[{"data":1,"prerenderedAt":716},["ShallowReactive",2],{"blog-\u002Fen\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication":3,"blog-\u002Fen\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication-surround":513,"blog-\u002Fen\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication-certifications":573},{"id":4,"title":5,"body":6,"categories":496,"cover":498,"cover_contain":499,"credly_badge_id":500,"date":501,"description":502,"extension":503,"meta":504,"navigation":505,"path":506,"related_certifications":507,"seo":509,"slug":510,"stem":511,"__hash__":512},"blog\u002Fen\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication.md","Goal: 100%, Veeam Backup & Replication v12 Security",{"type":7,"value":8,"toc":484},"minimark",[9,14,18,21,24,30,33,43,48,51,62,66,69,107,126,129,136,140,143,150,227,230,236,373,375,381,397,418,422,425,481],[10,11,13],"h2",{"id":12},"real-world-use-case","Real-world use case",[15,16,17],"p",{},"You want to make your Veeam backups more reliable beyond the default settings: here are the Veeam Analyzer's recommendations and my additional improvements.",[15,19,20],{},"As an administrator and user of Veeam Backup & Replication since 2011, I've developed deep expertise in data protection best practices. Securing Veeam Backup & Replication v12 (version 12.3.1.3617) is a strong recommendation from the vendor, which provides a built-in security and compliance tool.",[15,22,23],{},"This security approach revolves around two main areas:",[15,25,26],{},[27,28,29],"strong",{},"Securing the infrastructure",[15,31,32],{},"Infrastructure security measures follow standard Windows hardening practices, including:",[34,35,36,40],"ul",{},[37,38,39],"li",{},"Secure operating system configuration",[37,41,42],{},"Access management",[15,44,45],{},[27,46,47],{},"Secure product configuration",[15,49,50],{},"Configuration measures specifically focus on protecting the Veeam B&R application itself, covering:",[34,52,53,56,59],{},[37,54,55],{},"Secure configuration of Veeam components",[37,57,58],{},"Data and communication encryption",[37,60,61],{},"Identity management and authentication",[10,63,65],{"id":64},"fundamental-prerequisites","Fundamental prerequisites",[15,67,68],{},"Before implementing this, it was essential to make sure that:",[34,70,71,74,77,80,83,86,89,92,95,98,101,104],{},[37,72,73],{},"Access to the server is locked down to prevent unauthorized physical access",[37,75,76],{},"The server still has Microsoft support (this ensures access to security patches)",[37,78,79],{},"The server has sufficient resources",[37,81,82],{},"The server has dedicated bandwidth for data transfers (backup and restore)",[37,84,85],{},"The server is either in a dedicated management domain OR in a workgroup (standalone).",[37,87,88],{},"The server is protected by a security solution (ideally an XDR-type solution)",[37,90,91],{},"The server is dedicated to Veeam software (uninstall unnecessary third-party tools or Veeam plugins)",[37,93,94],{},"The server is in a separate broadcast domain (physical or virtual)",[37,96,97],{},"The server is filtered by a physical firewall and only allows what's strictly necessary",[37,99,100],{},"The server is only accessible via the server's management console AND via a third-party bastion-type solution (no RDP), with logging",[37,102,103],{},"The server is monitored for connections (Veeam console), via syslog (for the SIEM).",[37,105,106],{},"Secret management (encryption key) is handled in a dedicated, externalized KMS",[15,108,109,110,117,118,125],{},"Some of these principles are part of the Zero Trust model; Veeam illustrates this perfectly ",[111,112,116],"a",{"href":113,"rel":114},"https:\u002F\u002Fwww.veeam.com\u002Fblog\u002Fzero-trust-data-resilience.html",[115],"nofollow","at the following link",". For a Windows installation, the ",[111,119,122],{"href":120,"rel":121},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fwindows\u002Fsecurity\u002Foperating-system-security\u002Fdevice-management\u002Fwindows-security-configuration-framework\u002Fsecurity-compliance-toolkit-10",[115],[27,123,124],{},"Security Compliance Toolkit (SCT)"," tool can help you meet Veeam's recommendations more quickly.",[15,127,128],{},"From that point on, I implemented the measures below, to reach our 100% score:",[15,130,131],{},[132,133],"img",{"alt":134,"src":135},"","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication\u002F908a812a8e.png",[10,137,139],{"id":138},"summary-of-the-analyzers-best-practices","Summary of the Analyzer's best practices",[15,141,142],{},"Here are the 35 remediation steps I deployed via GPO:",[144,145,147],"h3",{"id":146},"backup-infrastructure-security",[27,148,149],{},"🔐 Backup infrastructure security",[34,151,152,159,164,169,175,181,187,192,199,204,210,215,221],{},[37,153,154,155,158],{},"The ",[27,156,157],{},"Remote Desktop Service (TermService)"," service is disabled.",[37,160,154,161,158],{},[27,162,163],{},"Remote Registry (RemoteRegistry)",[37,165,154,166,158],{},[27,167,168],{},"Windows Remote Management (WinRM)",[37,170,154,171,174],{},[27,172,173],{},"Windows firewall"," is enabled.",[37,176,177,180],{},[27,178,179],{},"SMBv3 signing and encryption"," are enabled.",[37,182,183,186],{},[27,184,185],{},"WDigest credential caching"," is disabled.",[37,188,154,189,158],{},[27,190,191],{},"Web Proxy Auto-Discovery (WinHttpAutoProxySvc)",[37,193,194,195,198],{},"Outdated versions of ",[27,196,197],{},"SSL and TLS"," are disabled.",[37,200,201,186],{},[27,202,203],{},"Windows Script Host",[37,205,154,206,209],{},[27,207,208],{},"SMBv1"," protocol is disabled.",[37,211,154,212,209],{},[27,213,214],{},"LLMNR",[37,216,154,217,220],{},[27,218,219],{},"LSASS"," service is enabled\u002Fconfigured to run as a protected process.",[37,222,154,223,226],{},[27,224,225],{},"NetBIOS"," protocol is disabled on all network interfaces.",[228,229],"hr",{},[144,231,233],{"id":232},"️-product-configuration",[27,234,235],{},"⚙️ Product configuration",[34,237,238,244,250,255,260,266,273,279,286,293,299,305,311,317,323,330,336,342,349,355,361,366],{},[37,239,240,243],{},[27,241,242],{},"MFA"," is enabled for the backup console.",[37,245,246,249],{},[27,247,248],{},"Immutable or offline (air-gapped)"," media are used.",[37,251,252,174],{},[27,253,254],{},"Password loss protection",[37,256,257,180],{},[27,258,259],{},"Email notifications",[37,261,262,265],{},[27,263,264],{},"Configuration backup"," is enabled and encrypted.",[37,267,268,269,272],{},"All backups follow the ",[27,270,271],{},"3-2-1"," rule.",[37,274,275,278],{},[27,276,277],{},"Reverse incremental"," backup mode is avoided.",[37,280,281,282,285],{},"Backups to ",[27,283,284],{},"cloud repositories"," are encrypted.",[37,287,288,289,292],{},"Unknown Linux servers are ",[27,290,291],{},"not automatically trusted",".",[37,294,295,296,292],{},"The configuration backup ",[27,297,298],{},"is not stored on the backup server",[37,300,301,304],{},[27,302,303],{},"Host-to-proxy traffic encryption"," is enabled in network transport mode.",[37,306,307,310],{},[27,308,309],{},"Hardened repositories"," are not hosted on virtual machines.",[37,312,313,316],{},[27,314,315],{},"Network traffic encryption"," is enabled on the backup network.",[37,318,319,322],{},[27,320,321],{},"Password authentication"," is disabled