Veeam BDR Script Toolkit
| Field | Detail |
|---|---|
| Audience | T2 / T3 (T1 may run the read-only scripts) |
| Version | 1.0 |
| Last Updated | October 2026 |
| Applies To | DTC BDRs on Veeam B&R 13.1.1.18, and the Hyper-V hosts and endpoints they protect |
| Source | HALO 1146283 and HALO 1179664 |
Every script below is a NinjaOne script. They run as SYSTEM unless noted. They take their settings from NinjaOne script variables, never from prompts. Read-only scripts change nothing and are safe to run at any time.
Which script fixes what
| Problem | Script | Page |
|---|---|---|
| BDR not on 13.1.1.18 | Veeam v13 Upgrade | Version Standard |
| Jobs fail in seconds — outdated Data Mover | Veeam Update Managed Host Components | Server Jobs Fail in Seconds |
| Guest processing fails on Hyper-V VMs | Enable-HvGuestServiceInterface | Guest Processing Fails |
| Every job off at a site | Repair-VeeamJobState | Jobs All Disabled |
| Outdated agent blocks the upgrade; Error 1714 | Veeam DB Issues Report, then Repair-VeeamAgentRegistration | Endpoint Agent Blocks the Upgrade |
| Which BDRs are behind, and why | Get-VeeamFleetState | Version Standard |
| Schedules off-standard, overlapping the copy window | Veeam Schedule Window (Standard) | Veeam Backup and Replication Standards |
Veeam v13 Upgrade
File: Invoke-VeeamV13Upgrade.ps1, v4.53 · NinjaOne: script 203 · Changes the BDR
Moves a BDR one hop per run along the supported route to the pinned build: 12.3.1 → 12.3.2 → 13.1.0.411 → the 13.1.1.18 patch. Re-run until the BDR reads 13.1.1.18. A BDR already at target exits without changes, after checking its managed host components, so it is safe to run fleet-wide.
What it does, in order: preflight gates (disk, pending reboot, chain format, licence, agents, services); pause every job and drain running sessions; install as the local admin through a one-shot scheduled task (setup refuses LocalSystem); confirm the result from the installed-programs entry; restore every job. It will not reboot until paused jobs are confirmed back on. It recovers a wedged backup service, pauses the Service Provider Console agent for the patch, and repairs a broken PowerShell 7.
Variables: downloadUrlV13, sha256V13, enablePatch, patchArgs, downloadUrlPatch, sha256Patch, and stopServicesForPatch (default 0). Current values are on the runbook.
Read the result from: the RESULT: line; BLOCKED BY: for a gate halt; PATCHDIAG: after a failed patch; NEEDS A PERSON where it stops on purpose. It writes its state to the veeamUpgradeState custom field. Logs are in C:\ProgramData\DTC\Logs\VeeamUpgrade\.
Run it during business hours, outside 22:00–04:59.
Get-VeeamFleetState
File: Get-VeeamFleetState.ps1, v2.1 · Read-only
Reports where every BDR stands. It reads only the registry and the upgrade logs and never loads the Veeam PowerShell module — loading it hung 237 devices in v1.0 — so it finishes across the fleet in seconds.
Read the result from: one VER| line per BDR (build, position AT_TARGET / NEEDS_PATCH / NEEDS_1_HOP, state, blocker, last run, script version), plus SETUP| lines with the installer's own reason codes. Trust this over NinjaOne software inventory, which lagged 41 hours during the upgrade.
Veeam Update Managed Host Components
Changes the managed hosts · no variables
Brings the Veeam components on a BDR's managed Hyper-V hosts — Data Mover, Installer Service, Guest Interaction Proxy and Hyper-V Integration — up to the backup server's version, using Update-VBRServerComponent. Safe to run repeatedly: a current host is left alone. Exits 0 where Veeam isn't installed.
Read the result from: Managed hosts: N; out of date: M, then UPGRADED <host> per host fixed — about 26 seconds each — or FAILED.
Repair-VeeamJobState
File: Repair-VeeamJobState.ps1, v1.0 · Variable: mode = report (default) or repair
Finds backup, backup copy and agent jobs that are switched off. repair re-enables only jobs that ran in the last 30 days, with the correct enable command for each job type, and leaves long-dormant jobs for a person to decide. Times out after 150 seconds, so a wedged service can't hang it.
Read the result from: JOBSTATE|<BDR>|<enabled>/<total>|..., and JOB| lines marked WOULD-ENABLE, ENABLED or FAILED.
Veeam DB Issues Report
Read-only · no variables
Reads the database-issues report Veeam setup writes on each upgrade attempt (C:\ProgramData\DTC\Logs\VeeamUpgrade\VbrDatabaseIssuesSetupReport.xml). Prints every error-severity issue with its title, description and named objects. No Veeam calls, no services, no network — nothing that can hang.
Read the result from: DBFILE| (the report's timestamp — older than the last upgrade run means stale) and DBISSUE| lines. The named objects are the endpoints to fix.
Repair-VeeamAgentRegistration
File: Repair-VeeamAgentRegistration.ps1, v1.1 · Runs on the endpoint, not the BDR · Variable: mode = report (default) or repair
Clears what stops the BDR upgrading an endpoint's agent. If a pending reboot is the cause — behind every Error 1714 so far — repair reboots the endpoint with 60 seconds' notice. Otherwise it removes the broken old agent so the BDR can push a current one. It never touches the BDR's registration.
Repair mode reboots the machine. Run it outside working hours.
Enable-HvGuestServiceInterface
File: Enable-HvGuestServiceInterface.ps1 · Runs on Hyper-V hosts · Variable: mode = report or apply (default apply)
Turns on the Hyper-V Guest Service Interface for VMs that have it disabled. report changes nothing and exits 2 where it finds work, so the sites that need it stand out. apply is a live setting change with no reboot; it reads each change back and logs every other integration service that's off. Exits 0 on a BDR or anything without the Hyper-V role.
Veeam Schedule Window (Standard)
File: Set-VeeamScheduleWindow.ps1, v2.1 · Variable: mode · Changes job schedules
Applies DTC's standard windows so server backups, workstation backups and the S3 copy don't collide:
| Jobs | Window |
|---|---|
| Server (periodic) | 06:00–20:59, Monday–Saturday |
| Workstation (daily) | Starts 21:00, Monday–Friday |
| Cloud copy | 22:00–04:59 Monday–Saturday, all day Sunday; hourly within the window |
Skips any job that is running, leaves copy jobs alone unless copy conversion is enabled, and reports how many jobs it changed.
Config Backup Repair
NinjaOne: script 433 · built during the v13 pilot (HALO 1146283)
Repairs a Veeam configuration backup job that points at a repository that no longer exists, so a configuration backup can complete before an upgrade. Classify the fleet with a dry run before applying.
Related
- NinjaOne Veeam Alerts & Custom Fields — Where to Start
- Veeam Setup Failure Reference (13.1.1.18)
- Veeam v13 Fleet Upgrade — Runbook & Milestone Tracker
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | October 2026 | Z. Boogher | Initial release covering the nine scripts built for the v13 upgrade (HALO 1146283, HALO 1179664). |