Veeam Cloud Connect is a feature of Veeam Backup & Replication that lets organizations send backup copies or VM replicas from their on-premises environment to a service provider’s cloud infrastructure. It connects the customer’s Veeam server to provider-hosted cloud repositories or cloud hosts over a secure, encrypted channel. This enables off-site backup storage, VM replication, and cloud-based recovery without the cost of building a secondary data center. The customer keeps control over backup jobs, retention, and recovery. The provider manages the backend infrastructure.
-
Veeam Cloud Connect Explained
On the customer side, you keep running Veeam Backup & Replication as normal. On the provider side, the service exposes either cloud storage or virtualization resources, depending on your needs. That tenant/provider model is central to how the whole system holds together.
Cloud Connect operates in two functional modes. In cloud repository mode, the provider hosts the storage location where your backup copies land. Your data lives offsite, separate from your primary environment. In cloud host mode, the provider hosts virtualization infrastructure so you can create runnable VM replicas there, not just backup files. One mode is mainly about data protection. The other is mainly about keeping systems recoverable and online during a disaster.
An important clarification: Cloud Connect extends an existing Veeam strategy into a provider’s cloud. It does not function as a standalone backup product, and it does not replace the need for defined recovery objectives, tested restore procedures, or proper retention planning.
-
How Veeam Cloud Connect Works
The connection between your environment and the provider begins when your Veeam Backup & Replication server reaches out to the provider’s cloud gateway. Traffic moves through an encrypted SSL/TLS tunnel, so data in transit is protected before it ever reaches the repository or cloud host.
For backup jobs, the flow is direct. Your Veeam server runs the job, the data passes through the cloud gateway, and backup copies write to the cloud repository assigned to your tenant account. For replication, the flow adds a few steps. Your Veeam server sends a request to the cloud gateway. The gateway passes that request to the provider’s Veeam server. A TLS certificate is established, a secure channel opens, and VM data is transferred to the cloud host. During a declared disaster, you can fail over to those replicas.
Throughout all of this, the split between customer and provider responsibilities stays consistent. You manage job schedules, retention policies, and recovery actions. The provider manages the physical infrastructure, platform availability, and storage environment. Neither side needs to hand over operational control to the other.
-
What Are Provider-Hosted Repositories?
Provider-hosted repositories are the cloud storage locations where your backup data lives in Cloud Connect’s backup mode. Understanding them helps explain why the offsite model works the way it does.
When the provider sets up your tenant account, they assign a storage quota tied to a specific cloud repository. As your backup jobs run, that quota gets consumed. The provider can configure several types of backend storage behind that repository, including Linux-hardened repositories with immutability, scale-out backup repositories, and S3-compatible object storage such as Amazon S3, Microsoft Azure Blob Storage, Wasabi, and Veeam Data Cloud Vault.
Multi-tenant isolation is a key piece of this design. Even though many tenants may share the same provider infrastructure, each tenant’s data is logically separated. According to Veeam, tenants get their own folder and cannot see or access each other’s repositories. That separation matters for organizations in regulated industries and for MSPs managing backup services for multiple clients.
The practical benefit for businesses is that they avoid purchasing, securing, patching, and scaling another backup storage environment. The provider owns that responsibility.
-
Backup vs. Replication in Veeam Cloud Connect
Cloud Connect handles two distinct scenarios, and mixing them up leads to mismatched expectations about recovery.
Cloud Connect Backup Cloud Connect Replication What it stores Backup copies of VMs, agents, and workloads Runnable VM replicas Target Provider cloud repository Provider cloud host Primary goal Data protection and restore Fast failover and workload recovery Recovery type File-level or full VM restore Failover to live VM replica Supports VMware, Hyper-V, Veeam Agents VMware vSphere, Microsoft Hyper-V Backup is primarily about keeping recoverable copies of data. If something goes wrong, you restore from that copy. Replication is about keeping a runnable version of your VM in a provider’s cloud environment so that, if your production site fails, you can fail over quickly without rebuilding from scratch. Both are valid approaches, and many organizations use them together, depending on which workloads need faster recovery and which just need protection.
-
Common Recovery Use Cases
Cloud Connect’s value shows up most clearly in specific failure scenarios.
Ransomware recovery is probably the most commonly cited reason businesses move backups offsite. According to Veeam’s 2025 ransomware research, 89% of organizations had their backup repositories targeted by attackers. An off-site copy in a provider-managed repository, especially with optional immutable storage enabled, provides a clean recovery point that attackers cannot reach via the same path they used to compromise local systems.
Accidental deletion is less dramatic but equally disruptive. When local copies are gone, the cloud repository gives your team another place to pull file-level or full VM restores.
Local infrastructure outages due to hardware failures or site-level disruptions can take down both production systems and local backup storage simultaneously. A cloud repository stays available even if everything at the primary site is offline.
For replication users, disaster recovery failover means you can bring individual VMs or full site workloads online from cloud-hosted replicas. Tenants can fail over at the VM level or across groups of VMs, depending on the recovery scope.
Maintaining offline, encrypted, and regularly tested backups is a core recommended defense. Cloud Connect supports that recommendation, but testing your actual restore procedures still falls on your team to schedule and verify.
-
Security and Compliance in Veeam Cloud Connect
SSL encryption covers data in transit from your environment to the provider’s cloud gateway. At rest, encryption is available through provider configuration, and OTAVA includes end-to-end SSL encryption as part of our Cloud Connect service.
Immutable storage is the option most relevant to ransomware resilience. When enabled, backup files are locked for a defined retention period. They cannot be altered, deleted, or encrypted, even by an attacker who gains access to the storage environment. Veeam supports this through Linux hardened repositories on the provider side.
Multi-tenant isolation, as noted above, keeps your repository data separate from other tenants. For organizations in regulated industries, this matters. Cloud Connect can support compliance with HIPAA, PCI-DSS, and SOC 2 requirements, depending on how the service provider’s infrastructure is configured and certified.
The cost of not protecting backup environments is high. IBM’s 2025 Cost of a Data Breach Report puts the global average breach cost at $4.4 million, and IBM emphasizes that resilience includes regularly testing incident response plans alongside backup availability. Having an off-site backup is step one. Knowing it restores cleanly under pressure is a different and equally important step.
-
Protect Your Business With OTAVA Cloud Connect
OTAVA is a Veeam Platinum Partner and the 2025 VCSP Partner of the Year – USA, with certified engineers managing Cloud Connect deployments for IT teams, MSPs, and compliance-sensitive organizations. Our model keeps backup schedules, retention policies, and recovery decisions in your hands. We handle the infrastructure, 24/7 monitoring, and support behind it.
There are no hidden fees. No ingress, egress, bandwidth, or licensing charges. You pay for the storage you use. Optional immutable storage, application-aware backups for SQL, Active Directory, Oracle, Exchange, and more, plus unlimited backup volume, are all available through our service.
Talk to an OTAVA expert today to simplify your offsite backup strategy and put a provider-managed cloud repository behind your Veeam environment.