14 Veeam Backup & Replication 13.1 is now available, with enhancements spanning identity protection, hypervisor support, malware detection, backup infrastructure and operational automation. The release includes automated Active Directory forest recovery, additional hypervisor integrations, broader workload protection and new capabilities within Veeam Intelligence. For storage and data protection teams, several repository changes deserve equal attention. Veeam 13.1 expands how immutable object storage can be used during recovery, adding read-only repository access from a second backup server, scale-out options for unstructured data, clearer capacity reporting and additional threat-detection workflows. These updates make the backup repository a more active part of the recovery process. Instead of focusing only on where backups are stored, organizations can build workflows around independent recovery access, integrity validation, forensic investigation and capacity growth. Veeam 13.1 object storage updates at a glance The object storage and repository changes most relevant to backup architects include: Read-only access to immutable object storage from a second Veeam backup server Object storage extents for scale-out NAS and unstructured data backup repositories Malware analytics, Indicators of Compromise scanning and Threat Hunter support for unstructured data Reporting that distinguishes logical backup size from actual object storage consumption New archive copy and minimum immutability options Gateway mode for IBM AIX and Oracle Solaris backups sent to S3-compatible object storage Individually, these features address specific operational problems. Together, they support a broader shift toward backup architectures designed around recoverability rather than backup completion alone. Read-only object storage supports independent recovery operations One of the most useful additions in Veeam 13.1 is read-only access to immutable object storage repositories. A second Veeam Backup & Replication server, such as one located at a disaster recovery site, can connect to an immutable repository already managed by the production backup server. The second server cannot write to or modify the stored data. It can use the repository for restores, recoverability checks and Data Integration API-based forensic or ransomware scans without assuming ownership or disrupting active backup jobs. Previously, accessing the repository from another backup server could require transferring repository ownership. That introduced coordination requirements and made regular testing more difficult, particularly when the production environment needed to remain available. Read-only access provides a cleaner separation between production backup operations and recovery activities. An organization could maintain a secondary Veeam server with access to an immutable repository and use it to: Test restores without changing the production repository Investigate backup data following suspicious activity Validate recovery points from a separate administrative environment Restore data if the primary Veeam server becomes unavailable The option applies to immutable object storage repositories, and read-only access is selected when the repository is connected on the second server. The feature should still be supported by a deliberate recovery architecture. Separate credentials, network segmentation, multi-factor authentication and documented access procedures remain important. Veeam’s own guidance reinforces this: the credentials used to add the repository on the second server should themselves carry read-only permissions, because full-access credentials can lead to unpredictable behavior. Read-only mode limits what the secondary Veeam server can do, but it does not independently isolate the underlying storage network or credentials. Object storage can scale unstructured data protection Veeam 13.1 also expands the role of object storage in protecting NAS and other unstructured data. Object storage can now be used as an extent within the scale-out backup repositories used for unstructured data backup. Capacity can be added incrementally across on-premises or cloud-based object storage deployments without redesigning the repository or interrupting existing jobs. This is important because unstructured data rarely grows in predictable increments. File shares, video repositories, research data, engineering files and application-generated content can quickly outgrow a fixed backup target. A scale-out repository allows storage capacity to expand alongside the protected data while keeping backup management within Veeam. Veeam 13.1 introduces several related improvements: Grandfather-Father-Son retention can be configured directly within NAS and object storage backup jobs. Weekly, monthly and yearly restore points can reference existing backup data rather than requiring additional full copies. Files larger than 32 MB can be processed incrementally, so Veeam transfers only modified portions instead of reading the entire file again. Access control list changes can be captured during incremental backups and reapplied during recovery. Additional source-side parallelism improves throughput when protecting large individual file shares. Unstructured data management and recovery receive fuller coverage in the Veeam web interface. The repository must still be sized for the required ingest rate, retention period and recovery throughput. Object storage removes many fixed-capacity limitations, but network bandwidth, gateway resources and the performance of the underlying storage nodes continue to determine how quickly data can be protected and recovered. Malware detection extends to unstructured backups Unstructured data often contains a large percentage of an organization’s valuable information, but it can be difficult to monitor during a ransomware incident. Attackers may encrypt, rename or delete files across large shares while remaining unnoticed until users begin reporting inaccessible data. Veeam 13.1 extends malware detection to unstructured data workloads. File-level analytics can identify suspicious patterns such as mass renaming or deletion, while Indicators of Compromise scanning provides another signal for identifying potentially malicious activity. Veeam Threat Hunter also supports file-share and object-storage backups. Administrators can run automated post-backup