Unstructured Data Protection
Enhancements to NAS and unstructured data backup in this release are focused on simplifying long-term retention, reducing storage costs, and improving scalability and performance. Organizations can apply Grandfather-Father-Son (GFS) with weekly, monthly and yearly backups to long term retention directly in backup jobs, leverage archive storage in multiple roles (primary, secondary, and archival tier), and scale protection to multi-petabyte environments using object storage. Performance and data consistency are also improved through optimized processing of large file shares and enhanced tracking of file permissions.
Malware Detection — With this release, malware detection capabilities are extended to unstructured data workloads, introducing file-level analytics and Indicators of Compromise (IoC) scanning. File-level detection analyzes suspicious file system activity, including mass file renames and deletions, helping organizations identify potential ransomware attacks and other malicious activity earlier in the incident lifecycle. Combined with IoC-based inspection, this capability provides deeper visibility into the integrity of protected unstructured data. Available with the Advanced Edition of Veeam Universal License, it enhances cyber resilience by helping administrators detect threats before they impact recovery operations.
Threat Hunter support — Veeam Threat Hunter now supports file share and object storage backups, extending signature-based malware detection and YARA rule scanning to unstructured data workloads. Administrators can perform both automated post-backup scans and on-demand inspections to identify known threats and suspicious content within protected data. By combining signature-based analysis with customizable YARA rules, Threat Hunter provides deeper visibility into potential malware infections and helps organizations validate backup integrity before recovery. Available with the Advanced Edition of Veeam Universal License, this capability strengthens cyber resilience for NAS and object storage environments.
GFS retention — Grandfather-Father-Son (GFS) retention can be configured directly within NAS and object storage backup jobs, allowing administrators to define weekly, monthly, and yearly restore points without additional jobs. The implementation is storage-efficient, as GFS points reference existing data from previous backups instead of creating new full copies. This capability simplifies backup configuration, reduces administrative overhead, and enables cost-efficient long-term retention while maintaining compliance with data retention policies.
Archive storage as direct backup target — NAS environments that rely on internal snapshot replication for day-to-day recovery now have a cost-effective path to long-term disaster recovery by storing an additional copy outside of their storage to an archive. In this scenario, rather than landing backups on hot object storage and tiering them out later, Veeam can write unstructured data backups directly to archive-class storage as the primary repository. The workflow itself stays intact: the same source, cache repository, proxy, and processing components remain in place. Only the destination changes. No architectural redesign, no additional infrastructure. Because archive storage is optimized for rarely accessed data, restores are not immediate; data must first be retrieved from the archive tier before it can be restored. Supported archive targets include Veeam Data Cloud Vault Archive, Azure Archive, and AWS S3 Glacier.
Archive storage as a secondary target — With this release, backup jobs can create an additional copy directly in archive-class storage as a secondary target alongside the primary repository. Supported targets include Amazon S3 Glacier, Azure Archive, and Veeam Data Cloud Vault Archive. This capability enables cost-efficient long-term retention and redundancy, allowing organizations to meet compliance and resiliency requirements without maintaining a second copy on expensive hot storage.
Tiered archival — With this release, archive-class object storage can be configured as an archive target. Backup data can be automatically moved to archive storage as it ages out of the primary retention window, or recent restore points can be copied to archive immediately upon creation. Supported targets include Veeam Data Cloud Vault Archive, Azure Archive, and Amazon S3 Glacier. This capability enables automated, cost-efficient long-term retention without additional workflows, helping organizations meet compliance requirements while reducing storage costs.
SOBR object storage extent support — Scale-out backup repositories have long been available for NAS backups; V13.1 now adds object storage as a supported extent type for them. This enables horizontal scaling across large on-premises and cloud-based object storage deployments for Unstructured Data Backup. As your data grows, the SOBR grows with it: add capacity incrementally by extending the repository with additional object storage extents, without redesigning your backup architecture or interrupting running jobs.
Improved single-share backup performance — Source-side reader thread parallelism has been improved, enabling multiple threads to process data from a single share concurrently. This capability increases backup throughput for large file shares, reducing backup windows and improving efficiency when protecting high-capacity NAS workloads.
Incremental Processing of Large Files — Unstructured Data Backup now supports incremental processing of files larger than 32 MB. Instead of reprocessing the entire file when changes occur, Veeam can identify and process only the modified portions, significantly reducing backup windows, network utilization, and repository consumption for large files that change frequently.
ACL changes support — NAS backup tracks and processes now ACL changes, capturing them in incremental backups and reapplying them during restore operations.
Full Web UI coverage — With this release, unstructured data sources, backup jobs for file shares and object storage, along with monitoring and recovery operations, are fully available in the Web UI.