<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Veeam Software Official Blog</title>
	<atom:link href="https://www.veeam.com/blog/feed" rel="self" type="application/rss+xml" />
	<link>https://www.veeam.com/blog</link>
	<description>Availability technologies overviews and discussions. News, thoughts &#38; updates about Veeam solutions.</description>
	<lastBuildDate>Mon, 08 Jun 2026 20:11:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://img.veeam.com/blog/wp-content/uploads/2023/12/14182530/favicon-228x228-1-120x120.png</url>
	<title>Veeam Software Official Blog</title>
	<link>https://www.veeam.com/blog</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Veeam at HPE Discover 2026: 15 Years, One Vision</title>
		<link>https://www.veeam.com/blog/veeam-hpe-discover-2026.html</link>
		
		<dc:creator><![CDATA[Joanna Paul]]></dc:creator>
		<pubDate>Mon, 08 Jun 2026 19:02:19 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Technology and Storage Partners]]></category>
		<guid isPermaLink="false">https://www.veeam.com/blog?p=213009</guid>

					<description><![CDATA[<p>Join Veeam at HPE Discover 2026 in Las Vegas from June 16 – 18 and see how HPE and Veeam deliver an AI-ready private cloud, as well as modern virtualization and resilience built into every layer of your infrastructure.</p>
<p>The post <a href="https://www.veeam.com/blog/veeam-hpe-discover-2026.html">Veeam at HPE Discover 2026: 15 Years, One Vision</a> appeared first on <a href="https://www.veeam.com/blog">Veeam Software Official Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><em>Join Veeam at HPE Discover 2026 in Las Vegas from June 16 – 18 and see how HPE and Veeam deliver an AI-ready private cloud, as well as modern virtualization and resilience built into every layer of your infrastructure.</em></p>
<p><a title="HPE Discover Las Vegas 2026 | HPE" href="https://www.hpe.com/us/en/discover/lasvegas.html" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">HPE Discover 2026</a> brings together 12,000 IT and business leaders to explore what&#8217;s next in hybrid cloud, AI infrastructure, and enterprise resilience. At the center of that conversation, you&#8217;ll find Veeam.</p>
<p>This year is a major milestone in our partnership, too. HPE and Veeam are celebrating 15 years of joint innovation, where we’ve covered everything from validated architectures for storage and virtualization to integrated platforms that protect some of the world&#8217;s most demanding environments.</p>
<h2>Make the Veeam Booth Your First Stop</h2>
<p>Stop by booth #2039 to speak with Veeam experts, see demos, and learn how HPE + Veeam’s joint portfolio addresses the decisions that keep IT leaders up at night. We also have a dedicated private meeting room available throughout the event for more in-depth conversations.</p>
<p>Whether your priorities are accelerating AI adoption, modernizing your virtualization environment, or tightening your resilience posture, our team will be ready with practical guidance that’s tailored to your environment.</p>
<p>If you&#8217;re new to what we’ve built together, 15 years is a long story (and one worth hearing).</p>
<h2>See How HPE + Veeam Deliver Private Cloud for the AI Era</h2>
<p>Private cloud is back on the agenda. AI workloads, data sovereignty requirements, and the need for tighter governance are driving organizations toward environments where they have greater control, without sacrificing cloud agility. At HPE Discover Las Vegas 2026, customers can explore how HPE + Veeam deliver a unified, AI-ready private cloud platform built around three priorities:</p>
<ul>
<li><strong>AI-ready private cloud:</strong> Validated designs for AI workloads, secure data pipelines with Veeam Kasten<em> for Kubernetes,</em> and a faster path from pilot to production.</li>
<li><strong>Modern virtualization:</strong> <a title="HPE Morpheus VM Essentials Backup &amp; Recovery | Veeam" href="https://www.veeam.com/products/virtual/hpe-morpheus-backup.html" data-wpel-link="internal" target="_blank" rel="follow">HPE VM Essentials</a> and Veeam Data Platform together enable multi-hypervisor support and smoother migrations from vSphere, giving your organization flexibility without the management overhead. <a title="Veeam Delivers Agentless Backup for HPE Morpheus VM Essentials" href="https://www.veeam.com/blog/veeam-agentless-backup-hpe-morpheus-vm-essentials.html" data-wpel-link="internal" target="_blank" rel="follow">Read the blog</a></li>
<li><strong>Built-in resilience and trust:</strong> Data Resilience by Design and the Data and AI Trust Maturity Model ensure the data that feeds your AI models is protected, governed, and recoverable. Not just for today’s operations, but for the AI investments shaping tomorrow.</li>
</ul>
<h2>Join Veeam at the Virtualization and CloudOps Hub</h2>
<p>Experience the future of CloudOps at this exclusive networking event with the CloudOps founding team! Or, get hands-on experience with Morpheus Enterprise, Morpheus Essentials, and OpsRamp.</p>
<p>Spaces are limited and filling quickly.<br /><a title="HPE Discover Hub Las Vegas 2026" href="https://discover.mitcreators.com/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">Register now</a><br /><br />On June 16 at 7:45 a.m. before the show floor gets moving, join us for the CloudOps Channel Partner Breakfast too!<br /><a title="CloudOps Channel Partner Breakfast at HPE Discover Las Vegas" href="https://booking.discover.mitcreators.com/book?activity=partnerBreakfast" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">Sign up</a></p>
<h2>What You Can Take Away From Our Conversations</h2>
<ol>
<li><strong>Private cloud is a strategic decision again.</strong> AI, sovereignty, and governance demands are reshaping where organizations run their most critical workloads. Build your resilience strategy around that reality, not the one from five years ago.</li>
<li><strong>Virtualization modernization is also a protection conversation.</strong> Migrating from vSphere isn&#8217;t just an infrastructure decision; it&#8217;s an opportunity to rethink how you protect, manage, and recover virtual machines (VMs) across a multi-hypervisor environment. <a title="Expanding the Veeam Data Platform with HPE Morpheus VM Essentials" href="https://www.veeam.com/blog/expanding-veeam-data-platform-hpe-morpheus-vm-essentials.html" data-wpel-link="internal" target="_blank" rel="follow">Read more about it in the blog</a></li>
<li><strong>AI needs a resilience foundation.</strong> The data powering your models deserves the same protection, governance, and recoverability as any other mission-critical asset. If it doesn&#8217;t have that, your AI strategy has a gap.</li>
<li><strong>Data resilience by design:</strong> Experience orchestrated resilience, from data protection to instant recovery, across your entire infrastructure when Veeam + HPE as a single, validated platform.</li>
