Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Blocky Security, SQL Server Protection & Entra ID Risks

Veeam
03/12/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Hello and welcome to episode 224, Need I Say More, of the Veeam Community Recap. I'm Rick Finn over the Rickotron. Day before vacation, normal circumstances, joined by my co-conspirator, Maddalena. And Maddy, I understand you're in normal circumstances, but I'm going to call it new circumstances. What is going on? Good day, Rick, and good day, community. Indeed, you know, this was my intro. You took it from me. But yes, indeed, I have a new background because I kind of moved a little bit. But no worries. The old background that I know everyone enjoys is not gone because I'm going to go at that place from time to time as well. But not going into many details. Tell me about you, Rick. You are in normal circumstances, but you are preparing for vacation. Two weeks? No, 10 days, 10 days. 11 over two weekends. So yeah, it is about two weeks. So I'm excited. Yes, I have a big vacation coming up, going on one of those Alaska cruises. Really excited about that. And I know you like a cruise. So did you ever get to do Alaska? No, I've never done Alaska. That's one of my... Alaska and Hawaii, these two states are two states that I really like, I would like to go to. Other than that, in the US, I've seen a little bit, I would say. So these two are on my list to do. You've seen Ohio. That's all you need to see. Yeah, that's all I need. Columbus. Yeah, that's right. No, actually, I'm excited. Alaska is one of the three US states I have not yet visited, with the other being North Dakota and Montana. Oh, sorry, and Vermont. So there'll be three left. Other than that, I've been to all 50 US states. So pretty excited for that. Well, next time we need the feedback from you, an overview of the Alaskan cruise. I thought about doing the recap again on a cruise in 2021. I did one on a cruise. We were in Slovakia on the Danube River, and I did it from our patio. The Wi-Fi was actually good enough for recap. That was kind of crazy. Some of you may remember that. But now I'm actually going to properly vacate because I got the kids and all, so we'll go with it. But we've got a good solid list of community stuff. Oh, by the way, does that same chair? Looks like the same chair. It's not the same chair. New chair as well. New chair. New digs, Maddy. Love it. Well, congratulations. I know that just the work to get to a new space is horrible. It takes forever. I would call it tiring, but exciting. Yeah, yeah. It's like, what else? Might as well throw something else on Maddy's plate. She's busy already. Let's make it more. Because you were the busiest people I know. So anyways, congratulations. And yeah, stay tuned for more on that. Ready to jump in? Absolutely. A lot of good stuff. All right. First up is Luis. He's picked up a partner that he ran into at VeeamOn. Groudata is blocky for Veeam, and he's got some feedback on that. And what caught your eye on this one? Well, a rather controversial topic from what I can see in the comments. So that caught my eye, basically. Luis is discussing Blocky, which is basically a security software designed to protect Veeam backups from ransomware and other threats by basically creating a zero trust environment for Windows-based Veeam repositories for the ones that don't know what is Blocky. And there might be a bunch out there. I think this can be a great solution, as Luis says, for the ones that use Windows and don't have Linux skills or for whatever reason don't want or can't use Linux. And it's a zero change deployment and ease of use. This would be one of the benefits. It that's a benefit. At the same time, it adds a layer of security features, includes MFA for admin access, disk level tamper protection, real-time alerts, and centralized multi-site management. As you can see in the comments, other community members that are using Linux seems to prefer the Linux-based solution, which is kind of obvious if you use Linux and you have good skills for that. You kind of want to use the Linux-based hardened repositories, right, the VHR, as, you know, free and native alternative. Derek even goes further with his comment and questions a little bit. It truly offers the same protection as hardened repositories in there. So I would say let's ask the larger community, what do you think? Let us know in the comments. Have you used Blocky? What's your preference? But great stuff from Luis. Thank you for sharing it with us. I think we might have had at some point somebody from Blocky that kind of gave an overview to our Veeam 100 members. So yeah, pretty cool. Yeah, thank you, Luis. This is interesting because that's one of the really interesting and unique things about Veeam is there's so many ways that we can put backup on ultra-resilient targets, so immutable, offline, air-gapped. And we had the Groud Data team actually on our team call recently, maybe a month or two ago. And this was actually in place as a partner even before we had the Linux-hardened repository. And I have spoken to some organizations that absolutely cannot support Linux, period. They will not do it. So I see this as one of those, if you're really going to standardize on Windows, then here is an option for you. And