Incorporating a Microsoft Azure Blob Storage repository without immutability requires connecting to the Azure Blob Storage service to store and manage objects without implementing immutability policies.

When adding Microsoft Azure Blob storage, different storage account types can be used for Veeam Backup for Microsoft 365.

Performance Tier Account Type Services Access Tier
Standard General-purpose V2 Blob Hot, Cool, Archive
General-purpose V1 Blob N/A
Blob Storage Block Blob and append blob Hot, Cool, Archive
Premium Block Blob Storage Block Blob and append blob N/A

Note:

The Archive tier supports only Backup copy jobs.

We will add Azure Blob Storage, which lacks immutability, to our Veeam Backup for Microsoft 365 Infrastructure in the following steps.

1. Sign in to the Azure portal with a global admin account.

https://portal.azure.com

2. On the Azure services page, select +Create resource.

3. Search and select the storage account on the Create a resource page.

4. Click Create on the Storage account page.

5. In the Basics tab, under Project details, ensure the correct subscription is selected.

6. Under the Project details, click Create New to create a new resource group.

7. Under Instance details, type the name for the new storage account.

8. Select the Region for the new storage account.

9. Select Azure Blob Storage or Azure Data Lake Storage Gen 2 as the Preferred storage type.

10. Select Standard as Performance.

11. Select Locally-redundant storage (LRS) as Redundancy.

Note:

Veeam Backup & Replication supports all types of Azure Storage redundancy.

12. Click Next.

13. In the Advanced tab, under Security, keep the default settings.

14. Under Security, ensure that you unselect Enable Hierarchical Namespace.

15. Under Access protocols, keep the default settings.

16. Under Blob storage, select Cool as the Access tier.

17. Under Azure files, keep the default settings.

18. Click Next.

19. In the Networking tab, under Networking connectivity, select Enable for the Public network access.

20. Select Enable from all networks for the public network access scope.

21. When a customer has an ExpressRoute or Site-to-Site VPN connecting directly on-premises to Azure, you can create private endpoints for the storage account and turn off the public endpoint. Ensures the blob container is accessible only on the organization’s site.

22. Under the Network routing, keep the default settings and click Next.

23. In the Data protection tab, under Recovery, unselect Enable Point-in-time restore for containers.

24. Unselect Enable soft delete for blobs.

25. Unselect Enable soft delete for containers.

26. Unselect Enable soft delete for file shares.

27. Under Tracking, unselect Enable versioning for blobs.

28. Unselect Enable blob change feed.

29. Under Access control, unselect Enable version-level immutability support.

30. Click Next.

31. In the Encryption tab, under the Encryption type, select Microsoft-managed keys (MMK).

32. Under Enable support for customer-managed keys, select Blobs and files only.

33. Ensure unselect Enable infrastructure encryption.

34. Click Next.

35. In the Tags tab, you can specify the Resource Manager tags on the Tags tab to help organize your Azure resources.

36. Click Next.

37. In the Review + create tab, click Create.

38. Creating the new storage account may take a few minutes.

39. Click Go to the resource.

40. On the newly created storage account page, under Security + networking, select Access keys.

41. On the Access keys page, under key1, select Show Key and copy the storage account name and key of key1. We need them for Veeam storage repository settings later.

42. On the newly created storage account page, under Data storage, select Containers.

43. On the Containers page, click +Add container.

44. On the new container page, enter a name for your new container and click Create.

45. Verify the new container was created.

46. Login to the Veeam Backup for Microsoft 365 Manager server.

47. Open the Veeam Backup for Microsoft 365 console and click Connect.

48. Select Backup Infrastructure on the Veeam Backup for Microsoft 36 Home page.

49. On the Backup Infrastructure page, select Object Storage Repositories.

50. Right-click Object Storage Repositories and click Add object storage.

51. On the Object storage repository name and description page, type Azure Blob Cool Tier as the Object storage repository name and click Next.

52. Select Backup to object storage on the Target location for your backups page and click Next.

53. On the Object storage type page, select Azure Blob and click Next.

54. On the Microsoft Azure Blob Storage type page, select Azure Blob Storage.

55. Click Add in Specify account credentials to connect to Microsoft Azure blob storage field.

56. Type the Azure storage account name in the Account field and paste key1 in the Shared key field (you copied them when you created the Azure storage account).

57. Click OK.

58. On the Microsoft Azure Storage Account page, select Azure Global (Standard) in the Region field and click Next.

59. On the Microsoft Azure blob container page, select an Azure Blob container (you created it previously when you created your Azure Storage Account and settings) and click Browse on Folder.

60. Click New Folder on the Select the folder page.

61. Type the name as the new folder name and click OK.

62. If you want to control the storage spend, select Limit object storage consumption, enter the storage size and click Next.

63. On the Backup proxy page, click Select in the Backup proxy or proxy pool field.

64. Select Proxy pool (or Proxy).

65. On the Select Backup Proxy page, select the backup proxy pool and click OK.

66. Click Next on the Backup proxy page.

67. On the Retention policy settings page, select the retention period in the Retention policy field.

68. Select the retention type.

Note:

The retention type of the object storage repository cannot be changed once set.

69. Click Advance.

70. On the Advance page, select how often the retention policy should be applied and click OK.

71. Click Next on the Retention policy settings page.

72. On the Data immutability and encryption page, select Encrypt backups stored in this repository and click Add.

73. On the Add Password page, enter the password in the Password and Verify Password fields.

74. Click OK.

75. Click Finish on the Data immutability and encryption page.

76. Verify that the new Azure Blob Cool Tier Repository has been added.

I hope you enjoy this post.

Cary Sun

X: @SifuSun

Web Site: carysun.com

Blog Site: checkyourlogs.net

Blog Site: gooddealmart.com

Amazon Author: Amazon.com/author/carysun