Managing AWS KMS Connections

To encrypt backed-up data using an AWS KMS master key, you must first connect to an AWS account that manages this key. To learn how to do that, follow the instructions provided in section Adding AWS KMS Connections. After you add a connection to AWS KMS, you can use the AWS master key to encrypt the backed-up data as described in the Edit Encryption Settings step of the Editing Backup Policies section.

The KMS connection that you add to Veeam Data Cloud will be available for all tenants in your Veeam Data Cloud organization that use the same Azure region.

Before you connect to an AWS account, check the following prerequisites:

  • Make sure that the IAM user that will be used to perform data encryption has all the required permissions.
  • Make sure that you have created the AWS KMS master key in the AWS account. For more information, see AWS Documentation.
  • Make sure that you have created an access key ID and a secret access key that will be used to authenticate requests to the AWS account. Keep in mind that you can see and copy this ID and key only when creating an access key pair. For more information, see AWS Documentation.

In This Section