on Linux servers.",[37,324,325,326,329],{},"Backup services run under the ",[27,327,328],{},"LocalSystem"," account.",[37,331,332,335],{},[27,333,334],{},"Encryption credentials and passwords"," are renewed at least once a year.",[37,337,154,338,341],{},[27,339,340],{},"SSH server"," is disabled on hardened repositories.",[37,343,344,345,348],{},"S3 Object Lock's ",[27,346,347],{},"Governance mode"," doesn't guarantee true immutability.",[37,350,154,351,354],{},[27,352,353],{},"latest product updates"," are installed.",[37,356,154,357,360],{},[27,358,359],{},"PostgreSQL"," server is configured according to recommendations.",[37,362,363,365],{},[27,364,309],{}," are not used as backup proxy servers.",[37,367,368,369,372],{},"Recommendations on ",[27,370,371],{},"encryption password length and complexity"," are followed.",[228,374],{},[144,376,378],{"id":377},"recommendation-not-applied",[27,379,380],{},"🚫 Recommendation not applied",[34,382,383],{},[37,384,385,386,292,389,392,393,396],{},"The backup server ",[27,387,388],{},"should not be part of the production domain",[390,391],"br",{},"\n→ ",[27,394,395],{},"Waived"," (justification): Uses a dedicated management domain.",[15,398,399,400,292,404,406,411,412,417],{},"All the explanations are available ",[111,401,116],{"href":402,"rel":403},"https:\u002F\u002Fhelpcenter.veeam.com\u002Fdocs\u002Fbackup\u002Fvsphere\u002Fbest_practices_analyzer.html?ver=120",[115],[390,405],{},[111,407,410],{"href":408,"rel":409},"https:\u002F\u002Fwww.veeam.com\u002Fblog\u002Fsecurity-compliance-analyzer.html",[115],"Veeam One"," can also help you, as can the ",[111,413,416],{"href":414,"rel":415},"https:\u002F\u002Fbp.veeam.com\u002Fvbr\u002F",[115],"best practices"," site.",[10,419,421],{"id":420},"conclusion","Conclusion",[15,423,424],{},"Adopting Veeam's recommendations fits well with a simple but well-controlled architecture. The backup server's criticality warrants special attention, since it's essential in the event of an incident. We could also mention recommendations not covered by the Veeam Analyzer:",[34,426,427,433,439,445,451,457,463,469,475],{},[37,428,429,432],{},[27,430,431],{},"Externalizing the database",": Migration to a dedicated PostgreSQL server",[37,434,435,438],{},[27,436,437],{},"Database hardening",": Changing default credentials and restricting access",[37,440,441,444],{},[27,442,443],{},"Proxy isolation",": Deployment on a separate machine (non-Windows environment)",[37,446,447,450],{},[27,448,449],{},"Network hardening",": Stronger filtering with restricted access to critical resources only via the proxy",[37,452,453,456],{},[27,454,455],{},"Stronger encryption at rest",": Encrypting all volumes (not just Veeam files).",[37,458,459,462],{},[27,460,461],{},"Advanced backup strategy",": Implementing the 3-2-1-1-0 rule, complemented by SureBackup (systematically and manually testing backups if SureBackup isn't feasible)",[37,464,465,468],{},[27,466,467],{},"Air-gapped backup",": Storage physically disconnected from the network (tapes, rotating offline storage)",[37,470,471,474],{},[27,472,473],{},"Smart card authentication",": Strengthening account authentication (YubiKey)",[37,476,477,480],{},[27,478,479],{},"Documentation and procedures",": Detailed disaster recovery plan (DRP) with documented restore procedures (Veeam failover).",[15,482,483],{},"The architecture would become more complex but would significantly strengthen the security posture and resilience of the backup system. It's perhaps only after adapting this architecture that my score would truly be 