Veeam Software Appliance and Veeam Infrastructure Appliance

Veeam continues to invest across the Veeam Software Appliance (VSA) and Veeam Infrastructure Appliance (VIA) platform, delivering targeted improvements in operational efficiency, security hardening, and deployment flexibility with each release.

General Improvements

Drive expansion – Administrators now can add additional drives to an existing Veeam Software Appliance deployment after installation to extend available storage capacity. This can be used for multiple purposes, including capacity extension within existing Scale-out Backup Repositories or creating new Repositories.

FC and iSCSI storage support — Veeam appliances now support attaching Fiber Channel (FC) and iSCSI storage devices, along with multipathing, enabling deployment in enterprise SAN environments.

Custom log path configuration – A custom file system path now can be set for Veeam log files using Host Management Console to redirect logs to a dedicated mount point or storage volume on the Logs and Services page.

Extended unattended deployment control — Two additional flags are now available: DataCollection to allow automatic joining to Veeam Service Provider Console and Veeam ONE and High Availability to skip high availability-related steps during automated deployment.

Upgrade to Veeam JeOS 9.6 — All Veeam Appliances are now upgraded to Veeam Enterprise Linux JeOS 9.6, extending hardware compatibility and incorporating the latest kernel improvements and platform updates.

Updates Mirror via Enterprise Manager — Enterprise Manager can now act as a centralized update mirror, caching product updates from the official Veeam repository and distributing them to managed Veeam Infrastructure Appliance (VIA) and Veeam Software Appliance (VSA) deployments. This capability is particularly valuable in environments with restricted, proxied, or tightly controlled internet connectivity, where direct access to external update services is limited. By centralizing update distribution and reducing external connectivity requirements, organizations can simplify update management while maintaining greater control over how updates are delivered across their backup infrastructure.

Observability

Prometheus-compatible metrics — Veeam appliances now expose a broad set of system metrics through Node Exporter, enabling seamless integration with Prometheus-compatible monitoring platforms and observability stacks. This allows organizations to collect, visualize, and analyze appliance health and performance data using their existing monitoring tools and processes. This capability is available when a Veeam Universal License is installed on the backup server.

Syslog support for appliance events — Veeam appliances now can forward system logs and operational events to an external syslog server for centralized log aggregation, SIEM integration and compliance-driven audit trails without additional agents.

Resource consumption dashboard — Host Management Console now includes a live resource monitoring view that shows CPU, memory and disk utilization. This helps administrators quickly identify resource bottlenecks and correlate workload spikes with infrastructure load.

Email notifications for storage load — Veeam Backup & Replication now sends an email notification whenever appliance storage utilization exceeds configured thresholds, providing early warning before capacity becomes critical.

User management and MFA

Streamlined MFA configuration — Multi-factor authentication (MFA) initialization is now available in the Web UI in addition to text user interface (TUI).

Unified user management — User creation includes optional assignment of Veeam Backup & Replication roles during onboarding. MFA configuration is also unified, with settings defined in Host Management automatically applied to Veeam Backup & Replication access. This capability simplifies user management, reduces administrative overhead, and ensures consistent access control and security policies across the environment.

Optional MFA at deployment — Multi-factor authentication (MFA) was enforced during deployment, making it difficult to automate installations or deploy in environments without access to authenticator apps. With this release, Veeam Software Appliance (VSA) and Veeam Infrastructure Appliance (VIA) can be installed without enforcing MFA for the veeamadmin and veeamso accounts. MFA can be enabled later from the Host Management Console.

Longer MFA secret length support — MFA now supports 160-bit secrets to improve compatibility with modern authenticator applications and enterprise MFA solutions, helping organizations align with current security standards.

Localization

Host Management localization — The Host Management Console adds support for German, Japanese, and French, allowing each user to select their preferred display language independently.

Keyboard layout selection – Terminal User Interface initialization wizard and menu now include keyboard layout selection.

Security and compliance

Improved certificate management – It’s now possible to import workload certificates into the system certificate store and apply custom TLS certificates to the Host Management Console Web UI without manual certificate operations at the OS level.

Password expiration configuration — Administrators can define password expiration policies directly in Host Management to enforce password lifecycle requirements, improving security posture and ensuring compliance with internal and regulatory standards.