that is the Veeam way, is to have the options. And Derek and Marcus Dynamic both bring up really good points, but you've got to also remember they're advanced practitioners, so they can handle implementing the Linux-type options and stuff. But nonetheless, thank you, Luis, for sharing this point on Blocky by Veeam. Absolutely. Thank you, Luis. I was super excited about this one because literally, no joke, I'm going to show you right here. I'm working on the lab on my SQL Server number three. I literally am doing it right now today. But Maddy, what caught your eye on Chris's topic of protecting SQL Server with Veeam? Well, first of all, Chris, read your mind. But no, joke aside, he has been really consistent with posting strong content every week. And if I'm not wrong, we mentioned it last week with a really good post as well. And it's great to see this. So yeah, of course, this comes with a new dimension in the recap. And I really like about this one, this particular article, what I like is the fact that this is based on customer feedback, which is important for us and for Veeam in general. And he talks about the flexibility of SQL Server backup options using Veeam. You know, whether on-premises, in Azure VMs, or as Azure PaaS, I 100% agree with his highlight that there is no one-size-fits-all strategy. And the optimal choice really depends on your infrastructure, your admin preferences, and recovery goals. And then basically, he goes over all options in detail. Six, as he mentions, agent-less image-level backup, Veeam-based. This is the simplest, most common approach for virtualized environments. And then the Veeam agent for Microsoft Windows, Veeam plugin for Microsoft SQL Server. For environments where DBAs prefer native backup control, the Veeam plugin allows you to trigger backups from within the SQL Server itself using native backup database syntax. And then Azure YAS with Veeam agent for Microsoft Windows. Veeam agent is fully supported on Azure VMs running SQL Server, and it's managed just like any other protected machine. Azure YAS with Veeam backup for Microsoft Azure. And then last but not least, the Azure SQL PaaS with Veeam backup for Microsoft Azure. And the last part, I think, is very important. He says each option serves a specific purpose, and the best choice really depends on a few things that actually Chris mentioned there. So you can just read it. I'm not going to go over all. But overall, really great segmentation of all these. So I kind of enjoyed it, and I know you might have some thoughts, Rick. Yeah. So first of all, great write-up. And I love to have all of these different ways identified. A lot of times organizations pick a platform or a way of running something like databases for different reasons based on different requirements, physical, virtual, cloud, on-prem, et cetera. And I don't know if I missed it, but I would add that there's also AWS RDS as an option here. But I think that he is coming fresh off of some customer conversations that were, in this example, going Azure. But there's yet another way that you can protect SQL databases with Veeam. So I think it's awesome. I've been playing in the lab with the new enterprise app plugin for SQL Server. There's some new enhancements in v13 for that. Well-timed. Thank you so much, Chris. And you're right, Maddy. I think three or four of the last recaps, we have called Chris's name, and maybe he's scheming something. I don't know. Maybe. That's what I'm thinking. Well done, anyway. Well done. Well done, Chris. All right. Next up, number three, JFM on our team. Julia is talking about hidden costs of Microsoft Enter ID being compromised and some of those risks. I really like this topic. Quite interesting topic, I believe. Did you know that Enter ID is heavily by hackers attacks exceed 600 million daily attempt? Oh, I thought it was 600,000. But regardless, they're both a lot. That's what I read. Now, if this number is insane, I don't know. I mean, if this number is accurate, this is pretty insane. That's what I meant. I did not expect that. It's a... Yeah, but it's a massive target. I mean, it is the identity management of the business world. So sure, it makes sense. Yeah, that's crazy. Let us know if you know what different number. Might just be wrong. I don't know. But anyway, it looks like a high number. So that's the important one that it kind of needs to be protected. So I think that's why Julia decided to write on that. The tricky part in here, as Julia says, is that a breach does not always announce itself with clear warnings or big alerts. And it can start really as a single phishing email. And we all know it. We all received it like a security hole waiting to be found somewhere, even like just a setting that was not correct done. And, you know, once the attacker gets into your Entry ID, they very rare just go for the first thing they find. Instead, they're going to look around. They're going to just increase their access. They're going to stay in there for a while and learn more about the company's online setup. And then they go into kind of attack and go for what is actually important. So Entry ID, I think it's kind of one of the targets in there. So what we should kind of take away from this article, I think, is that, you know, a compromised Entry ID is going to cause