Veeam Backup & Replication v13 – data security at a new level

VeeamON 2025 in San Diego – Veeam Backup & Replication v13 changes the game During this year’s VeeamON 2025 conference in San Diego,…

VeeamON 2025 in San Diego – Veeam Backup & Replication v13 changes the game

During this year’s VeeamON 2025 conference in San Diego, one thing became clear: Veeam isn’t slowing down for a moment!
The new version of the platform – Veeam Backup & Replication v13 – is not just an update, but also a complete reconstruction of the architecture for security and backup management, in which terms such as Zero Trust, immutability, and automation take on real significance.

High Availability (HA) – Veeam clustering, finally natively

The most anticipated moment of the conference was the announcement of the high availability (HA) mechanism.
Veeam Backup & Replication v13 introduces the ability to configure an Active-Passive cluster with automatic synchronization and role takeover in the event of a failure.

Thanks to this:

  • backup workloads can be automatically transferred to the standby node,
  • the VBR configuration is replicated in real time,
  • planned or automatic failover/failback is possible.

Importantly – HA works natively only in the Veeam Software Appliance environment on Rocky Linux, which shows that Veeam is consistently focusing on the new platform and backup security.
Until now, implementing HA required integration with external tools, whereas now a single click is all it takes.

2 Cloud4You
Fig. 1. High-availability cluster diagram in Veeam v13 divided into primary and secondary nodes.

HA configuration requires several conditions to be met:

> Both nodes must be installed as software appliances on Rocky Linux.

> Static IP address assignment and proper DNS name resolution configuration are required.

> Data synchronization must take place through a dedicated communication channel, which should provide low latency.

Rocky Linux and Veeam Software Appliance – the foundation of the new architecture

The most exciting moment was when Veeam Software Appliance was presented – a ready-to-use, integrated environment based on Rocky Linux, built according to the Just Enough OS philosophy.
The Veeam team announced a complete transition from traditional Windows installations to software appliances, which are:

  • pre-configured and pre-hardened in accordance with DISA STIG guidelines,
  • automatically updated through Veeam repositories (both the OS and the application),
  • ready to be deployed in an all-in-one model with the option of immutable backups and full support for cloud backups.

The words spoken on stage perfectly summed up this approach:

“Backup should not be an IT project. It should be a ready-to-use product.”

The new architecture eliminates manual configurations, reduces the risk of errors, and dramatically increases the level of security.
This is the first step towards backup environments fully managed like enterprise-class appliances.

3 Cloud4You
Fig. 2. Guest operating system selection – Rocky Linux (64-bit) when creating a virtual machine in the VMware ESXi 8.0 U2 environment.

RBAC and SSO – granular control and Zero Trust in practice

Veeam announced a complete redesign of the permissions system (RBAC) during the security presentation.
The new model allows for the creation of custom user roles with precisely defined permission scopes – from the repository level to individual virtual machines.

Combined with SSO (Single Sign-On) integration through Microsoft Entra ID, Okta, or other identity systems, Veeam is moving closer to the Zero Trust Backup Infrastructure model.

This is not a cosmetic change, but an entirely new foundation for operational security.
As emphasized at the conference, RBAC in v13 is not an add-on – it is a core element of the system.

4 Cloud4You
Fig. 3. “Overview” dashboard in Veeam v13 – central platform view with information on compliance, detected malware anomalies, server status, and workload protection.

Universal CDP – continuous protection, independent of the platform

An important announcement was Universal CDP (Continuous Data Protection). Previously, this mechanism was available exclusively for VMware vSphere Enterprise Plus, but now it operates at the operating system level – for Windows, Linux, as well as cloud environments.

Thanks to agent-based replication, Veeam enables RPOs measured in seconds, regardless of the hypervisor. This is a major step forward for companies that require high service availability and are planning Disaster Recovery as a Service (DRaaS) deployments.

5 2 Cloud4You
Fig. 4. Universal CDP operation diagram in Veeam v13 – data replication using Source and Target CDP Proxy and I/O Filter.

