam Explorer for Microsoft SQL Server can now restore databases from backups created by Veeam Backup for AWS to on-premises target SQL servers, streamlining “reverse migration” and test-restore scenarios in hybrid environments.

MongoDB

New MongoDB platforms — Protection coverage at the Enterprise Application plug-in is expanded with official support for MongoDB Community Edition and Percona Server for MongoDB.

Oracle

Oracle Incremental Merge support with Veeam Application Backup Repository - One of the most popular DBA strategies which maintains an always-current image copy of the database by rolling forward only the latest incremental changes, minimizing both the backup window and storage usage, is now supported. DBAs can now perform Oracle Incremental Merge on our new Application Backup Repository (ABR), with ABR snapshots additionally enabling “time travel” to previous points in time. In this release, it is a manual process: DBAs specify the ABR as an NFS target in their RMAN script. Recovery options include switching to the image copy, or reverting to a snapshot (which requires a control file restore) and then switching back to production by moving the data files. Note that ABR snapshot creation and backup schedules must not overlap.

Oracle Database 26ai — Oracle 26ai is now fully supported by the Oracle RMAN plug-in and for application-aware processing of virtual and physical machines.

Extended Oracle HA, DR and Engineered Systems coverage — This release adds official support to the Oracle RMAN plug-in for additional Oracle high-availability and engineered platforms. Oracle Fail Safe based on Windows Failover Cluster and clusters based on Pacemaker, Corosync and the Red Hat HA add-on, as well as Oracle SEHA clusters, are now supported in standalone mode, while Oracle Database Appliance is supported in both standalone and managed modes.Oracle RMAN script export - Veeam Explorer for Oracle RMAN now enables export of the RMAN restore script to share with a DBA, making the restore procedure easier for DBA teams. Simply step through the familiar restore wizard in a password-less manner, the wizard performs no validations, and the script is generated at the end.

PostgreSQL

PostgreSQL on Windows — Windows-based PostgreSQL workloads can now be protected with application-aware processing on VMware and Hyper-V. In addition, Veeam Explorer for PostgreSQL now supports Windows-based restore targets. A new SSPI-based authentication mechanism, attempting Kerberos first and then failing over to NTLM, enables processing of Windows guests.

Patroni-managed PostgreSQL cluster support — Veeam now provides application-aware protection for PostgreSQL clusters managed by Patroni on Linux, delivering application-consistent backups with support for point-in-time recovery. Cluster topology is discovered and maintained automatically, with Veeam rescanning the environment during each backup to keep configuration information up to date while continuously processing WAL data from the primary node. Recovered databases are immediately accessible through Veeam Explorer for PostgreSQL, providing the same granular recovery capabilities available for standalone PostgreSQL deployments. Available with paid Veeam Universal License editions (Essentials, Advanced, and Premium), this capability simplifies protection and recovery of highly available PostgreSQL environments while maintaining consistent administrator experience.

Veeam Explorer for PostgreSQL individual database restore — In response to numerous customer requests, Veeam Explorer for PostgreSQL now supports selecting one or more individual databases and restoring them to the original or a different location, extending the scope of supported restore scenarios. This also maximizes the value of Patroni support, where granular recovery is often preferred over restoring an entire instance.. A new wizard step is now included in Veeam Explorer for PostgreSQL to authenticate to the target PostgreSQL instance. This functionality is supported for backups of Linux-based workloads only.

SAP HANA

Custom SAP HANA backup file prefixes — A new option in the policy settings lets you define custom prefixes for SAP HANA backup files, making backups easy to identify, sort and align with internal naming conventions, audits and multi-tenant environments.