far more than just, you know, some tech cleanup. And it's going to actually trigger even if you don't think about it's going to trigger a business crisis. It's going to disrupt your operation. You're going lose revenue and then might go to reputational damage depending on, you know, what's going to be affected and how and compliance fall out for sure. And, you know, the traditional backups definitely matter. But your identity structure must also be protected and recoverable. So I think that's where she's kind of pushing with this article. And she says, like, at some point in the article, you know, the solution is like, just go like have state stay like in layers, just go for the layers and go for the prevention, isolation, backup test. And then, of course, the important thing is also to reinforce the security first culture. You know, it's very important to train your employees on all these matters. So I think all in all, it's just a really good article that's kind of educational and kind of eye opener for the people that didn't really take this seriously. So, yeah. No, I agree. I agree. And Julia, thank you for writing this. I know she's been doing a lot with our intra solution. And by the way, it's available in Veeam Data Cloud. It's kind of interesting because I see some of the transactions when customers enroll. People are enrolling every day to this. This is really awesome. So it's good stuff. Thank you, JFM. All right. Now, I don't know if this is the first time we've called Derek Gloski on the Vanguard blog spotlight, but he might have been called once before. Do you remember? Yeah. Okay. We did call it. But when you were on vacation, I was with AZ and Louis doing the recap. So we did mention Derek, but I think that was kind of the first time when we called him on the BBS because previously we used to call him when he used to be a legend and post at the community hub. But great to have back Derek in the recap as well. Yeah. It looks like he's talking about adding an S3 compatible object storage to an offline, getting an error message about service unavailable. And this is interesting because I'm also playing with the same object storage in the lab as well. And you want to know what's even crazier? On this other screen, I just got a Teams message from someone at object first. So this is just an inceptive, spooky, weird recap because I'm literally working on all of these things right here. But it looks like Derek goes through the full fix to get it back to where we need it. Oh, yeah. It's a very thorough one. I mean, if you encounter this, if you have this situation that you are running it with a customer that has a very secure offline network and they kind of want to move to the more immutable storage as well, then you might just get this error. You might just you want to use Adobe as well. So you might just encounter this error as well. So this would be a really actually good article for you to use to know where's the issue coming from. From what I understood, there are kind of he went to support of object first. They were very prompt. And it seems like there were kind of two things that went wrong. The time problem and TP. And then there was something with the certificate validation problem. So Derek is sharing there the steps to fix the issue. But what he's saying, basically, if you're using Vim in an offline environment, trying to add an object storage ought to be or any S3 compatible object storage as repository, he says, make sure both the server and storage appliance use the same time by a local NTP and then disable Windows certificate validation that requires internet because the certificate is self signed and won't be validated anyway. So this will avoid that 503 service unavailable error when adding the object storage. So, yeah, I mean, I think this is this is great finding and great sharing. Thank you, Derek. Yeah, indeed. In fact, I was doing the same thing exactly. But on the 13 being software appliance, I didn't get this error. But I know why the difference between the different versions, but nonetheless, good to call your name again, Derek. And I'm just mesmerized that that mutable AI generated image. I think it's actually pretty cool. So love it. Yeah. Awesome. All right, we're gonna switch over to special department news. And I have translated this into English, at least the text, but not the image. We have a in Portuguese event from Beth and Andre from Brazil. Absolutely, that's going to happen next Wednesday, July 30. As I can see your time 6pm. I'm not sure if you are on the same time with Brazil. Brazil would be that would be for that would be four o'clock Sao Paulo time. Okay, so yeah, I guess because Andres, you know, he's a trainer. So and bet is VMC certified. So I think they are the best people to hear about why you should become a VM certified professional. So I think this is going to be good. There are already like 35 people that registered didn't expect less from the Brazil community. We know we have a strong one there. So if you still have time, this is recorded on Wednesday, we are going to share it most probably either Thursday evening or Friday morning. So you have plenty of time to register for this one. If you are going to be busy and you can't commit to be live, joining them, then as you always know, we are