<li><strong>Expanded support for HPE Alletra Storage MP B10000 and HPE StoreOnce efficiency.</strong> Veeam Data Platform uses the latest HPE StoreOnce Catalyst to deliver up to 60:1 data reduction, remove incremental backup limits, accelerate restores, support new hybrid cloud use cases, and lower TCO. It also adds NVMe support and new snapshot integrations for faster backups and near-instant recovery of critical workloads. New reference architectures for end-to-end immutability across the HPE Alletra Storage MP portfolio are expected soon, which will further strengthen ransomware and data loss protection.</li>
<li><span class="TrackChangeTextInsertion TrackedChange TrackChangeHoverSelectColorRed SCXW61040301 BCX8"><span class="TextRun SCXW61040301 BCX8" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun TrackChangeHoverSelectHighlightRed SCXW61040301 BCX8">AI at scale starts with trusted, resilient data.</span></span></span><span class="TrackChangeTextInsertion TrackedChange TrackChangeHoverSelectColorRed SCXW61040301 BCX8"><span class="TextRun SCXW61040301 BCX8" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun TrackChangeHoverSelectHighlightRed SCXW61040301 BCX8"> HPE + Veeam help organizations build an AI-ready </span></span></span><span class="TrackChangeTextInsertion TrackedChange TrackChangeHoverSelectColorRed SCXW61040301 BCX8"><span class="TextRun SCXW61040301 BCX8" lang="EN-US" xml:lang="EN-US" data-contrast="auto"><span class="NormalTextRun TrackChangeHoverSelectHighlightRed SCXW61040301 BCX8">foundation where data is protected, governed, and recoverable—so teams can move from experimentation to production with greater confidence, control, and resilience.</span></span></span></li>
</ol>
<p><a title="Veeam and HPE Extend Strategic Partnership and Unveil Next-Gen Data Protection to Supercharge Enterprise Resilience" href="https://www.veeam.com/company/press-release/veeam-and-hpe-extend-strategic-partnership-and-unveil-next-gen-data-protection-to-supercharge-enterprise-resilience.html" data-wpel-link="internal" target="_blank" rel="follow">Read the PR announcement</a></p>
<h2>Connect with Veeam at HPE Discover 2026</h2>
<p>Visit us at booth #2039 or <a title="Join us at HPE Discover 2026" href="https://go.veeam.com/HPE-Discover" data-wpel-link="internal" target="_blank" rel="follow">request a meeting</a> to reserve time with our team. Our team includes alliance experts, solutions architects, and senior leaders who are ready to have a real conversation about your priorities.</p>
<p>Whether you want to strengthen your resilience posture, accelerate AI infrastructure, or simplify your virtualization environment, we&#8217;ll help you turn those priorities into action.</p>
<p><strong>Resources:</strong></p>
<p><a title="Join us at HPE Discover 2026" href="https://go.veeam.com/HPE-Discover" data-wpel-link="internal" target="_blank" rel="follow">Join us at HPE Discover 2026</a></p>
<p><a title="HPE Morpheus VM Essentials Backup &amp; Recovery | Veeam" href="https://www.veeam.com/products/virtual/hpe-morpheus-backup.html" data-wpel-link="internal" target="_blank" rel="follow">Backup &amp; Recovery for HPE Morpheus VM Essentials</a></p>
<p><a title="Discover 2025 HPE Private Cloud Business Edition, VM Essentials and Veeam Data Platform Explainer" href="https://www.youtube.com/watch?v=yzVdf9TNu5c" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">HPE Private Cloud Business Edition, VM Essentials and Veeam Data Platform Explainer</a></p>
<p><a title="HPE &amp; Veeam: Private Cloud Backup for VMs and Kubernetes" href="https://www.veeam.com/blog/hpe-veeam-private-cloud-protection.html" data-wpel-link="internal" target="_blank" rel="follow">HPE and Veeam: Enhancing Private Cloud Data Protection with Morpheus Software, VM Essentials, and Kubernetes</a></p>
<p><a title="The Data Residency Gap: Policy, Practice &amp; True Understanding | Wake Up S02E08" href="https://www.youtube.com/watch?v=uid_DIYKM_Y" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">The Veeam Wake Up Podcast with Jan De Clercq, Security Chief Technologist, HPE</a></p>
<p><a title="The Great VM Reset: Insights from HPE and Veeam" href="https://www.youtube.com/watch?v=RL1xh3BFDUY" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">The Great VM Reset: Insights from HPE and Veeam</a></p>
<p><a title="HPE Morpheus VM Essentials Software - Using Veeam agents for protection" href="https://www.youtube.com/watch?v=6gNpuTauEoM" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">HPE Morpheus VM Essentials Software &#8211; Using Veeam agents for protection</a></p>
<p>The post <a href="https://www.veeam.com/blog/veeam-hpe-discover-2026.html">Veeam at HPE Discover 2026: 15 Years, One Vision</a> appeared first on <a href="https://www.veeam.com/blog">Veeam Software Official Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Why You Should Make Veeam a Must-Visit at Pure Accelerate 2026</title>
		<link>https://www.veeam.com/blog/veeam-pure-accelerate-2026.html</link>
		
		<dc:creator><![CDATA[Joanna Paul]]></dc:creator>
		<pubDate>Thu, 04 Jun 2026 14:11:32 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Technology and Storage Partners]]></category>
		<guid isPermaLink="false">https://www.veeam.com/blog?p=212989</guid>

					<description><![CDATA[<p>Join Veeam in Las Vegas, June 16–18, to see how faster recovery, stronger cyber resilience, and simpler data protection come to life with Veeam + Everpure.</p>
<p>The post <a href="https://www.veeam.com/blog/veeam-pure-accelerate-2026.html">Why You Should Make Veeam a Must-Visit at Pure Accelerate 2026</a> appeared first on <a href="https://www.veeam.com/blog">Veeam Software Official Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><em>Join Veeam in Las Vegas, June 16–18, to see how faster recovery, stronger cyber resilience, and simpler data protection come to life with Veeam + Everpure.</em></p>
<p><a title="Join us at Pure Accelerate 2026" href="https://go.veeam.com/pure-accelerate" data-wpel-link="internal" target="_blank" rel="follow">Pure Accelerate 2026</a> is a great moment for organizations looking at balancing AI-ready infrastructure, operational simplicity, with stronger cyber resilience. At the event, customers can explore how Veeam helps turn protection and recovery into a strategic advantage, with solutions designed to simplify operations, strengthen resilience, and support real-world recovery goals at scale.</p>
<h2>Make the Veeam booth your first stop</h2>
<p>If you are heading to <a title="Pure Accelerate 2026 - June 16-18 - Las Vegas | Everpure" href="https://www.everpuredata.com/accelerate.html" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">Pure Accelerate 2026</a> in Las Vegas, make the Veeam booth a priority. Whether your focus is reducing backup overhead, accelerating restores, or strengthening ransomware readiness, our Veeam experts will be ready with practical guidance, proven strategies, and conversations tailored to your environment. Additionally, learn more about Veeam’s acquisition of Securiti AI, and how you can accelerate safe AI at scale across workloads.</p>
<h2>See how Veeam and Everpure can elevate protection and recovery</h2>
