Replica, CDP replica, restore, storage and cloud plans: what each recovers from and where.
From Ultra Transcenders VRO-13 by Tony Rough (coming January 2027)
Choosing the plan type is the first design decision, and it follows from how the workloads are protected. Each type supports a different combination of protection source, target environment, verification and follow-up actions.
Recovery plans come in five types:
| Plan type | Protects / recovers | Target environment | Verification before running | Actions after the plan runs |
|---|---|---|---|---|
| Replica | vSphere VMs protected by Veeam replication jobs | VMware vSphere | Readiness check, malware scan, DataLab test | Permanent failover, failback (original or new location), commit failback, undo |
| CDP replica | vSphere VMs protected by Veeam CDP policies | VMware vSphere | Readiness check, malware scan, DataLab test | Permanent failover, failback (original or new location), commit failback, undo |
| Restore | vSphere VM backups (to vSphere or Hyper-V), Veeam agent backups (to vSphere), Hyper-V VM backups (to Hyper-V) | VMware vSphere, Microsoft Hyper-V | Readiness check, malware scan, DataLab test (vSphere locations only) | Halt or reset; no undo |
| Storage | vSphere VMs on datastores backed by replicating NetApp or HPE storage | VMware vSphere | Readiness check, DataLab test; no malware scan | Plan stays IN-USE; undo, or reset to run again (for example to fail back) |
| Cloud | vSphere VM, Hyper-V VM and Veeam agent backups | Microsoft Azure | Readiness check, malware scan; no DataLab test | Halt or reset; no undo |
For every type, a new plan can be run immediately or scheduled, and at any point it can be halted and reset. The User Guide describes a plan as ready once it has passed a readiness check plus whichever of malware scan and DataLab test its type supports.
Malware scanning varies by plan type too. Every type except storage plans can check whether restore points carry a Suspicious or Infected malware flag. Antivirus and YARA scans apply only to restore and cloud plans, and machines restored to Hyper-V can be scanned with antivirus software and YARA rules only on demand, not during a DataLab test or plan execution. Scanning CDP replica plans requires the Veeam Backup & Replication server managing the CDP policies to run version 13.0.1 or later. Chapter 9: Ransomware recovery: malware scans and clean room failover covers the details.
Common trap: Planning a DataLab test for a cloud plan or a Hyper-V restore - DataLab testing is not supported for Microsoft Azure or Microsoft Hyper-V recovery locations; cloud plans are verified by readiness checks and malware scans.
Common trap: Expecting a storage plan to return to its normal mode after failover - Orchestrator deliberately leaves it IN-USE so the results stay visible and automatic infrastructure updates cannot modify it; it must be reset before it can be tested, checked or run again.
This note is one section of Ultra Transcenders VRO-13: Veeam Recovery Orchestrator 13, an independent study guide that explains every topic the course covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to the Veeam Help Center.
Due on Amazon in January 2027, in Kindle and paperback editions.
About the book · VRO-13 terms in the glossary · All VRO-13 study notes
What each Orchestrator role can and cannot do, and why building and running plans are separate.
How a plan's state shows its readiness and its mode shows what it is doing.
What a readiness check verifies, how often it runs and what it costs compared with a DataLab test.
How the embedded backup server restores and fails over in a clean room when production is lost.