[ Applies to ] StorageGuard / Veeam Backup & Replication / Data Protection (Backup)
This article lists the recommended baseline checks for Veeam Backup & Replication. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
Veeam Backup & Replication (VBR) provides backup, replication and recovery for virtual, physical and cloud workloads, with features such as immutable repositories, encryption and automated recovery verification.
Why hardening Veeam Backup & Replication matters
Backup servers are a common ransomware target. Securing VBR's credentials, repositories, encryption and verification settings protects backup data and ensures clean, tested recovery points are available.
Recommended baseline checks
The baseline below contains 81 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-F9311T211V01 | Approved AD domain |
| SG-F8324T211V01 | Approved cloud credentials |
| SG-F1148T211V01 | Approved DNS servers |
| SG-C0044T211V01 | Approved KMS server |
| SG-C0406T211V01 | Approved SMTP server |
| SG-C0015T211V01 | Approved Syslog servers |
| SG-F4959T211V01 | Approved system credentials |
| SG-F3426T211V01 | Assets without SureBackup verification |
| SG-C0331T211V01 | Audit log retention |
| SG-F6691T211V01 | Backup encryption (standalone agent) |
| SG-C0063T211V01 | Backup image encryption |
| SG-F6542T211V01 | Backup Immutability Period (Hardened Linux) |
| SG-C0029T211V01 | Centralized log server |
| SG-F9876T211V01 | Clean backup existence |
| SG-C0197T211V01 | Client IP ACL |
| SG-F7225T211V01 | Cloud gateway certificate - Authority |
| SG-F4319T211V01 | Cloud gateway certificate - expiration |
| SG-F5803T211V01 | Cloud gateway certificate - Self-Signed |
| SG-F5397T211V01 | Cloud gateway NAT usage |
| SG-C0713T211V01 | Configuration Backup enabled |
| SG-F7884T211V01 | Configuration backup recent execution |
| SG-C0709T211V01 | Configuration Backup retention |
| SG-C0712T211V01 | Configuration Backup schedule |
| SG-C0080T211V01 | Data in-transit encryption |
| SG-F3293T211V01 | Data retention period |
| SG-F7817T211V01 | DNS server configuration |
| SG-F3925T211V01 | DNS server redundancy |
| SG-C0401T211V01 | Email notification security (TLS) |
| SG-C0402T211V01 | Email notification status |
| SG-C0067T211V01 | Encrypted configuration backup |
| SG-C0571T211V01 | Encryption password - backup protection |
| SG-C0600T211V01 | End of support |
| SG-C0162T211V01 | Expired SSL certificate |
| SG-F5865T211V01 | External configuration Backup storage |
| SG-F6854T211V01 | Failover plan status |
| SG-C0177T211V01 | FIPS mode status |
| SG-F2396T211V01 | Four-Eyes Authorization Licensing |
| SG-F2340T211V01 | Four-Eyes authorization status |
| SG-C0600T211V02 | Future end of support |
| SG-C0049T211V01 | KMS server configuration |
| SG-C0052T211V01 | KMS server redundancy |
| SG-C0538T211V01 | Malware detection - enable file extension auto update |
| SG-C0539T211V01 | Malware detection - enable file system activity analysis |
| SG-C0540T211V01 | Malware detection - enable notification |
| SG-C0541T211V01 | Malware detection - enable preventive backup |
| SG-C0542T211V01 | Malware detection - enable suspicious encryption monitoring |
| SG-C0570T211V01 | Malware detection - suspicious encryption monitoring sensitivity |
| SG-C0234T211V01 | Maximum password age |
| SG-C0239T211V01 | Multi-factor authentication |
| SG-C0085T211V01 | Network traffic encryption |
| SG-C0231T211V01 | Non-default local users |
| SG-F9673T211V01 | Password loss protection |
| SG-C0293T211V01 | Protected recovery copies |
| SG-F6033T211V01 | Proxy encrypted data transfer |
| SG-F9739T211V01 | Recent YARA scan (SureBackup) |
| SG-F9712T211V01 | Recovery token lifetime |
| SG-F4124T211V01 | Repository access permission |
| SG-F3072T211V01 | Secure restore settings |
| SG-F7533T211V01 | Security Analyzer recent execution |
| SG-C0711T211V01 | Security notifications status |
| SG-C0447T211V01 | Self-signed certificate |
| SG-F1607T211V01 | Single-use credentials (Linux repository) |
| SG-C0011T211V01 | SMTP authentication |
| SG-C0146T211V01 | SMTP enabled |
| SG-C0058T211V01 | SNMP community default string |
| SG-C0155T211V01 | SNMP service disabled |
| SG-F5486T211V01 | SureBackup DiskContentValidation |
| SG-F9692T211V01 | SureBackup Recovery testing |
| SG-F9087T211V01 | SureBackup scan notification |
| SG-F2049T211V01 | SureBackup Scheduled |
| SG-F2659T211V01 | SureBackup VM scan settings |
| SG-C0714T211V01 | SureBackup without Malware scan |
| SG-F2522T211V01 | SureBackup YARA scan |
| SG-C0306T211V01 | Syslog communication protocol |
| SG-C0019T211V01 | Target OS version |
| SG-C0448T211V01 | Trusted certificate-authority (CA) |
| SG-F9378T211V01 | Trusted hosts policy |
| SG-C0116T211V01 | Unapproved admin users |
| SG-F4936T211V01 | Unapproved user groups |
| SG-F9788T211V01 | User role configuration |
| SG-F8297T211V01 | YARA rules for SureBackup |
Related components
A complete baseline also covers the components that manage, connect to or protect Veeam Backup & Replication. Review the configuration of:
- Veeam ONE
- Hardened Linux repositories
- Backup proxies and gateway servers
- Veeam Cloud Connect
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.