<p>One of the biggest reasons to connect with Veeam at the event is to see how Veeam Data Platform complements Everpure’s intelligent control capabilities to reduce operational friction and improve recovery outcomes. Customers can explore how Everpure Fusion helps orchestrate FlashArray systems fleet-wide while Veeam delivers the backup and recovery engine, bringing centralized visibility, automated registration, and consistent policy enforcement across datastores. The result is a more streamlined path to protection, faster recovery, and greater confidence in resilience.</p>
<ul>
<li><strong>Fleet-wide policy control:</strong> Apply protection policies once and enforce them consistently across the environment.</li>
<li><strong>Snapshot-driven speed:</strong> Leverage array snapshots for low-impact backup and near-instant restores where appropriate.</li>
<li><strong>Anomaly-aware recovery:</strong> Pair anomaly detection and incident workflows to accelerate the path to clean restores.</li>
</ul>
<h2 aria-level="2"><span data-contrast="none">Don’t miss Veeam’s breakout session</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h2>
<h3><b><span data-contrast="auto">Redefining Data Resilience: Veeam and Everpure’s Next-Gen Integration</span></b><span data-ccp-props="{}"> </span></h3>
<p><span data-contrast="auto">Hear from Veeam’s experts <a href="https://www.veeam.com/cxo/thought-leadership/emilee-tellez.html" data-wpel-link="internal" target="_blank" rel="follow">Emiliee Tellez</a> and <a href="https://www.veeam.com/blog/author/mark-polin" data-wpel-link="internal" target="_blank" rel="follow">Mark Polin</a> to Discover how Veeam and Everpure are setting new standards in data protection with industry-leading SafeMode immutable storage snapshots, integrated Pure1 anomaly detection, and unified fleet management via Fusion. Explore validated cyber-resilience, seamless VMware integration, and flexible as-a-service licensing—empowering your enterprise with true next-gen data resilience.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Wednesday, June 17 from 1:45-2:30pm</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Room: Jasmine D</span><span data-ccp-props="{}"> </span></p>
<h2>Learn how to make clean recovery more repeatable</h2>
<p>Customers visiting Veeam can also engage on one of the most urgent topics at Everpure Accelerate: clean recovery after a cyber incident. Today, resilience is not just about restoring data. It is about restoring with speed, accuracy, and confidence. Veeam can show how anomaly detection signals, incident context, and restore point intelligence help teams identify trusted recovery options faster and build a more repeatable path to isolated recovery and validation.</p>
<ul>
<li><strong>Fast, storage-integrated protection:</strong> Using snapshot-based approaches where they make sense to improve performance and reduce overhead.</li>
<li><strong>Recoverability you can validate:</strong> Moving beyond “we have backups” to “we can restore and prove it,” with repeatable processes and reporting.</li>
<li><strong>Cyber resilience workflows:</strong> How anomaly signals and incident context can help narrow the search for clean restore points during an attack.</li>
<li><strong>Operational simplicity at scale:</strong> Reducing the time spent onboarding, registering, and managing protection across many systems.</li>
<li><strong>Cloud like consumption: </strong>SLA-aligned, as-a-service delivery options through approved MSPs/GSIs with predictable, consumption-based pricing—reducing operational burden through managed monitoring, patching, and policy management. <a title="Veeam and Everpure Deliver Cyber Resilience as-a-Service" href="https://www.veeam.com/blog/veeam-everpure-storage-cyber-resilience-as-a-service.html" data-wpel-link="internal" target="_blank" rel="follow">Read the blog</a></li>
</ul>
<h2>What you can take away from the conversation</h2>
<ol>
<li><strong>Design for fleet scale, not single systems.</strong> Standardize policies and automate onboarding so protection doesn’t drift as the environment grows.</li>
<li><strong>Assume you’ll need clean recovery, not just recovery.</strong> Build workflows that help you identify trustworthy restore points and practice isolated recovery. <a title="Veeam | EverPure: Pure1 Veeam Anomaly Awareness Workflow | Demo
" href="https://www.youtube.com/watch?v=qxVdfbLvJqU" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">Watch the demo</a></li>
<li><strong>Use storage capabilities strategically.</strong> Snapshot integration and all-flash performance can improve RPO/RTO—when paired with an enterprise-grade backup and recovery platform.</li>
</ol>
<h2>Get Started with Veeam and Everpure Today</h2>
<p>Natively integrated with Everpure Flash Array through the Universal Storage API and validated by the <a title="Veeam Alliance Partner Integrations &amp; Qualifications" href="https://www.veeam.com/solutions/alliance-partner/integrations-qualifications.html" data-wpel-link="internal" target="_blank" rel="follow">Veeam Ready program</a> to provide a simple, resilient, easy to scale solution for enterprises</p>
<p>Visit the Veeam booth 13 at Pure Accelerate 2026 at Resorts World in Las Vegas or <a title="Join us at Pure Accelerate 2026" href="https://go.veeam.com/pure-accelerate" data-wpel-link="internal" target="_blank" rel="follow">request a meeting</a> with our experts for a chance to talk through your protection strategy, see how Veeam and Everpure can work together across your environment, and discover practical ways to improve recovery speed, operational simplicity, and cyber resilience. Whether you are modernizing infrastructure, strengthening ransomware readiness, or planning for greater scale, the Veeam team will be ready to help you turn those priorities into action.</p>
<p><strong>Resources:</strong></p>
<p><strong>Demo: </strong><a title="Veeam | EverPure: Pure1 Veeam Anomaly Awareness Workflow | Demo
" href="https://www.youtube.com/watch?v=qxVdfbLvJqU" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">Pure1 Veeam Anomaly Awareness Workflow</a></p>
<p><a title="Is Your CISO Holding You Back — Or Setting You Free? Wake Up | S02E07" href="https://www.youtube.com/watch?v=MW71Jdf9Ozc&amp;list=PL0afnnnx_OVBJFAJKhUnZNPJtzbcB_owK&amp;index=3&amp;t=130s" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">Veeam Wake Up Podcast with Rick Orloff, VP and CISO at Everpure</a></p>
<p><strong>On demand webinar: </strong><a title="Cyber Resilience Strategies for Modern Enterprises" href="https://www.veeam.com/resources/videos/webinar-cyber-resilience-power-of-three-modern-enterprises.html" data-wpel-link="internal" target="_blank" rel="follow">Achieving Cyber Resilience with Veeam, Everpure, and Nutanix</a></p>
<p><a title="Veeam Portfolio Trial for SaaS Backup and Data Protection" href="https://www.veeam.com/products/portfolio-trial.html?ad=try_now_sticky" data-wpel-link="internal" target="_blank" rel="follow">Try Veeam for free for 30 days</a></p>



<p></p>



