If you have existing VDC (Veeam Data Cloud) Vault repositories that were originally added using the earlier shared key authentication method, Veeam Backup & Replication may prompt you to perform a component upgrade. The message may be similar to:
Component update: Update Required — Switch to Microsoft Entra ID authentication
This upgrade changes the Vault repository authentication method from shared keys to Microsoft Entra ID authentication, improving security and aligning the repository with the newer Veeam Data Cloud Vault integration model.
This is particularly relevant because Veeam Backup & Replication 12.3.1 introduced automatic upgrade of Veeam Vault V1 repositories using shared key authentication to V2 repositories using Entra ID authentication. In VBR v13, Veeam Data Cloud Vault integration only supports using the newer Entra ID auth rather than the earlier shared key method.
In some environments, attempting the upgrade may fail with an error similar to:
Failed to assign Veeam Data Cloud Vault with the storage account
A common cause is that the Veeam Backup & Replication server has not yet been authorised with Veeam Data Cloud Vault, or the required storage vault has not been assigned to the VBR workload.
Step 1: Authorise the VBR server with Veeam Data Cloud Vault.
In the Veeam Backup & Replication console, start the process to add or manage a Veeam Data Cloud Vault repository and click ‘Authorize‘ when prompted.
The authorisation will register the backup server in Veeam Data Cloud.
You do not need to complete the entire ‘New Object Storage Repository’ wizard. For this remediation, complete the ‘Account’ step to authorise the VBR server with Veeam Data Cloud Vault, then proceed to Step 2.

Veeam documents this process here: https://helpcenter.veeam.com/docs/vdc/userguide/vault_vbr.html
Account Requirements by VBR Version:
- VBR Build 13.0.1.2067 and newer: The account must have access to both Veeam My Account and Veeam Data Cloud (VDC), and hold Vault Administrator rights in VDC.
- VBR versions prior to Build 13.0.1.2067: In addition to VDC access, the account registering the server must hold the License Administrator role in Veeam My Account. If you are unsure who holds this role, please consult your Veeam Account Representative.
Note: Starting with build 13.0.1.2067, the License Administrator requirement was removed—any user with the required Veeam Data Cloud permissions can register the server.
Step 2: Confirm VBR is registered in VDC portal
After authorisation, confirm that the VBR server is registered in the Veeam Data Cloud portal.
In Veeam Data Cloud Vault, a workload is an installation of a Veeam product that can use a storage vault as a backup target.
To check the registered workload:
- Open the relevant Vault tenant in the Veeam Data Cloud portal.
- Go to Workload Registration.
- Confirm that the Veeam Backup & Replication server appears in the list of registered workloads.
The process is documented here: https://helpcenter.veeam.com/docs/vdc/userguide/vault_workloads.html

Step 3: Assign the storage vault to the VBR server
Once the VBR server is registered, assign the required storage vault to that VBR workload/server.
Veeam documents this process here: https://helpcenter.veeam.com/docs/vdc/userguide/vault_storage_vaults_edit.html#assigning-storage-vaults-to-workloads
In the Veeam Data Cloud portal:
- Go to Storage Vaults.
- Locate the storage vault.
- Click Assignments.
- In the Assign Vault to workload window, find the required Veeam Backup & Replication server.
- Click Assign.
- Confirm the assignment.
After assigning the vault, allow a few minutes for the certificate/public key update to complete on the Microsoft Azure Entra ID side.

Step 4: Retry the component upgrade in VBR
Once the VBR server is authorised, visible as a registered workload in Veeam Data Cloud, and the storage vault has been assigned to that workload, return to the Veeam Backup & Replication console and retry the component upgrade.
You can access this from the VBR main menu:
Main menu ≡ > Upgrade
If the Veeam Data Cloud Vault repository is correctly authorised and assigned, the upgrade should now be able to switch the repository from shared key authentication to Microsoft Entra ID authentication successfully.
Upgrading the VDC Vault component updates the authentication to Entra ID. Special thanks to Ben Thomas for validating this process and providing the final screenshot.