posting it on our YouTube community playlist. So make sure you checking it out in there. Indeed, and Brazil always does it right. There's no doubt about that. So thank you, Beth. Thank you, and enjoy the content. Really good crowd. So thank you for that. All right, next up is a guy named Jeff and Michael Cade with episode number two on the Michael Cade live stream show. And looks like they're gonna talk about hands on learning pretty cool stuff. Yeah, absolutely. I mean, if you put together about the pod man, that was the topic that they kind of approached in their first episode, or one of the topics they approached. And yeah, I think it's pretty cool, really good for the people that are interested in the cloud native world. It's not just, you know, beam technology. This is just like cloud native technology in general with different touches. So I think it can be very interesting if you are on a learning path. It's educational. It's, you know, you can also ask questions because it's live. It's going to be on YouTube, streamed on YouTube, on Michael's Cade YouTube, which I think it's 90 days of devs. You have the link somewhere there, I believe. Join, yeah, join the event here, cloud native show episode two. This is going to be a series. So I think we're going to have, as I mentioned last time, we're going to have like about one to two shows per month, depending on of course, their availability as well. But I think this is going to be cool. The date is 31st of July, and the time is 9am Eastern, which I believe is going to be 4pm my time, so 3pm CET. 2pm UK time for Michael. Yeah. I think for GMT, yeah, that's a good time. It's like a 2pm, yeah. It's crazy. Well, you used to live in London, right? Yeah. I used to live in London. All these interesting things about Maddy are coming out on this show. London was great. I was there two weeks ago. It was great to be back. Wonderful city. Thank you, Jeff. Thank you, Michael. Good stuff. All right. Next up, let's see if I can do this right on the switch. Did not. There it is. Who's new? Via Sophia plus 169. This is fantastic. Yes, I think it's again, the Vimy University or I don't know, maybe our internal teams, you know, they are just having I know there are some VIMON tours right now. And I must say, I think some of the MVPs and some of the community members were invited, I believe, to talk at some of these events. So they might just mention the community hub. So it could be from different parts. But I'm sure Vimy University has as well something to do with it. But great stuff. Welcome, everyone. Yeah, indeed. I just love seeing these names. They're funny. Just it's just awesome. Third line support. That's funny. I mean, just like it's just awesome code sack. These are awesome. Technical. That's great. Anyways, we could look at that all day. Coolest usernames. Six up for this one. Justice, BLT, Speedy, Texas Tech, NoData, Wolversore. So question, dearest Madalina, does that acronym mean anything to you? It sounds very familiar. BLT, yes. But I can't tell you So there's a sandwich. It's a bacon, lettuce, tomato sandwich? Yes, BLT. True. I haven't had one in a very long time. Is that a common thing in Europe? I mean, it's a good combo. It works on like a lightly toasted bread. I mean, not in Romania, not in Spain, not in Italy, not in France. Might, I don't know, might just be in the UK. I can't remember eating that a lot in the UK. So might be more like an American thing. Might be. I just getting close to lunch. So sorry, it sticks out. I'm getting close to dinner. So yeah. There you go. There you go. All right. And then Alfred's pick with a GIF or is it a GIF? I think it's a GIF. Alfred's pick with a GIF is the rhythmic technologist. And so much so that Sophia put a infinite pair of sunglasses on this animated fellow on a computer. And that is where we're going to leave it. Madalina, thank you so much for preparing the content here today. Absolutely. My pleasure as always. Enjoy your vacation, Rick. Let's see what we're going to do. Yeah. So you got to select a victim. I mean, a volunteer to join you. You could call out to the membership body or to the team. I really appreciate that. Oh, I got it. It's somewhat special department and it's not promoted yet. So I'm going to spill the beans here. Thursday, the 31st of August, we also have the tech fights, which is one of those live streams that we do on LinkedIn. We're going to do a special one. It's going to be an intern takeover because 31st July is National Intern Day in the US. And so we have four interns on our team. We featured Grover and Henry in some of the content already yet this year and Jada as well and Avdi. But they're going to do the live stream. So I'm going to be tuning in from Alaska to watch it. I can't miss it. So I even bought the internet package on the boat. So I'm going to be heckling them. So stay tuned for that. I'm going to add a link in the comments. It's not out there yet. We only promoted the week before. Whenever it's going to be ready. Maybe by Friday, it's going to be ready, right? Because it's the 23rd already. So by Friday, I would think it's going to be up. Yeah, it should be. So you heard it here on the community hub first. So all right, have a great weekend and Manny, I will be back for 226. So we'll see you in two episodes.