<script src="https://fast.wistia.com/player.js" async></script><script src="https://fast.wistia.com/embed/owtxyrlcs8.js" async type="module"></script><style>wistia-player[media-id='owtxyrlcs8']:not(:defined) { background: center / contain no-repeat url('https://fast.wistia.com/embed/medias/owtxyrlcs8/swatch'); display: block; filter: blur(5px); padding-top:56.25%; }</style> <wistia-player media-id="owtxyrlcs8" aspect="1.7777777777777777"></wistia-player>
<p>The post <a href="https://www.veeam.com/blog/veeam-pure-accelerate-2026.html">Why You Should Make Veeam a Must-Visit at Pure Accelerate 2026</a> appeared first on <a href="https://www.veeam.com/blog">Veeam Software Official Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Announcing the Data &#038; AI Trust Gap Report: Why AI Ambition Is Outpacing Trust</title>
		<link>https://www.veeam.com/blog/data-ai-trust-gap-report.html</link>
		
		<dc:creator><![CDATA[Dave Russell]]></dc:creator>
		<pubDate>Wed, 03 Jun 2026 11:59:56 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Data Security Best Practices]]></category>
		<guid isPermaLink="false">https://www.veeam.com/blog?p=212977</guid>

					<description><![CDATA[<p>The opportunity around AI is real, but without visibility, governance, and executive alignment, results stay out of reach.</p>
<p>The post <a href="https://www.veeam.com/blog/data-ai-trust-gap-report.html">Announcing the Data &amp; AI Trust Gap Report: Why AI Ambition Is Outpacing Trust</a> appeared first on <a href="https://www.veeam.com/blog">Veeam Software Official Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><em>The opportunity around AI is real, but without visibility, governance, and executive alignment, results stay out of reach.</em></p>
<h2>AI Ambition Is Everywhere. Trusted Data Is Not.</h2>
<p>That is the clearest takeaway from The Data &amp; AI Trust Gap, Veeam’s new global research report, which is based on a survey of 600 senior leaders across North America, Europe, and Asia Pacific. The findings point to a hard truth: Most organizations do not have an AI adoption problem. Rather, they have trust issues around their data, which ends up slowing AI progress.</p>
<p>And the pressure to move faster with AI is intense. Some 83% of CEOs report feeling the need to accelerate their AI and data capabilities. But 95% say data challenges have slowed advancements in the past year. That gap between ambition and execution is where this report begins. If organizations want AI to deliver real business value, they need more than access to models and infrastructure. They need data they can trust, governance they can prove, and leadership alignment strong enough to turn strategy into action.</p>
<p><a href="https://go.veeam.com/data-ai-trust-gap-report" data-wpel-link="internal" target="_blank" rel="follow"><em>Download the full report</em></a><em> to see the complete findings and what they mean for your organization.</em></p>
<h2>The Real AI Challenge Is Trust</h2>
<p>AI is no longer an experiment for most organizations. According to the report, 88% are already using or piloting AI agents. But governance is not keeping pace. That mismatch creates risk fast. When leaders cannot clearly see what data exists, where it lives, how AI is using it, or who owns the risk, trust breaks down. And when trust breaks down, so do outcomes.</p>
<p>Our report explores the gap between AI ambition and results, and shows that the organizations making the most progress are not necessarily the ones moving fastest. Instead, those organizations seeing the biggest results are the ones first building the right foundations.</p>
<h2>What the Data Tells Us</h2>
<p>Here are some of the clearest takeaways from our survey of 600 senior leaders from across the globe.</p>
<h3>1. CEOs see the opportunity, but the foundation is still missing</h3>
<p>The upside is clear to leadership. Nearly half of all CEOs believe trusted, compliant data could boost revenue or efficiency by more than 25%. Plus, across all respondents, 38% say the same.</p>
<p>Of course, belief is not the same as readiness. Most leaders say their organization’s data still needs to be more:</p>
<ul>
<li>Up to date (79%)</li>
<li>Accurate (74%)</li>
<li>Accessible (71%)</li>
</ul>
<p>This data serves as a wake-up call, that while organizations understand the value of trusted data, many still lack the visibility, controls, and accountability needed to act on it.</p>
<h3>2. There is a major leadership disconnect around AI visibility</h3>
<p>One of the most striking findings in the report is the gap between what CEOs believe and what technical leaders see. For example, some 65% of CEOs say their organization has a complete and reliable AI inventory, while only 44% of CISOs and 52% of CIOs agree.</p>
<p>That matters because AI strategy, compliance posture, and risk tolerance are often set at the top. And if the view from the top is incomplete, the decisions built on it can be too.</p>
<h3>3. Ownership of AI risk is fragmented</h3>
<p>When asked who holds primary responsibility for what AI agents do, respondents did not point to one clear owner.</p>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="1189" height="697" src="https://img.veeam.com/blog/wp-content/uploads/2026/06/03102956/Agentic-AI-Risk-Ownership-The-Data-and-AI-Trust-Gap.png" alt="Agentic AI risk ownership" class="wp-image-212986" srcset="https://img.veeam.com/blog/wp-content/uploads/2026/06/03102956/Agentic-AI-Risk-Ownership-The-Data-and-AI-Trust-Gap.png 1189w, https://img.veeam.com/blog/wp-content/uploads/2026/06/03102956/Agentic-AI-Risk-Ownership-The-Data-and-AI-Trust-Gap-250x147.png 250w, https://img.veeam.com/blog/wp-content/uploads/2026/06/03102956/Agentic-AI-Risk-Ownership-The-Data-and-AI-Trust-Gap-700x410.png 700w, https://img.veeam.com/blog/wp-content/uploads/2026/06/03102956/Agentic-AI-Risk-Ownership-The-Data-and-AI-Trust-Gap-768x450.png 768w, https://img.veeam.com/blog/wp-content/uploads/2026/06/03102956/Agentic-AI-Risk-Ownership-The-Data-and-AI-Trust-Gap-120x70.png 120w" sizes="(max-width: 1189px) 100vw, 1189px" /></figure>



<p>In other words, responsibility is spread across the organization, but not always in a structured way. That type of strategy can make it harder to enforce controls, respond to issues quickly, and prove accountability when regulators or boards ask tough questions. What the report shows clearly: When ownership is defined well, outcomes improve. When responsibility is diffused, confidence drops.</p>
<h3>4. Shadow AI is already a real business problem</h3>
<p>The report also highlights how quickly AI use is spreading beyond approved channels. Some 95% of organizations know employees are using unapproved AI tools, and 93% of senior leaders recognize shadow AI as a problem. Yet only 25% of organizations provide all employees with access to approved AI tools.</p>
<p>That gap is notable. If people need AI to do their jobs and the business does not give them governed options, they will find their own. Policy alone will not solve that. Organizations need practical guardrails, approved alternatives, and consistent enforcement.</p>
<h3>5. Most organizations are still not AI-ready</h3>
<p>One of the strongest themes in the report is that AI readiness is not about hype. It is about fundamentals.</p>
<p>The research identifies three building blocks of AI readiness:</p>