scans or initiate on-demand inspections using signature detection and customizable YARA rules. These capabilities can help identify suspicious content and determine whether a recovery point should be considered for restoration. This creates a useful division of responsibilities within the backup architecture: Veeam monitors backup activity, analyzes data and helps identify appropriate recovery points. Immutable object storage prevents protected backup objects from being altered or deleted during their retention period. A secondary Veeam server can access the repository in read-only mode to perform investigation or recovery operations. No single control determines whether an organization can recover from ransomware. Detection helps teams understand what happened, immutability preserves usable recovery points, and testing confirms that those points can actually be restored within the required recovery window. Both the unstructured-data malware detection and the Threat Hunter capabilities are available with the Advanced Edition of the Veeam Universal License, so licensing should be reviewed as part of upgrade planning. Actual-size reporting improves object storage planning Object storage backup consumption can be difficult to estimate from logical backup sizes alone. Data reuse and other storage optimizations mean the amount shown for a backup chain may differ from the physical capacity consumed on the repository. Veeam 13.1 addresses this by displaying both values. “Backup size” represents the logical size, while “Actual size” shows the capacity consumed after optimizations. Administrators can view consumption for a specific repository tier or the combined amount stored across all tiers. This improves several common planning activities: Forecasting when an on-premises object storage cluster will need additional capacity Comparing logical data growth with physical repository consumption Understanding how much space individual backup chains occupy Evaluating retention changes before they are implemented Identifying unexpected consumption increases earlier The improvement is particularly useful for scale-out storage. Administrators can base expansion decisions on actual repository utilization instead of relying on estimates derived from protected capacity or logical backup size. It also provides better information for conversations between backup, infrastructure and finance teams. Backup administrators can explain what is consuming physical capacity, while storage administrators can plan expansion before the repository approaches operational limits. Archive controls provide more retention flexibility Veeam 13.1 introduces a Copy policy for the scale-out backup repository Archive Tier. With this policy, qualifying GFS restore points can be copied to an archive tier as soon as they are created, while the local version remains available on the Performance Tier until its normal expiration date. Copy and Move policies can be combined, allowing recent restore points to remain on faster storage while another copy is retained on lower-cost archive storage for compliance or long-term resilience. One design constraint is worth noting: the Copy policy applies only to Direct Archival configurations, meaning a scale-out backup repository with a Performance Tier and an Archive Tier. Configurations that include a Capacity Tier between the two do not support Copy mode and continue to rely on the existing Move policy. Archive repositories can also be configured with a minimum immutability period. Instead of keeping data immutable for its entire retention period, administrators can define a fixed period during which the data cannot be deleted or modified. After that period expires, the archive data can be managed according to the organization’s retention requirements. That flexibility requires careful policy design. A shorter immutability window may reduce capacity pressure, but it can also expose older recovery points to deletion while they are still operationally or legally important. The immutability period should account for: The time it may take to discover a compromise The number of clean historical restore points required Regulatory retention requirements Expected investigation and recovery timelines The cost and performance characteristics of the archive service Veeam’s direct archive options apply to supported archive-class services, such as Veeam Data Cloud Vault Archive, Azure Archive and Amazon S3 Glacier, rather than every S3-compatible repository. An on-premises object storage platform can therefore remain the primary immutable recovery layer while a separate archive service retains infrequently accessed data for longer periods. Gateway mode expands S3 backup options for Unix environments Many large enterprises continue to operate critical IBM AIX and Oracle Solaris systems. These environments are often isolated from the internet and separated from general-purpose storage networks. Veeam 13.1 adds Gateway mode when backing up AIX and Solaris agents to S3-compatible object storage. Backup and restore traffic can be routed through a gateway server assigned in Veeam instead of requiring every protected endpoint to communicate directly with the object storage system. This can simplify deployment in environments where: Unix systems cannot connect directly to the backup repository Firewall rules restrict endpoint access to storage networks Backup traffic must pass through a designated security zone Administrators want centralized control over object storage connectivity Direct internet access from protected systems is prohibited The gateway becomes an important part of the data path and should be sized accordingly. CPU, memory, network throughput and gateway availability can all affect backup and restore performance. Broader workload support raises the bar for the repository Veeam 13.1 adds native support for Citrix XenServer, XCP-ng and Sangfor aSV, while Platform9 and VergeOS join through the Universal Hypervisor API. The release also continues expanding recovery options across VMware, Hyper-V, Nutanix AHV, Proxmox VE and public cloud targets. The benefit is greater workload portability, but it also means that more data types may converge on the same backup infrastructure. Virtual machines, physical systems, cloud workloads, databases, file shares and identity systems can all generate different backup patterns. A