# Veeam backup app

**URL:** <https://community.appgovscore.com/t/veeam-backup-app/50>\
**Category:** SaaS Applications\
**Created:** [January 9, 2024, 7:54am UTC](https://community.appgovscore.com/t/veeam-backup-app/50 "2024-01-09T07:54:39Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![CrushNetworks](https://avatars.discourse-cdn.com/v4/letter/c/e9a140/32.png) [@CrushNetworks](https://community.appgovscore.com/u/CrushNetworks)\
**Post date:** [January 9, 2024, 7:54am UTC](https://community.appgovscore.com/t/veeam-backup-app/50/1 "2024-01-09T07:54:39Z")

</div>

I get the most flags for the Veeam backup tool. I have the free/community edition. Anyone else seen this?

---

<div class="post-metadata">

**Author:** ![SanderBerkouwer](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.appgovscore.com/sanderberkouwer/32/13_2.png) [@SanderBerkouwer](https://community.appgovscore.com/u/SanderBerkouwer)\
**Post date:** [January 12, 2024, 8:51am UTC](https://community.appgovscore.com/t/veeam-backup-app/50/2 "2024-01-12T08:51:11Z")

</div>

Yes, I’m seeing it, too.  
Veeam Backup gets flagged in the App Gov Score and App Gov Accelerator solutions, because:

- It uses Public Client Flows. This is potentially dangerous.
- It uses old authentication libraries. This is potentially dangerous.
- It uses a certificate with years of validity. This is potentially dangerous.
- It uses high-risk API permissions. This is potentially dangerous.

---

<div class="post-metadata">

**Author:** ![CrushNetworks](https://avatars.discourse-cdn.com/v4/letter/c/e9a140/32.png) [@CrushNetworks](https://community.appgovscore.com/u/CrushNetworks)\
**Post date:** [January 12, 2024, 3:48pm UTC](https://community.appgovscore.com/t/veeam-backup-app/50/3 "2024-01-12T15:48:25Z")

</div>

What do we tell the vendor? Does eNow recommend removal? I can download and reinstall their free community edition again and see if better score but I’d have to reconfigure the app is my guess. Lots of time.

---

<div class="post-metadata">

**Author:** ![SanderBerkouwer](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.appgovscore.com/sanderberkouwer/32/13_2.png) [@SanderBerkouwer](https://community.appgovscore.com/u/SanderBerkouwer)\
**Post date:** [February 6, 2024, 8:30am UTC](https://community.appgovscore.com/t/veeam-backup-app/50/4 "2024-02-06T08:30:20Z")

</div>

**Public Client Flows**  
The Public Client Flow issue that the App Gov Score and App Gov Accelarator solutions flag is related to the way the product team at Veeam have programmed the solution. [This is as designed](https://forums.veeam.com/veeam-backup-for-microsoft-365-f47/modern-authentication-restore-reirect-url-how-to-t69338.html), but could be further improved by Veeam [as indicated by Alistair Pugin in his blogpost on public client flows](https://www.appgovscore.com/blog/public-client-flows-what-you-need-to-know). An inquiry on [their forums](https://forums.veeam.com/) would be the obvious thing to do.

**Authentication libraries**  
[Veeam regularly updates the Veeam Backup for Microsoft 365 solution](https://www.veeam.com/kb4106). Make sure you are on the latest build to get updates that include updated authentication libraries

**Certificate**  
The use of a certificate with a long validity period is something I frown upon. Veeam has chosen the route of least administrative burden and has traded in on certificate lifecycle management and thus security. This is as designed, but a question in the Veeam forums could be raised about this practice.

**Risky permissions and roles**  
A backup solution will have high-risky API permissions. There is nothing to be done about those, because the permissions are required to access your data in order to make backups of it.

---

<div class="post-metadata">

**Author:** ![CrushNetworks](https://avatars.discourse-cdn.com/v4/letter/c/e9a140/32.png) [@CrushNetworks](https://community.appgovscore.com/u/CrushNetworks)\
**Post date:** [February 8, 2024, 12:16am UTC](https://community.appgovscore.com/t/veeam-backup-app/50/5 "2024-02-08T00:16:34Z")

</div>

I am more than happy to post in Veeam’s forums…if you could craft a simple, short message that outlines the concerns, I will post there. I will also download and try their latest release, and see what if anything improves.

---

<div class="post-metadata">

**Author:** ![SanderBerkouwer](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.appgovscore.com/sanderberkouwer/32/13_2.png) [@SanderBerkouwer](https://community.appgovscore.com/u/SanderBerkouwer)\
**Post date:** [February 29, 2024, 9:13am UTC](https://community.appgovscore.com/t/veeam-backup-app/50/6 "2024-02-29T09:13:14Z")

</div>

I have started [a thread on the Veeam R&D Forums](https://forums.veeam.com/veeam-backup-for-microsoft-365-f47/entra-application-best-practices-t92612.html). 👍  
Mike Resseler (A Belgium guy, and program manager for all of Veeam’s cloud solutions last time I spoke with him…) already responded and shared that some of these items are already being looked into.