100%…",{"title":134,"searchDepth":485,"depth":485,"links":486},2,[487,488,489,495],{"id":12,"depth":485,"text":13},{"id":64,"depth":485,"text":65},{"id":138,"depth":485,"text":139,"children":490},[491,493,494],{"id":146,"depth":492,"text":149},3,{"id":232,"depth":492,"text":235},{"id":377,"depth":492,"text":380},{"id":420,"depth":485,"text":421},[497],"Sécurité","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication\u002Ffd1cbd3a9e.png",false,null,"2025-08-18","Veeam Analyzer recommendations and additional improvements: from a simple architecture to a hardened security posture for Veeam v12.","md",{},true,"\u002Fen\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication",[508],"certificat-veeam-certified-engineer-vmce",{"title":5,"description":502},"objectif-100-securite-veeam-backup-replication","en\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication","FGMp2rwfUW_44wh7hMq_vHzs5P-7TIikq50E5i-44I0",[514,522,530,538,545,552,559,566],{"title":515,"path":516,"stem":517,"date":518,"cover":519,"categories":520,"children":-1},"ISO\u002FIEC 27001 Lead Implementer","\u002Fen\u002Fblog\u002Fcertificat-iso27001-lead-implementer","en\u002Fblog\u002Fcertificat-iso27001-lead-implementer","2026-03-05","\u002Fimages\u002Fblog\u002Fcertificat-iso27001-lead-implementer\u002F364fa30a2c.png",[521,497],"Certifications",{"title":523,"path":524,"stem":525,"date":526,"cover":527,"categories":528,"children":-1},"Achieving a 0% Exposure Score with Microsoft Defender Vulnerability Management","\u002Fen\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management","en\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management","2025-10-27","\u002Fimages\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management\u002Fe8a06eec09.png",[529,497],"Microsoft",{"title":531,"path":532,"stem":533,"date":534,"cover":535,"categories":536,"children":-1},"GitHub Copilot","\u002Fen\u002Fblog\u002Fcertificat-microsoft-github-copilot","en\u002Fblog\u002Fcertificat-microsoft-github-copilot","2025-08-28","\u002Fimages\u002Fblog\u002Fcertificat-microsoft-github-copilot\u002Fcf8333d63e.png",[521,537],"Code",{"title":539,"path":540,"stem":541,"date":542,"cover":543,"categories":544,"children":-1},"Take Back Control of Your Microsoft Directories with an Infrastructure as Code Approach","\u002Fen\u002Fblog\u002Freprenez-controle-annuaires-microsoft-infrastructure-as-code","en\u002Fblog\u002Freprenez-controle-annuaires-microsoft-infrastructure-as-code","2025-08-25","\u002Fimages\u002Fblog\u002Freprenez-controle-annuaires-microsoft-infrastructure-as-code\u002F96c873f6c1.png",[529,497],{"title":546,"path":547,"stem":548,"date":549,"cover":550,"categories":551,"children":-1},"Optimal Hardening of Active Directory Security","\u002Fen\u002Fblog\u002Fdurcissement-optimal-securite-active-directory","en\u002Fblog\u002Fdurcissement-optimal-securite-active-directory","2025-08-13","\u002Fimages\u002Fblog\u002Fdurcissement-optimal-securite-active-directory\u002F9dc4acd9d6.png",[497],{"title":553,"path":554,"stem":555,"date":556,"cover":557,"categories":558,"children":-1},"Full Application of the Zero Trust Model in Microsoft 365","\u002Fen\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365","en\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365","2025-08-10","\u002Fimages\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365\u002Fcea858f515.png",[497],{"title":560,"path":561,"stem":562,"date":563,"cover":564,"categories":565,"children":-1},"Goal: 100%, Microsoft 365 Exposure Management","\u002Fen\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365","en\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365","2025-08-09","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365\u002Fe8a06eec09.png",[497],{"title":567,"path":568,"stem":569,"date":570,"cover":571,"categories":572,"children":-1},"Goal: 