Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
KNOWLEDGE BASE ARTICLEVEEAMVERIFIED

PUBLISHER UPDATE · KB4900

KB4900 release notes and known issues

Outbound Public IP Addresses Used by Veeam Data Cloud

Scope: Veeam products. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

Outbound Public IP Addresses Used by Veeam Data Cloud KB ID: 4900 Product: Veeam Data Cloud for Microsoft 365 Veeam Data Cloud for Microsoft Azure Published: 2026-09-10 Last Modified: 2026-09-10 Purpose This article lists the outbound public IP addresses that Veeam Data Cloud uses when connecting from the cloud to infrastructure that a customer hosts and controls, for example a Microsoft Azure Key Vault used for BYOK encryption. These addresses are not used for inbound connections made to Veeam Data Cloud. The addresses belong to the control plane shared by all Veeam Data Cloud products, so they are not specific to any one product. If a resource in the environment receives connections from Veeam Data Cloud and restricts access with an IP-based rule, whether in a firewall, a security group, a conditional access policy, or a similar control, that rule must account for the addresses listed below. If no IP-based restrictions are applied to connections from Veeam Data Cloud, no action is required. Solution Address Change Scheduled for October 2026 The addresses listed below are changing. Five new ranges come into use on 2026-10-12, and the three existing addresses will be retired on 2026-10-22. To ensure a smooth transition, any IP-based rule governing connections from Veeam Data Cloud must be updated to include the new ranges. Outbound Public IP Addresses IP address Status Notes 4.223.88.40/30 (4.223.88.40 – 4.223.88.43) Upcoming Will become active on 2026-10-12 13.78.8.220/30 (13.78.8.220 – 13.78.8.223) Upcoming Will become active on 2026-10-12 20.28.182.92/30 (20.28.182.92 – 20.28.182.95) Upcoming Will become active on 2026-10-12 20.46.44.192/30 (20.46.44.192 – 20.46.44.195) Upcoming Will become active on 2026-10-12 52.189.108.8/30 (52.189.108.8 – 52.189.108.11) Upcoming Will become active on 2026-10-12 20.18.9.116/32 Active Will be retired after 2026-10-22 40.86.73.61/32 Active Will be retired after 2026-10-22 135.225.48.195/32 Active Will be retired after 2026-10-22 Swipe to show more of the table Advised Action Any IP-based rule that governs connections from Veeam Data Cloud should permit every address listed above as Upcoming or Active. Permitting an upcoming address early has no effect on traffic and avoids a gap in connectivity when it comes into use. Leave an active address in place until after its retirement date, so that connections from Veeam Data Cloud continue to reach the environment while the change is applied. An address listed as Retired is no longer used and can be removed from the rule. Keeping Your Configuration Current This list is not fixed. Addresses may be added, changed, or withdrawn as the service evolves, and any rule that references them must be updated to match. Changes are published on this page in advance whenever possible. Because a rule built against an out-of-date list may block legitimate traffic, this page should be reviewed periodically. If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case. To submit feedback regarding this article, please click this link: Send Article Feedback To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.

Improvements and security content

  • Outbound Public IP Addresses Used by Veeam Data Cloud KB ID: 4900 Product: Veeam Data Cloud for Microsoft 365 Veeam Data Cloud for Microsoft Azure Published: 2026-09-10 Last Modified: 2026-09-10 Purpose This article lists the outbound public IP addresses that Veeam Data Cloud uses when connecting from the cloud to infrastructure that a customer hosts and controls, for example a Microsoft Azure Key Vault used for BYOK encryption. These addresses are not used for inbound connections made to Veeam Data Cloud. The addresses belong to the control plane shared by all Veeam Data Cloud products, so they are not specific to any one product. If a resource in the environment receives connections from Veeam Data Cloud and restricts access with an IP-based rule, whether in a firewall, a security group, a conditional access policy, or a similar control, that rule must account for the addresses listed below. If no IP-based restrictions are applied to connections from Veeam Data Cloud, no action is required. Solution Address Change Scheduled for October 2026 The addresses listed below are changing. Five new ranges come into use on 2026-10-12, and the three existing addresses will be retired on 2026-10-22. To ensure a smooth transition, any IP-based rule governing connections from Veeam Data Cloud must be updated to include the new ranges. Outbound Public IP Addresses IP address Status Notes 4.223.88.40/30 (4.223.88.40 – 4.223.88.43) Upcoming Will become active on 2026-10-12 13.78.8.220/30 (13.78.8.220 – 13.78.8.223) Upcoming Will become active on 2026-10-12 20.28.182.92/30 (20.28.182.92 – 20.28.182.95) Upcoming Will become active on 2026-10-12 20.46.44.192/30 (20.46.44.192 – 20.46.44.195) Upcoming Will become active on 2026-10-12 52.189.108.8/30 (52.189.108.8 – 52.189.108.11) Upcoming Will become active on 2026-10-12 20.18.9.116/32 Active Will be retired after 2026-10-22 40.86.73.61/32 Active Will be retired after 2026-10-22 135.225.48.195/32 Active Will be retired after 2026-10-22 Swipe to show more of the table Advised Action Any IP-based rule that governs connections from Veeam Data Cloud should permit every address listed above as Upcoming or Active. Permitting an upcoming address early has no effect on traffic and avoids a gap in connectivity when it comes into use. Leave an active address in place until after its retirement date, so that connections from Veeam Data Cloud continue to reach the environment while the change is applied. An address listed as Retired is no longer used and can be removed from the rule. Keeping Your Configuration Current This list is not fixed. Addresses may be added, changed, or withdrawn as the service evolves, and any rule that references them must be updated to match. Changes are published on this page in advance whenever possible. Because a rule built against an out-of-date list may block legitimate traffic, this page should be reviewed periodically. If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case. To submit feedback regarding this article, please click this link: Send Article Feedback To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Veeam products

Affected versions

  • 4.223.88.40
  • 4.223.88.43
  • 13.78.8.220
  • 13.78.8.223
  • 20.28.182.92
  • 20.28.182.95
  • 20.46.44.192
  • 20.46.44.195
  • 52.189.108.8
  • 52.189.108.11
  • 20.18.9.116
  • 40.86.73.61
  • 135.225.48.195

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Official publisher evidence

VEEAMVERIFIED

Outbound Public IP Addresses Used by Veeam Data Cloud

Checked 28 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source