Password reset restriction — Administrators can disable password reset through the Host Management Console, limiting password reset operations to the Host Manager Terminal User Interface only.

Control over FIPS-compliance — Host Management Console introduces a strict, global FIPS compliance mode that enforces consistent cryptographic standards across both system-level and application-level components to simplify compliance management for regulated environments, ensure consistent security configuration while reducing administrative overhead and configuration errors.

Reduced permissions on log folders — Log directories and files now use stricter permissions, reducing exposure of sensitive log data.

Veeam Software Appliance

Extended HotAdd support – VSA now supports HotAdd transport mode for VMware vSphere backups in all-in-one deployments. This capability enables higher backup performance and removes previous limitations, allowing organizations to deploy Veeam Software Appliance in VMware Cloud environments while achieving efficient data transfer.

Hyper-V VM image — A ready-to-use Hyper-V virtual machine image is available for Veeam Software Appliance.

PostgreSQL security hardening — The internal PostgreSQL database on Veeam Software Appliance is hardened following industry-standard database security best practices, with a focus on audit logging and log-file security.

Automatic database disk quota expansion — Veeam Software Appliance now automatically expands the database quota when its free space becomes low and alerts administrators if the underlying storage volume is running out of space.

High Availability

Support for cross-subnet HA clusters — Designed for real-world enterprise architectures, v13.1 enhances High Availability with support for cross-subnet HA clusters, enabling HA nodes to be deployed across different networks or sites - meeting common enterprise segmentation requirements without added deployment complexity.

Flexible Deployment — High Availability now supports flexible deployment approaches: a standard cluster for straightforward environments, or a cross-subnet cluster for larger organizations that want to place nodes in a geographically separate data center or a separate network segment - while still presenting a single HA cluster identity.

Synchronization Experience Enhanced —To make High Availability more transparent and resilient, we’ve improved the day-to-day maintenance experience across HA nodes by reducing manual coordination and keeping key configuration elements aligned automatically.

Users synchronization — User synchronization is now automatic, keeping the secondary aligned with the primary and avoiding the inconsistencies that can occur with manual user management.

Private fix synchronization — Private fixes (hotfixes delivered outside the standard update channel) are now automatically synchronized between HA cluster nodes, eliminating manual application to the secondary node.

REST API coverage — makes HA management easier to automate and operate at scale, with support for key HA lifecycle actions.

Data lag observability — See exactly how much data lag exists before a switchover or failover, so administrators can make an informed decision before committing to the operation.

Version observability — See when a secondary node is in the process of being upgraded, so administrators have full visibility into replica health before relying on it for failover. Overall, more granular statistics about HA are now collected.

Modify cluster settings — Existing High Availability clusters can now be edited, allowing changes to cluster endpoint parameters: the virtual IP address and cluster DNS name for a regular cluster, or both external IP addresses and the cluster DNS name for a cross-subnet cluster.

Veeam Infrastructure Appliance

Single-disk deployment option — Veeam Infrastructure Appliance can be deployed on a single-disk server without a dedicated backup storage disk. This capability supports use cases where Veeam Infrastructure Appliance operates as a backup proxy with remote storage or when Application Backup Repository should be used, simplifying deployment and allowing more flexible use of available infrastructure.

Unified boot options — Veeam Infrastructure Appliance now uses a unified boot menu for all roles, including Infrastructure Server, iSCSI & NVMe/TCP, and Hardened Repository. The appliance role is selected later during the initialization wizard.

Expanded repository path support — Backup repositories can be created at or under /var/lib/veeamdata/backup on Veeam Infrastructure Appliance deployments for greater flexibility in storage design, supporting single-disk configurations and simplifying deployments where additional storage devices are not available.

Application Backup Repository deployment — Veeam Infrastructure Appliance in Hardened Repository role can now act as an Application Backup Repository (ABR). Storage Pool management for ABR is available directly from Host Management Console. For more details, see the Application backup repository section of this document.

Direct SAN mode support — Veeam Infrastructure Appliance now supports Direct SAN access over Fibre Channel and iSCSI, letting VIA read virtual machine data directly from SAN storage for faster, production LAN-free backups.

Backup from Storage Snapshots over NVMe/FC — BoSS jobs can now retrieve snapshot data over NVMe/FC, giving VIA a lower-latency path to the storage array and reducing backup windows for NVMe-based arrays.