<ul>
<li>Ambition</li>
<li>Visibility</li>
<li>Governance</li>
</ul>
<p>Only 7% of organizations have all three in place today. But here is the upside. Among that small group of 7%, around 97% report significant, formally quantified business outcomes from their data initiatives over the past year.</p>
<p>That is the real story this research report uncovered. The gap is not between organizations that care about AI and those that do not. Rather, it is between organizations that have built the foundation for trusted execution and those still trying to scale without it.</p>
<h2>What It Takes to Make AI Work at Scale</h2>
<p>This report is not a warning against AI. It is a reminder that trust is what makes AI useful at scale.</p>
<p>Organizations need:</p>
<ul>
<li>Clear visibility into where data lives and how it flows</li>
<li>Enforced controls, not policy alone</li>
<li>Recovery that is tested and validated</li>
<li>Executive alignment around ownership and accountability</li>
</ul>
<p>The four conditions above all have key roles to play in making safe, scalable AI possible. And the organizations seeing results are doing the work upfront. They are auditing their data, closing visibility gaps, assigning ownership, and building governance that can stand up to operational and regulatory pressure.</p>
<p>The Data &amp; AI Trust Gap lays out the full research, key statistics, and the leadership gaps organizations need to close to move from AI ambition to results.</p>
<p>Download the report to explore:</p>
<ul>
<li>Where C-suite perception diverges from technical reality</li>
<li>Why data trust is becoming a revenue and efficiency issue</li>
<li>What shadow AI is revealing about governance gaps</li>
<li>How AI-ready organizations are separating themselves from the pack</li>
</ul>
<p>If your organization is pushing AI forward, this report will help you understand what may be holding results back, and what to do next.</p>
<p>The post <a href="https://www.veeam.com/blog/data-ai-trust-gap-report.html">Announcing the Data &amp; AI Trust Gap Report: Why AI Ambition Is Outpacing Trust</a> appeared first on <a href="https://www.veeam.com/blog">Veeam Software Official Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Privacy Operations Agents Are Redefining How Organizations Scale With Agentic AI</title>
		<link>https://www.veeam.com/blog/privacy-operations-agents-agentic-ai-scale.html</link>
		
		<dc:creator><![CDATA[Cassandra Maldini]]></dc:creator>
		<pubDate>Wed, 03 Jun 2026 11:29:56 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Data Protection & Compliance]]></category>
		<guid isPermaLink="false">https://www.veeam.com/blog?p=212971</guid>

					<description><![CDATA[<p>AI is creating extraordinary opportunities for organizations to move faster, unlock value from data, and transform how work gets done. Across industries, businesses are deploying copilots, generative AI tools, and autonomous agents to improve productivity, accelerate decision making, and operationalize intelligence at an unprecedented scale.</p>
<p>The post <a href="https://www.veeam.com/blog/privacy-operations-agents-agentic-ai-scale.html">Privacy Operations Agents Are Redefining How Organizations Scale With Agentic AI</a> appeared first on <a href="https://www.veeam.com/blog">Veeam Software Official Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2>Why Trusted AI Requires Operational Governance</h2>
<p>AI is creating extraordinary opportunities for organizations to move faster, unlock value from data, and transform how work gets done. Across industries, businesses are deploying copilots, generative AI tools, and autonomous agents to improve productivity, accelerate decision making, and operationalize intelligence at an unprecedented scale.</p>
<p>However, AI is also forcing organizations to confront a reality that has existed for years: Most governance programs were never designed for the complexity of modern data ecosystems.</p>
<p>Long before generative AI entered the enterprise, organizations were already struggling to govern sprawling environments made up of cloud platforms, SaaS applications, analytics tools, third-party vendors, and constantly moving data. Privacy teams relied heavily on assessments, inventories, spreadsheets, email chains, and manual reviews to understand how information was being collected, used, and shared.</p>
<p>Those approaches were already under strain. AI did not create this problem, but it certainly exposed it.</p>
<p>As organizations adopt AI, data is no longer moving through relatively predictable business processes. Rather, it’s flowing through prompts, retrieval systems, orchestration layers, autonomous agents, model interactions, downstream integrations, and continuously evolving workflows. Information is enriched, transformed, inferred, combined, and reused across systems at a pace that traditional governance processes were never designed to manage.</p>
<p>The challenge organizations face today is not simply an AI challenge; it&#8217;s an operational governance challenge.</p>
<p>Effective governance can no longer function as a periodic compliance exercise that’s built around static assessments and point-in-time reviews. In AI environments, governance decisions must happen continuously across changing models, vendors, workflows, jurisdictions, prompts, orchestration layers, and downstream data uses.</p>
<p>This creates a fundamental scaling problem.</p>
<p>Privacy teams cannot manually evaluate every AI use case, workflow, vendor relationship, or downstream processing activity. Consent preferences cannot be managed reliably through disconnected systems, and governance programs cannot depend on static documentation when the underlying technology stack is evolving daily.</p>
<p>This results in a widening gap between the speed of innovation and the speed of governance. Closing that gap requires taking a different approach.</p>
<p>Organizations need governance capabilities that are embedded into operational processes, connected directly to the data they govern, and capable of generating evidence that controls are functioning as intended. Governance must become part of the infrastructure itself rather than a series of activities performed around it.</p>
<p>The organizations that succeed in the AI era will not be the ones that avoid innovation; that’s not an option. Those who will rise to the challenge will be those who can govern that innovation confidently at scale.</p>
<h2>The Next Phase of Privacy Operations</h2>
<p>For years, privacy programs have focused on creating policies, assessments, inventories, notices, and workflows that are designed to help organizations meet regulatory obligations. Those capabilities are still essential, but they are not sufficient on their own.</p>
<p>The future of privacy operations is not simply documenting governance; it’s operationalizing and treating governance as part of the product too. We must, then, learn from our friends in product. We need to learn how to deploy governance and how to ship it.</p>
