In the modern threat landscape, cyber-attacks increasingly target backup data, creating a critical visibility gap for Security Operations Center (SOC) teams. To bridge this divide between data protection and security operations, Veeam Software, the global leader in data resilience, has launched the Veeam App for Microsoft Sentinel. This new solution provides advanced integration, empowering organizations to seamlessly detect, investigate, and respond to cyber threats and anomalies within their backup environments directly from their SIEM (Security Information and Event Management) platform, unifying backup and security intelligence for enhanced cyber resilience.
Veeam launched a new app for the Microsoft Sentinel SIEM platform.
The integration closes a critical visibility gap into backup security.
It ingests over 300 Veeam backup and security events into the SOC.
Features include automated response playbooks and bi-directional APIs.
The app surfaces adversary TTPs detected by Veeam Recon Scanner.
It is available at no extra cost for Veeam Data Platform Advanced and Premium customers.
The Veeam App for Microsoft Sentinel is designed to bring critical backup intelligence directly into the heart of security workflows. It allows SOC teams to monitor and investigate Veeam backup events—including job failures, suspicious activity, and ransomware detections—alongside other security signals. This centralized visibility helps teams detect threats earlier by revealing early indicators of compromise that target an organization's last line of defense: its backups.
A key capability of the integration is its bi-directional automation. Built-in playbooks and API connectivity allow security analysts to trigger actions directly from within Microsoft Sentinel. This enables automated responses such as initiating data restores, running malware scans, and launching remediation workflows. This streamlined response reduces manual effort and coordination time between IT and security teams, allowing for a faster and more decisive reaction to cyber incidents.
The app fundamentally breaks down the silos that traditionally exist between IT backup administrators and SOC analysts. By providing a unified view and shared workflows within a single platform, it fosters integrated collaboration. John Jester, Chief Revenue Officer (CRO) at Veeam, emphasized the strategic importance, stating, “With our new app for Microsoft Sentinel, data resilience meets security intelligence, empowering organizations with instant visibility into backup security events, suspicious activity, and ransomware threats.”
The launch of the Veeam App for Microsoft Sentinel represents a significant step towards a more holistic cybersecurity posture. By seamlessly integrating data resilience into security intelligence, Veeam ensures that SOC teams have the visibility and tools needed to protect the entire data estate. This empowers organizations to act decisively against threats, ensuring that their data remains safe, recoverable, and resilient in the face of evolving cyber-attacks.
Veeam®, the #1 global market leader in data resilience, believes every business should be able to bounce forward after a disruption with the confidence and control of all their data whenever and wherever they need it. Veeam calls this radical resilience, and we’re obsessed with creating innovative ways to help our customers achieve it.
Veeam solutions are purpose-built for powering data resilience by providing data backup, data recovery, data portability, data security, and data intelligence. With Veeam, IT and security leaders rest easy knowing that their apps and data are protected and always available across their cloud, virtual, physical, SaaS, and Kubernetes environments.