One of the biggest challenges with immutable object storage has always been proving that your backups are recoverable without compromising your secure backup repository.
With Veeam v13.1, organizations can now connect to an existing Object Storage Repository in Read-Only mode from a secondary Veeam Backup & Recovery Server and perform Test Restores directly from those backups without allowing any new backup data to be written.
This capability significantly improves disaster recovery validation, compliance testing, cyber resilience, and migration projects.
Why is this Important?
Many organizations maintain object storage repositories that contain years of immutable backups. Previously these repositories were often preserved for:
- Regulatory compliance
- Legal retention
- Cyber recovery
- Migration projects
- Air-gapped archives
However administrators wanted to validate backups without risking accidental modifications.
Now they can.
What is Read-Only Mode?
Read-Only Mode allows Veeam Backup & Replication v13.1 to connect to an existing object storage repository while preventing:
- New backup chains
- Backup copies
- Backup modifications
- Retention processing
- Metadata changes
Instead Veeam performs only:
- Backup import
- Backup browsing
- Restore operations
- Test Restore
- Instant Recovery (supported scenarios)
Architecture Overview

Typical Scenario
Imagine your organization has migrated from one Wasabi bucket to another.

Instead of deleting it, administrators simply:
- Add Repository
- Select Existing Object Storage
- Enable Read Only
- Import Metadata
- Perform Test Restores
No production jobs need to point to this repository.
No new backups are written.
How it Works
Let’s go through how to setup a Read-only Repository in Veeam Backup & Replication Server v13.1.
In my scenario I have deployed a fresh Veeam Backup & Replication Server v13.1 and will be connecting to an existing Object Storage Repository that is being used by another Veeam Backup & Replication Server.
- I will connect using the same object storage credentials as I did with the production repository.
- No bucket changes are required.
Since my primary Object Storage Repository is in Wasabi, I will be creating a Wasabi Read Only Repository in the Veeam Backup & Replication Server 13.1.
- Give the Read-Only Repository a Name and add a Description.

- Specify the Region and Credentials. In my case it is the Wasabi region for Australia. I am using Direct connection mode for connectivity.

- Select the Bucket and Folder that contains the backup chain from the production Veeam Backup & Replication Server.

At this point you will be asked if you would like to proceed with adding this repository in Read-Only mode to perform restores. Select Yes.

- Select the Mount Servers.

- Review the setting, Apply and Finish once the repository creation is complete.


You will see that the Used Space in the Read-Only repository that is created is 0 B in size. In the next step, we will import the backup.

- Now let’s import the backups into the Read-Only Repository. Here Veeam reads:
- Backup chains
- Restore points
- VM metadata
- File indexes
Nothing is modified.
Right Click on the newly created Read-Only Repository and select Import Backups.

Select Yes when this message pops up and then select OK when the import operation message appears.



- Select Next in the Apply screen and then select Finish.


- Veeam now starts the Backup Repository synchronisation.

Once the synchronisation is complete, the Used Space increases and you are able to see the backups chain and restore points in the Home screen under Capacity Tier (Imported).


With the Read Only Repository the available operations include:
- Browse backups
- Search backups
- Restore VMs
- Restore files
- Test Restore
Unavailable operations:
- Backup jobs
- Backup Copy
- Capacity Tier writes
- Retention cleanup
NEW in Veeam Backup & Replication v13.1 – Test Restore
Administrators can validate backup recoverability without performing a production restore.

Why Test Restore Matters
A backup is only valuable if it can actually be restored. Many organizations have:
- Immutable backups
- Air-gapped storage
- Multiple copies
Yet have never done a test recovery. Test Restore closes that gap.
Benefits include:
- Automated validation
- Compliance reporting
- DR testing
- Security assurance
- Cyber resilience

Compliance Use Cases
Many regulations require evidence of recoverability.
Examples:
- ISO 27001
- Essential Eight
- NIST
- CIS Controls
- Cyber Insurance
- Financial regulations
Instead of simply proving backups exist, you can now prove they can be restored.
Security Benefits
Read Only repositories reduce risk.
No accidental:
- Backup deletion
- Retention modification
- Repository corruption
- Backup chain alteration
Even if administrator credentials are compromised, the repository is not being actively written to.
Operational Workflow

Best Practices
Keep Existing Buckets
Don’t delete historical repositories immediately after migration.
Retain them for:
- Compliance
- Recovery
- Auditing
- Legal hold
Validate Regularly
Schedule Test Restore exercises.
Monthly or quarterly validation provides confidence that historical restore points remain usable.
Maintain Immutability
Even though the repository is read-only within Veeam, continue enforcing:
- S3 Object Lock
- Wasabi Immutability
- Azure Immutable Blob
- Object First Immutable Storage
Document Recovery
Store:
- Restore reports
- Recovery logs
- Test results
These become valuable during audits.
Key Benefits at a Glance
| Benefit | Value |
| Read-Only Repository | Protects historical backups from modification |
| No New Backup Writes | Ideal for retired or archived repositories |
| Test Restore | Validates recoverability without impacting production |
| Compliance | Demonstrates recoverability during audits |
| Cyber Resilience | Verifies immutable backups remain usable |
| Migration Support | Simplifies repository transitions while preserving access |
| Operational Confidence | Ensures archived backups can still be recovered |
Final Thoughts
Veeam Backup & Replication v13.1 extends the value of object storage beyond simply retaining backups. By allowing administrators to reconnect existing object storage repositories in Read-Only mode and execute Test Restores, this bridges the gap between long-term retention and proven recoverability.
Whether you’re migrating to new storage, preserving immutable archives for compliance, or strengthening your cyber resilience strategy, this feature ensures historical backups remain accessible, verifiable, and trustworthy without risking accidental changes to the repository.
The result is greater operational confidence, improved audit readiness, and a more resilient backup strategy built on the principle that every backup should be validated, not just stored.
Published: July 29, 2026 12:50pm
Leave a comment