<p>This means embedding controls directly into the systems where data is collected, processed, shared, and used. It also means connecting policy to execution and creating governance processes that can scale alongside modern technology environments.</p>
<p>This is the challenge Veeam’s latest privacy and AI governance innovations are currently addressing and will be designed to continually address in the future.</p>
<p>Rather than treating privacy as a collection of isolated compliance activities, the Veeam DataAI Command Platform approaches governance as an operational discipline that’s integrated directly into how organizations manage data, enforce policy, and demonstrate accountability.</p>
<p>A critical example of this is consent.</p>
<p>Most organizations have become reasonably effective at collecting cookie consent preferences. The harder problem is ensuring those preferences remain attached to data as it moves through warehouses, analytics environments, AI systems, SaaS applications, advertising technologies, and third-party ecosystems.</p>
<p>In modern environments, consent is no longer a banner problem — it&#8217;s a data infrastructure problem.</p>
<p>The Veeam Consent Agent is a full-stack consent compliance and remediation agent that’s designed to manage the entire consent lifecycle. It helps organizations move beyond consent collection by automating banner creation, testing, monitoring, remediation, and downstream enforcement. This agent captures user consent signals, including cookie preferences, marketing opt-outs, revoked permissions for AI personalization, and processing restrictions. Then, it helps propagate and enforce those preferences across the systems that must honor them, including analytics platforms, AI pipelines, advertising technologies, SaaS applications, and third-party ecosystems.</p>
<p>Powered by Veeam’s robust regulatory intelligence and jurisdiction-aware policy framework, the Consent Agent helps organizations identify compliance gaps, prioritize risk, generate audit-ready evidence, and maintain visibility into consent governance across increasingly complex environments.</p>
<p>At the same time, privacy teams are facing growing pressure to evaluate new technologies, document risk, demonstrate compliance, and respond to evolving regulatory expectations.</p>
<p>The challenge that comes with this is not a lack of expertise; it’s a lack of capacity.</p>
<p>Many governance professionals spend significant time gathering information, reviewing documentation, correlating evidence, and drafting responses to assessments before they can even begin the work that requires human judgment.</p>
<p>The Assessment Autocomplete Agent helps reduce that burden by analyzing supporting evidence and generating tailored assessment responses with a single click. It supports a wide range of governance workflows, including Data Protection Impact Assessments (DPIAs), EU AI Act conformity assessments, and vendor risk questionnaires. Rather than replacing human oversight, it accelerates the work leading up to it, allowing teams to focus their attention on risk evaluation, decision-making, and accountability.</p>
<p>This same principle also applies to privacy rights operations.</p>
<p>As privacy laws continue to expand globally, organizations must maintain intake mechanisms that accurately reflect evolving regulatory requirements and organizational obligations. The Data Subject Request Web Form Builder Agent generates and maintains intake forms configured to an organization’s operational and regulatory footprint. Teams can launch compliant forms more quickly, keep them aligned with changing legal requirements, and reduce the need for recurring legal review and development efforts every time regulations evolve. By automating much of that work, organizations can reduce the time required to deploy and maintain DSR forms by approximately 50%.</p>
<p>Together, these capabilities are designed to address a simple reality: Governance operations must be able to scale alongside the systems they govern.</p>
<h2>Trusted AI Starts with Operational Maturity</h2>
<p>Organizations often discuss AI governance as though it exists separately from privacy, security, compliance, and data governance. In practice, these disciplines are increasingly converging around the same foundational challenge: Understanding data, governing its use, enforcing policy consistently, and proving that controls are working.</p>
<p>Many of the capabilities required for trusted AI already exist within mature privacy programs. This includes things like visibility, consent governance, assessments, transparency, rights fulfillment, accountability, and policy enforcement.</p>
<p>What’s changed is the scale.</p>
<p>The volume of data, the pace of innovation, and the complexity of modern technology ecosystems have outgrown governance models that were built for a different era.</p>
<p>Trusted AI will not be achieved through static documentation or one-time reviews. It will be achieved through operational systems that can adapt as technologies, regulations, business processes, and data ecosystems evolve.</p>
<p>Privacy, security, data governance, resilience, compliance, and AI governance are increasingly converging into a shared operational challenge. The organizations that recognize this shift first will be best positioned to innovate with confidence.</p>
<p>Organizations that invest in operationally mature governance programs are doing more than improving compliance; they’re building the trust infrastructure that will determine who can innovate safely, responsibly, and successfully in the age of AI.</p>
<p class="p1"><b>Ready to move beyond manual governance? See how Veeam helps organizations operationalize privacy and AI governance at enterprise scale.</b></p>
<p>The post <a href="https://www.veeam.com/blog/privacy-operations-agents-agentic-ai-scale.html">Privacy Operations Agents Are Redefining How Organizations Scale With Agentic AI</a> appeared first on <a href="https://www.veeam.com/blog">Veeam Software Official Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>When Identity is Compromised: How to Recover and Keep Your Business Moving</title>
		<link>https://www.veeam.com/blog/entra-id-identity-attack-recovery.html</link>
		
		<dc:creator><![CDATA[Ben Young]]></dc:creator>
		<pubDate>Sat, 23 May 2026 06:02:54 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[Azure]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Data Protection and Compliance]]></category>
		<category><![CDATA[IaaS]]></category>
		<category><![CDATA[M365]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[PaaS]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[Salesforce for enterprise]]></category>
		<guid isPermaLink="false">https://www.veeam.com/blog?p=212911</guid>

					<description><![CDATA[<p>Identity attacks are no longer a question of "if"; they’re a question of "when." Microsoft's Digital Defense Report recorded 600 million identity-based attacks every single day in 2024. In fact, 93% of all cyberattacks now target identity systems, and 58% of organizations expect that number to grow. If your organization relies on Microsoft Entra ID, which virtually every modern enterprise does, you need a plan not just to resist these attacks, but to recover from them quickly and completely when one gets through.</p>