TL;DR

  • Blocky for Veeam offers Windows-based repository hardening for organizations that cannot support Linux, though community debate continues over whether it matches Linux hardened repository protection levels.
  • Six distinct methods exist for protecting Microsoft SQL Server with Veeam, spanning agent-based, agentless, plugin-based, and cloud-native approaches, with optimal choice depending on infrastructure and recovery requirements.
  • Microsoft Entra ID faces over 600 million daily attack attempts, and compromises often begin subtly before escalating to business-critical disruptions requiring layered prevention, isolation, backup, and employee training.
  • Adding S3-compatible object storage to offline Veeam environments can trigger 503 errors due to time synchronization and certificate validation issues, both resolvable through local NTP configuration and Windows certificate validation adjustments.
  • The Veeam community continues expanding with 169 new members and multiple upcoming educational events, including certification guidance in Portuguese and cloud-native hands-on learning streams.

Community-Driven Security and Protection Strategies

This episode of the Veeam Community Recap explores three critical security and data protection topics surfaced by community members. The discussion opens with Luis's analysis of Blocky for Veeam, a Windows-based security solution from Groud Data that creates a zero-trust environment for Veeam repositories. The team examines the debate between Windows-based hardening solutions versus Linux hardened repositories, acknowledging that some organizations have strict Windows-only policies that make alternatives like Blocky valuable. Chris's comprehensive breakdown of six different methods for protecting Microsoft SQL Server with Veeam follows, emphasizing that there's no one-size-fits-all approach and that the optimal strategy depends on infrastructure type, admin preferences, and recovery objectives.

Identity Security and Technical Troubleshooting

Julia's article on Microsoft Entra ID compromise highlights the hidden costs of identity breaches, noting that Entra ID faces over 600 million daily attack attempts. The discussion emphasizes that breaches often begin subtly through phishing or misconfigurations, with attackers establishing persistence before targeting critical assets. The episode also covers Derek's detailed troubleshooting guide for resolving 503 service unavailable errors when adding S3-compatible object storage to offline Veeam environments. His solution addresses time synchronization issues via local NTP and certificate validation problems in air-gapped deployments, providing a practical resource for organizations running highly secure offline networks.

Community Events and Educational Initiatives

The episode highlights upcoming community-driven educational content, including a Portuguese-language event on Veeam certification hosted by Beth and Andre in Brazil, and the second episode of Michael Cade's cloud-native live stream series with Jeff. The team also announces 169 new community members and previews a special National Intern Day edition of Tech Fights featuring Veeam's summer interns. These initiatives demonstrate Veeam's commitment to global community engagement and hands-on learning opportunities across different technical domains and experience levels.

Chapters

0:00 - Episode Introduction
3:19 - Blocky for Veeam Discussion
6:47 - SQL Server Protection Methods
10:46 - Microsoft Entra ID Security Risks
14:51 - S3 Object Storage Troubleshooting
18:13 - Community Events and News
22:26 - New Community Members
24:52 - Closing and Upcoming Content

Key Quotes

3:42 "... a rather controversial topic from what I can see in the comments ..."
6:18 "I have spoken to some organizations that absolutely cannot support Linux, period. They will not do it."
8:02 "... there is no one-size-fits-all strategy. And the optimal choice really depends on your infrastructure, your admin preferences, and recovery goals."
11:05 "Enter ID is heavily by hackers attacks exceed 600 million daily attempt ..."
12:01 "... a breach does not always announce itself with clear warnings or big alerts. And it can start really as a single phishing email."
13:02 "... a compromised Entry ID is going to cause far more than just, you know, some tech cleanup. And it's going to actually trigger even if you don't think about it's going to trigger a business crisis."
Categories:
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Cloud Security
  • Identity & Access
  • Best Practices
  • Technical Deep Dive
  • How-To
  • Windows repository hardening
  • SQL Server backup strategies
  • Microsoft Entra ID security
  • S3-compatible object storage
  • Linux hardened repositories
  • Veeam certification
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Blocky Security, SQL Server Protection & Entra ID Risks

              Upcoming Webinar Calendar

              • 06/17/2026
                12:00 PM
                06/17/2026
                Action1: The Remediation Gap: Vulnerability Management in the Age of AI
                https://www.truthinit.com/index.php/channel/2010/action1-the-remediation-gap-vulnerability-management-in-the-age-of-ai/
              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                LATAM: Accelerating Insights on AI Through an Engaging Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-through-an-engaging-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/02/2026
                10:00 AM
                07/02/2026
                Resilience Insights from Hybrid Threats When the Cloud Faces Challenges
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/

              Upcoming Events

              • Jun
                17

                Action1: The Remediation Gap: Vulnerability Management in the Age of AI

                06/17/202612:00 PM ET
                • Jun
                  23

                  The AI-Powered VMware Alternative

                  06/23/202601:00 PM ET
                  • Jun
                    24

                    LATAM: Accelerating Insights on AI Through an Engaging Webinar Series

                    06/24/202611:00 AM ET
                    • Jun
                      25

                      Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                      06/25/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version