100% - Microsoft 365 Security at Its Maximum","\u002Fen\u002Fblog\u002Fobjectif-100-securite-microsoft365","en\u002Fblog\u002Fobjectif-100-securite-microsoft365","2025-08-01","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-microsoft365\u002Fac33e55464.jpg",[497],[574],{"id":575,"title":576,"body":577,"categories":706,"cover":707,"cover_contain":505,"credly_badge_id":708,"date":709,"description":710,"extension":503,"meta":711,"navigation":505,"path":712,"related_certifications":500,"seo":713,"slug":508,"stem":714,"__hash__":715},"blog\u002Fen\u002Fblog\u002Fcertificat-veeam-certified-engineer-vmce.md","Veeam Certified Engineer (VMCE)",{"type":7,"value":578,"toc":702},[579,581,584,587,694,697,699],[10,580,13],{"id":12},[15,582,583],{},"To design and troubleshoot reliable Veeam backup plans for my clients, I took the VMCE certification.",[15,585,586],{},"The \"Veeam Certified Engineer\" training path is designed for IT professionals responsible for Veeam Backup & Replication.\nThe course catalog covers the following modules:",[34,588,589,594,599,604,609,614,619,624,629,634,639,644,649,654,659,664,669,674,679,684,689],{},[37,590,591],{},[27,592,593],{},"Data protection strategies",[37,595,596],{},[27,597,598],{},"Risk scenarios",[37,600,601],{},[27,602,603],{},"Core components",[37,605,606],{},[27,607,608],{},"Initial security considerations",[37,610,611],{},[27,612,613],{},"Virtual machine backup",[37,615,616],{},[27,617,618],{},"Agent backup",[37,620,621],{},[27,622,623],{},"Unstructured data backup",[37,625,626],{},[27,627,628],{},"Backup data optimizations",[37,630,631],{},[27,632,633],{},"Immutability and hardened repositories",[37,635,636],{},[27,637,638],{},"Object storage",[37,640,641],{},[27,642,643],{},"Transport modes",[37,645,646],{},[27,647,648],{},"Backup copies",[37,650,651],{},[27,652,653],{},"Scale-out Backup Repository",[37,655,656],{},[27,657,658],{},"Moving or copying backups",[37,660,661],{},[27,662,663],{},"Replication",[37,665,666],{},[27,667,668],{},"Verifying recoverability",[37,670,671],{},[27,672,673],{},"Veeam Backup Enterprise Manager",[37,675,676],{},[27,677,678],{},"Incident Response Planning",[37,680,681],{},[27,682,683],{},"Recovery scenarios and features",[37,685,686],{},[27,687,688],{},"Enacting a recovery",[37,690,691],{},[27,692,693],{},"Veeam Data Platform",[15,695,696],{},"The training takes about 4 days.\nYou should then allow around 1h45 for the certification exam itself: Veeam Certified Engineer.",[10,698,421],{"id":420},[15,700,701],{},"The Veeam Certified Engineer certification validates comprehensive expertise in Veeam Backup & Replication: data protection strategies, VM and agent backup, optimization, immutability, and replication. With about 4 days of training and a 1h45 exam, it covers both the implementation and management of recovery scenarios. A key certification for anyone responsible for data protection in a virtualized environment.",{"title":134,"searchDepth":485,"depth":485,"links":703},[704,705],{"id":12,"depth":485,"text":13},{"id":420,"depth":485,"text":421},[521],"\u002Fimages\u002Fblog\u002Fcertificat-veeam-certified-engineer-vmce\u002F4dd7c37e93.png","21923881-9ebd-4f03-9e06-0af121aea5cb","2024-08-24","Veeam Certified Engineer (VMCE): Pearson VUE certification, completed as part of my professional watch in cybersecurity and IT.",{},"\u002Fen\u002Fblog\u002Fcertificat-veeam-certified-engineer-vmce",{"title":576,"description":710},"en\u002Fblog\u002Fcertificat-veeam-certified-engineer-vmce","xL_9knEsJtR3do_4Ios2ZA_3mQ9g5eR5U_k_xokQEjM",1786644869456]