<p>The post <a href="https://www.veeam.com/blog/entra-id-identity-attack-recovery.html">When Identity is Compromised: How to Recover and Keep Your Business Moving</a> appeared first on <a href="https://www.veeam.com/blog">Veeam Software Official Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Identity attacks are no longer a question of &#8220;if&#8221;; they’re a question of &#8220;when.&#8221; Microsoft&#8217;s Digital Defense Report recorded 600 million identity-based attacks every single day in 2024. In fact, 93% of all cyberattacks now target identity systems, and 58% of organizations expect that number to grow. If your organization relies on Microsoft Entra ID, which virtually every modern enterprise does, you need a plan not just to resist these attacks, but to recover from them quickly and completely when one gets through.</p>
<p>This post walks through exactly how these attacks happen, where most organizations are exposed without realizing it, and what real recovery looks like.</p>
<h2><strong>Identity is Your New Perimeter</strong></h2>
<p>For years, enterprise security investment flowed toward the network edge, including firewalls, intrusion detection, and perimeter hardening. Now, that model is obsolete. With the shift to SaaS-based applications like Microsoft 365, Salesforce, Workday, and ServiceNow, the perimeter has moved. Today, your perimeter is your identity layer.</p>
<p>Microsoft Entra ID sits at the center of almost every modern organization. It controls who your users are, what groups they belong to, what applications they can access, and how every system authenticates against every other one via single sign-on. Breach Entra ID, and you haven&#8217;t just compromised one system; you&#8217;ve handed an attacker the keys to your entire connected environment.</p>
<p>The rise of AI agents and non-human identities means organizations will soon manage dozens of machine identities for every human user. Some analysts predict up to a hundred. Either way, each one of these machine identities is a potential attack surface, and each one needs to be protected.</p>
<h2><strong>How Fast an Attacker Can Own Your Environment</strong></h2>
<p>The most dangerous identity attacks don&#8217;t look like attacks at first. Consider what&#8217;s known as a watering hole attack, a technique that’s becoming increasingly common among sophisticated threat groups.</p>
<p>These attacks start on legitimate websites like LinkedIn, which is where the “watering hole” comes into play.  An attacker creates a convincing fake company with a professional page, targeted advertising, and a value proposition calibrated to appeal to IT administrators or infrastructure managers. This ad surfaces in the feeds of people who are most likely to have elevated Entra ID privileges. If someone clicks through, the site looks legitimate.</p>
<p>The victim is often prompted to authenticate their work account to access a &#8220;free AI-powered audit.&#8221; They use the standard Microsoft device login flow, which is the same process they use every day. No suspicious email, no unusual-looking link, and no malware download. Just a normal OAuth consent prompt that, once approved, hands the attacker a valid authentication token. It is worth noting that this is a numbers game, not every potential victim will have the elevated rights required but enough of them to do make it this scam a lucrative business.</p>
<p>From this point, the timeline is brutal:</p>
<ul>
<li><strong>Token captured.</strong> The attacker can now read personal emails, access OneDrive, and begin elevating themselves out of the personal context of just the user.</li>
<li><strong>Persistence installed.</strong> Because personal tokens expire, the attacker registers a backdoor application inside the tenant with elevated and more global permissions. Even if the victim changes their password, access remains.</li>
<li><strong>Lateral movement begins.</strong> With application-level permissions, the attacker can enumerate every user in the directory, access any OneDrive, modify user attributes, and delete data across the organization.</li>
<li><strong>Rogue admin created.</strong> A new global administrator account is inserted into the tenant with multi-factor authentication (MFA) disabled. The attacker now has their own durable credentials.</li>
<li><strong>SSO exploited.</strong> Because Entra ID controls are single sign-on, that rogue admin account can be added to any enterprise application, including Salesforce, Workday, and ServiceNow. The breach spreads beyond Microsoft 365 entirely.</li>
</ul>
<p>All of this can happen in minutes, and increasingly, AI is accelerating every stage of it. Data exfiltration now happens three times faster in AI-powered attacks with the ability to identify high value data that is second to none, from reconnaissance all the way through to extraction.</p>
<h2><strong>The Shared Responsibility Gap Nobody Talks About</strong></h2>
<p>Here is the part most IT teams don&#8217;t fully internalize until it&#8217;s too late: <strong>Microsoft secures the platform, but you’re responsible for what&#8217;s inside it.</strong></p>
<p>Microsoft guarantees uptime, resilience, and security updates for the Entra ID and Microsoft 365 infrastructure. That is their job, and they do it well. That said, the identity objects inside your tenant, including your users, groups, roles, application registrations, and audit logs, are still your responsibility. The data your organization creates inside SharePoint, OneDrive, Exchange, and Teams is also yours. Microsoft&#8217;s built-in retention is short, typically 30 days or less, with significant gaps in granularity, and therefore not very resilient when it comes to protecting your data.</p>
<p>This is the same shared responsibility model that applies to virtually every SaaS platform you use. Salesforce is responsible for Salesforce uptime, but you are ultimately responsible for your Salesforce data.</p>
<p>Most IT organizations have internalized this for traditional infrastructure. They back up their file servers, they back up their virtual machines (VMs), and they have recovery plans for on-premises systems. But identity? Entra ID? That still gets treated as infrastructure that &#8220;just works,&#8221; right up until it doesn&#8217;t.</p>
<h2><strong>Recovery is the Strategy</strong></h2>
<p>Preventing every identity attack is not a realistic goal. The threat volume is too high, the techniques too varied, and AI is making attackers faster and more targeted with every month that passes. The organizations that will weather these attacks best are the ones that can recover to a clean state quickly, minimize business disruption, and limit the blast radius.</p>
<p>What does this recovery actually look like in practice?</p>