Cloud and hybrid repositories – flexibility without compromises

The Scale-out Backup Repository (SOBR) mechanism in v13 has been significantly expanded, making it a key element of modern backup architectures based on the hybrid cloud model

The new version of Veeam Data Platform v13 introduces:

  • direct backup to object storage (S3, Azure Blob, IBM Cloud) without local buffering,
  • support for Immutable Storage (Amazon S3 Object Lock, Azure Blob Immutable Storage),
  • expanded Scale-out Backup Repository (SOBR) with hybrid tiering,
  • and the ability to automatically move older backups to the archive tier in the cloud.

In practice, this means the ability to combine local (on-premises) repositories with cloud resources within a single logical repository.
Thanks to this, administrators can dynamically manage the flow of data between tiers, depending on the age of the backup, its priority, or storage cost.

The result? Lower local storage consumption and even greater resilience against ransomware.

6 Cloud4You
Fig. 5. Layered data protection model in Veeam – from the production environment to offsite with immutability and air-gap protection.

New interface and web client – backup that looks like it belongs in the 21st century

Veeam has also taken care of the visual aspects – the VBR console has been completely redesigned. The modernized web interface, referred to as the “Aurora Theme”, complies with WCAG and VPAT standards, supports dark mode, and was built with browsers in mind.
The new “thin client” replaces the classic console, although the latter has also received a facelift – it is now based on Microsoft .NET UI/UX and finally scales properly in RDP sessions (which many administrators welcomed with relief).

This is not just cosmetic, but a foundation for future full backup management from a browser.

Changes to retention and cleanup of legacy features

One of the more widely discussed announcements was the confirmation that Veeam v13 is abandoning restore point-based retention. From now on, a time-based model – GFS – will be used, which better meets compliance and long-term data retention requirements.

Along with this change, Veeam is removing a number of outdated features:

  • Reverse Incremental mode,
  • older AD authentication methods for Cloud Connect,
  • and support for Windows agents below version 6.0.

This is a clear signal that Veeam is striving to simplify the architecture and eliminate legacy code.

Ransomware? Veeam goes one step further

The issue of security was present throughout all the presentations during the conference. Veeam Backup & Replication v13 introduces a number of mechanisms protecting backup copies:
– Immutable Backup Orchestrator – active detection of attempts to modify backups,
– AES-256-GCM encryption as standard,
– MFA for the VBR console,
– and full compliance with ISO 27001:2025, GDPR Art. 32, and NIST SP 800-207 standards.

Partnerships with SIEM providers (CrowdStrike, Splunk, IBM QRadar) will enable the integration of Veeam logs in CEF format. This is another step towards enterprise-class cyber resilience.

Our conclusions after VeeamON 2025

The VeeamON 2025 conference in San Diego clearly confirmed the direction in which the data protection industry is heading:
from simple backup creation to integrated management of an organization’s cyber resilience.
In the latest version of Veeam Backup & Replication v13, backup is no longer treated as a passive element of the IT infrastructure, but as an active component of the security system that interacts with monitoring, analysis, and automated response tools.

The new architecture of the solution is based on Rocky Linux and the concept of VSA/VIA appliances and symbolizes the transition from complex configuration environments to a simplified, scalable, and secure-by-design model.
The deployment of ready-to-use, pre-configured appliances eliminates human errors, speeds up deployment, and allows organizations to focus on their data protection strategy rather than managing backup infrastructure.

In turn, native High Availability support, the expanded RBAC mechanism, and integration with SSO and external identity providers clearly align with the Zero Trust Architecture philosophy, which is becoming the security standard in modern IT environments.
Backup is no longer an autonomous system and is becoming part of a cohesive organizational security ecosystem.

The development of cloud and hybrid repositories (SOBR) is also significant.
Thanks to the ability to create hybrid backup architectures combining local and cloud resources, companies can more effectively balance costs, ensure compliance with RODO regulations, and create long-term, immutable data copies resistant to ransomware.

It is worth emphasizing that Veeam continues the trend of automating security processes through Veeam Intelligence and AI mechanisms, which support event analysis, anomaly detection, and automated remediation.
This is an important step towards autonomous systems that not only respond to incidents, but can also prevent them.

Protect your data with Cloud4You – Veeam Gold Partner

As an Official Veeam Gold Partner, Cloud4You provides comprehensive implementation, configuration, and support for Veeam Backup & Replication solutions – both in local and cloud environments.

We help companies create secure, resilient, and compliant backup architectures based on the latest Veeam v13 technology.

Contact us!

Read more

Related articles

View all articles