How to Configure Veeam Backups with S3-Compatible Object Storage

TL;DR
Veeam Backup and Replication works natively with any S3 API compatible target, which means you can point it at ZATA Object Storage instead of paying hyperscaler egress fees.
The configuration path is straightforward: create a bucket, generate access keys, add an Object Storage Repository in Veeam, then attach it to a Scale Out Backup Repository as the Capacity Tier.
Pairing performance tier (local) with an S3 capacity tier gives you the 3 2 1 rule without a second data center.
ZATA offers immutability, predictable pricing, and no egress lock in, which matters when a ransomware event forces a full restore at 2 a.m.
Total setup time for a working Veeam Backup S3 pipeline is under 30 minutes.
Introduction: Why Modern Backups Need Object Storage
Tape is slow. NAS fills up. Traditional SAN scales expensively. Meanwhile backup data keeps growing, retention windows keep stretching, and compliance auditors keep asking harder questions. Object storage solved this problem for the hyperscalers a decade ago, and Veeam has spent the last several releases making sure enterprise backup admins can benefit from the same architecture on their own terms.
If you run Veeam Backup and Replication and you have not yet moved cold and archival data off primary storage, you are leaving money on the table and adding risk to your recovery posture.
What Is Veeam Backup and Replication?
Veeam Backup and Replication is the flagship data protection platform used by most mid to large enterprises for protecting VMware, Hyper V, physical servers, Microsoft 365, and cloud workloads. It supports a layered repository model, which is what makes Veeam Backup S3 integrations possible.
Understanding S3 Compatible Object Storage
S3 compatible storage speaks the same API that AWS S3 uses. Any client that can talk to S3 (Veeam included) can talk to ZATA without code changes. You get flat namespace, HTTP based access, near infinite scale, and per object metadata. That last piece is what enables features like object lock and immutability, which are non negotiable for ransomware resilient backups.
Why Use ZATA with Veeam Backups?
Three reasons enterprise IT teams pick ZATA Object Storage as their Veeam target:
Predictable economics. Flat pricing with no egress charges*. Restoring a 40 TB dataset does not trigger a surprise invoice.
Performance. Low latency reads make active full and synthetic operations feel local.
India first, globally available. Data residency matters, and ZATA gives you regional control without giving up S3 API compatible storage semantics.
Prerequisites for Configuring Veeam with S3 Storage
Before you start, confirm:
Veeam Backup and Replication v12 or later
Network reachability from the Veeam server to the ZATA endpoint on port 443
A ZATA account with billing active
Admin rights inside Veeam
Step by Step Guide to Configure Veeam with S3 Compatible Object Storage
1. Creating an S3 Bucket in ZATA
Log into the ZATA console, open Buckets, click Create Bucket, name it something like veeam-capacity-tier-prod, pick your region, and enable Object Lock if you want immutability. Save.
2. Generating Access Keys and Secret Keys
Under Access Management, generate a new key pair scoped to that bucket. Copy the access key and secret key immediately. The secret is shown once.
3. Adding Object Storage Repository in Veeam
In the Veeam console, go to Backup Infrastructure → Backup Repositories → Add Repository → Object Storage → S3 Compatible.
| Field | Value |
|---|---|
| Service point | Your ZATA endpoint URL |
| Region | The region you picked |
| Credentials | Paste your ZATA access and secret keys |
| Bucket | The bucket you just created |
| Folder | Create a new folder, for example veeam |
Enable Make recent backups immutable and set a retention window that matches your compliance policy.
4. Configuring Scale Out Backup Repository (SOBR)
Create a new Veeam Scale Out Backup Repository. Add your local performance extent (usually a fast disk array) as the Performance Tier, then add the ZATA repository you just created as the Capacity Tier.
5. Enabling Capacity Tier and Backup Policies
Choose your tiering mode:
Copy mode sends a copy of every backup to ZATA immediately for offsite protection.
Move mode offloads older restore points to ZATA to free local disk.
Both is what most enterprises actually want.
Point your backup jobs at the SOBR and run one to validate.
Best Practices for Veeam Backups on S3 Compatible Storage
Turn on immutability. It is the single most effective control against ransomware encrypting your backups.
Use per job encryption with keys you control.
Keep an eye on the offload window during business hours.
Test restores monthly. A backup you have never restored is not a backup.
Security and Compliance Considerations
Enable TLS everywhere, rotate access keys quarterly, restrict bucket access by IP where possible, and log every access event. For regulated workloads, immutability plus WORM style object lock covers most audit requirements.
Common Configuration Issues and Troubleshooting Tips
Connection failures: check DNS resolution and firewall rules for port 443 to the ZATA endpoint.
Access denied: the key pair is scoped to the wrong bucket, or object lock permissions are missing.
Slow offload: you are bandwidth constrained, not storage constrained. Check WAN throughput.
Benefits of Using ZATA for Veeam Backup Workloads
Scalable, S3 API compatible, immutable, no egress fees*, India based data residency, and priced for enterprise backup volumes rather than transactional workloads. That combination is why teams building modern data protection solutions choose ZATA.
Conclusion
Modernizing enterprise backup storage does not require a rip and replace. Veeam already knows how to talk to S3 compatible backup storage. ZATA gives you the target. Thirty minutes of configuration replaces tape libraries, cuts your storage bill, and gives you ransomware resilient backups with immutability built in.
Ready to configure Veeam with S3 object storage on ZATA?
Spin up your first bucket and start protecting workloads today.