<p><strong>Entra ID recovery</strong> needs to be granular. After an attack, you may need to restore specific user attributes that were modified, such as a job title, department, or group membership, without overwriting everything else. You may need to roll back application registrations, remove rogue service principals, or restore deleted users while blending your backup data with whatever short-term retention Microsoft still has available. A manual recovery at this level doesn&#8217;t scale, and the object relationships alone make it impractical without purpose-built tooling.</p>
<p><strong>Microsoft 365 recovery</strong> needs to reach every layer, including individual emails, specific OneDrive files, entire mailboxes, SharePoint sites, their permissions, and Teams data. It needs to support flexible restore options too, including back to the original location, to an alternate location, or downloaded directly for forensic purposes.</p>
<p><strong>SaaS recovery</strong>, such as restoring deleted Salesforce records or modified account data, needs to sit within the same unified workflow. When an attacker pivots Entra ID into Salesforce via SSO, your recovery can&#8217;t stop at Microsoft.</p>
<p><strong>Audit log preservation</strong> is often overlooked but critically important. Entra ID sign-in logs and audit logs capture who signed in from where, what changes were made, and what applications were accessed. Microsoft retains these for 30 days by default. If a breach is discovered 90 or 200 days later, however, those logs are gone. An independent backup that retains them indefinitely gives your security team, forensic investigators, and potentially your cyber insurance provider the evidence trail they need.</p>
<p>Veeam Data Cloud was built to address this recovery problem. It is a unified, subscription-based platform that protects Entra ID, Microsoft 365, Salesforce, and other workloads from a single interface, with granular restore capabilities, immutable encrypted storage, and advanced threat detection that monitors for anomalies in backup data in real time.</p>
<h2><strong>FAQs</strong></h2>
<p><strong>Can Microsoft recover my Entra ID if it&#8217;s compromised?</strong></p>
<p>Microsoft provides limited and short-term recovery capabilities, typically a recycle bin for recently deleted objects with a retention window of around 30 days. There is no native capability to restore specific object properties (like modified user attributes), recover application registrations at a granular level, or restore data beyond that short retention window. For a comprehensive recovery, an independent backup solution is required.</p>
<p><strong>What&#8217;s the difference between Microsoft&#8217;s built-in retention and independent backup?</strong></p>
<p>Microsoft&#8217;s built-in retention is designed for accidental deletion scenarios within a short timeframe. It is not designed for recovering from a sustained attack, restoring configurations that were modified rather than deleted, or preserving audit logs for forensic purposes beyond 30 days. An independent backup gives you a separate, immutable copy of your identity and data estate that sits outside the compromised environment, which is exactly what you need when the environment itself has been breached.</p>
<p><strong>How do identity attacks lead to SaaS breaches like Salesforce?</strong></p>
<p>Entra ID controls single sign-on for most enterprise SaaS applications. When an attacker gains sufficient access to an Entra ID tenant, they can enumerate all enterprise applications that are configured for single sign-on, add their own account to any of those applications, and authenticate directly as a legitimate user without ever touching Salesforce&#8217;s own security controls. The breach of Entra ID is the breach of everything connected to it.</p>
<p><strong>What should I back up to recover from an identity attack?</strong></p>
<p>At minimum: All Entra ID objects (users, groups, roles, application registrations, service principals), Microsoft 365 data (Exchange, OneDrive, SharePoint, Teams), Entra ID sign-in and audit logs, and any SaaS applications connected via single sign-on that contain business critical data. The audit logs in particular are frequently overlooked, but they’re are your forensic record of what happened and when.</p>
<p><strong>How quickly can an attacker move after gaining an OAuth token?</strong></p>
<p>Extremely quickly. With a valid OAuth token of a user with adequate access permissions, an attacker can enumerate your entire user directory, access data across multiple users&#8217; mailboxes and OneDrives, install persistence mechanisms, create rogue admin accounts, and pivot to connected SaaS applications, all within a single session. This is not a slow, methodical breach. It is rapid, and the window for detection before significant damage is narrow.</p>
<h2><strong>See the Attack (and Recovery) for Yourself</strong></h2>
<p>If you want to see exactly how this unfolds in a real environment, I ran a live product demo that walks through the full scenario I described in this post. It covers the watering hole attack from initial lure to rogue admin creation, lateral movement into Salesforce single sign-on, and then the complete recovery workflow inside Veeam Data Cloud including Entra ID, Microsoft 365, and Salesforce, all from a single interface.</p>
<p>The on-demand recording is available here: <a title="Under Attack: Simulating, Surviving and Restoring from an Identity Threat" href="https://www.veeam.com/resources/videos/product-demo-identity-threat-attack-simulation-recovery.html" data-wpel-link="internal" target="_blank" rel="follow">Under Attack: Simulating, Surviving and Restoring from an Identity Threat</a></p>
<p>It runs about 50 minutes and is worth watching with your team, particularly anyone who owns the identity or backup conversation in your organization.</p>
<h2><strong>Treat Identity Like Infrastructure</strong></h2>
<p>You already back up your VMs, you already have recovery plans for your file servers and databases, and you treat those systems as infrastructure: critical, recoverable, protected.</p>
<p>Your Entra ID tenant is infrastructure. Your Microsoft 365 environment is infrastructure. The identity layer that controls access to every system in your organization is infrastructure. It deserves the same level of protection, the same recovery planning, and the same independent backup strategy you apply to everything else.</p>
<p>Identity attacks are happening at scale, they are accelerating, and they will affect your organization. The question is whether you&#8217;ll be in a position to recover cleanly when they do, or whether you&#8217;ll be rebuilding from scratch, without logs, without granular restore points, and without the independent copy that sits outside the compromised environment.</p>
<p>The time to answer that question is before the attack, not after.</p>
<p>The post <a href="https://www.veeam.com/blog/entra-id-identity-attack-recovery.html">When Identity is Compromised: How to Recover and Keep Your Business Moving</a> appeared first on <a href="https://www.veeam.com/blog">Veeam Software Official Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