repository designed primarily around one hypervisor may no longer be sufficient. Storage architects should evaluate: Aggregate ingest across all protected platforms Restore performance during concurrent recovery operations Capacity expansion without disruptive migrations Support for immutable direct-to-object backups Failure-domain and site-level resilience Administrative separation between production and recovery The ability to preserve backups during infrastructure changes Object storage can help decouple the backup repository from individual hypervisor decisions. Organizations can change or add virtualization platforms while maintaining a consistent S3-compatible storage foundation for protected data. What Veeam 13.1 means for Scality ARTESCA Scality ARTESCA provides an on-premises S3-compatible repository designed for backup and cyber resilience. ARTESCA is listed in the Veeam Ready program as a Veeam Ready Repository – Primary Target for Veeam Backup & Replication 13, with validated attributes that include object immutability, IAM and STS, Smart Object Storage API support and governance mode. The repository changes in Veeam 13.1 align with several ARTESCA use cases: Independent recovery access: Veeam’s read-only repository mode can support recovery testing and investigation from a secondary Veeam server while the immutable repository remains managed by the production server. Unstructured data growth: Object storage extents allow Veeam’s unstructured data repositories to expand horizontally as protected capacity increases. Storage-layer immutability: ARTESCA uses S3 Object Lock to preserve backup objects during their defined retention period, complementing Veeam’s malware analysis and recovery orchestration. On-premises control: Organizations can retain backup data within infrastructure they control while using standard S3-compatible workflows from Veeam. Operational visibility: Veeam’s actual-size reporting provides better information for planning ARTESCA capacity expansion and retention. Scality also offers the ARTESCA+ Veeam Unified Software Appliance, which combines Veeam Backup & Replication with ARTESCA object storage. The solution is listed as Veeam Ready for Veeam Backup & Replication 13 and can be deployed as a primary backup system or as a secondary repository with a standby Veeam instance. As with any platform update, organizations should validate the exact Veeam build, ARTESCA version and intended architecture against the current compatibility information before upgrading production systems. How to prepare for Veeam Backup & Replication 13.1 The value of the release will depend on how its new capabilities are incorporated into the recovery design. An upgrade alone does not create an independent or tested recovery path. Before deployment, backup and storage teams should: Identify the relevant changes. Determine which workloads, repositories and recovery processes will benefit from the update. Validate version compatibility. Confirm supported Veeam, storage software and appliance versions before changing production infrastructure. Review repository access. Decide whether a second Veeam server should connect to an immutable repository in read-only mode. Reassess retention and immutability. Make sure the configured immutability period protects data throughout the expected threat-discovery and recovery window. Model actual capacity requirements. Use Veeam’s new physical-consumption reporting to compare current usage with future data growth and retention. Test recovery at the required scale. A successful file restore does not prove that hundreds of virtual machines or a multi-terabyte application can be recovered within the required RTO. Document identity and network dependencies. Recovery procedures should account for unavailable domain services, compromised credentials, inaccessible DNS and isolated network segments. Building a more usable recovery layer Veeam Backup & Replication 13.1 extends protection across identity systems, hypervisors, cloud workloads, applications and unstructured data. Its object storage changes are significant because they address what happens after backup data has been written. Read-only repository access supports recovery operations outside the production backup server. Malware scanning provides more information about the integrity of unstructured data. Scale-out object storage extents accommodate continued data growth, while actual-size reporting and archive controls improve capacity and retention planning. For organizations using Scality ARTESCA, Veeam 13.1 reinforces an architecture in which Veeam manages protection and recovery workflows while ARTESCA provides the immutable S3 storage foundation. The practical objective remains the same: preserve clean recovery points, maintain access to them during an incident and prove that the environment can restore data at the speed the business requires. Frequently asked questions What is new in Veeam Backup & Replication 13.1 for object storage? Veeam 13.1 adds read-only access to immutable object storage from a second backup server, object storage extents for unstructured data repositories, actual-capacity reporting, additional archive controls and Gateway mode for AIX and Solaris backups. It also extends malware detection and Threat Hunter capabilities to unstructured backup data. Can a second Veeam server access an immutable object storage repository? Yes. Veeam 13.1 allows a second backup server to add an immutable object storage repository in read-only mode. The secondary server can perform restores, recoverability checks and supported forensic operations without modifying the data or taking ownership from the production server. Does Veeam 13.1 improve NAS backup to object storage? Yes. Object storage can be used as an extent in scale-out repositories for unstructured data backup. The release also adds GFS retention within NAS backup jobs, incremental processing for large files, improved single-share performance and additional malware detection. Does Veeam Backup & Replication 13.1 support Scality ARTESCA? Scality ARTESCA is Veeam Ready for Veeam Backup & Replication 13 and supports validated object storage features including immutability, IAM and STS, SOSAPI and governance. The exact Veeam 13.1 build and ARTESCA version should be confirmed against the latest compatibility information before production deployment.