Backup
What is Proxmox Backup Server, and is it enough on its own?
PBS is a capable, free backup server for Proxmox VE. Here's what it protects, what it leaves to you, and how to add the copy that survives a bad day.

The short answer
Proxmox Backup Server (PBS) is free, open-source backup software for Proxmox VE virtual machines, containers and physical hosts. It deduplicates, compresses, encrypts and checksums backups. On its own it is one copy, usually on-site and run by the same admins. For ransomware or site loss, add an offsite, immutable copy and test restores.
Key takeaways
- Proxmox Backup Server is free and open-source software under the AGPL v3 licence, with incremental, deduplicated, Zstandard-compressed and SHA-256-checked backups.
- PBS never rewrites existing data blocks, so a compromised Proxmox VE host cannot alter backups that already exist, according to the Proxmox documentation.
- Proxmox's own guidance recommends the 3-2-1 rule, an off-site copy through sync jobs or tape, and API tokens without delete rights for backup clients.
- Verification jobs check stored data against checksums; Proxmox recommends re-verifying all backups at least monthly and testing restores to new guests.
- A second copy outside your own PBS host and admin accounts is what protects you when the PBS server itself is attacked, deleted or lost.
What is Proxmox Backup Server?
Proxmox Backup Server is a client-server backup system built for Proxmox VE. It backs up virtual machines, containers and physical hosts, and it's free, open-source software under the AGPL v3 licence.
According to the Proxmox Backup Server documentation (version 4.2 at the time of writing), the main building blocks are:
- Incremental backups: only the changes since the last backup are read and sent.
- Deduplication: identical data blocks are stored once, which keeps storage use down when you back up many similar VMs.
- Zstandard compression: fast compression of the data that does get stored.
- Client-side encryption: backups can be encrypted with AES-256-GCM before they leave the host, and transfers run over TLS.
- SHA-256 checksums: every data chunk is checksummed so corruption can be detected.
- Remote sync and tape: datastores can be synced to another PBS instance, and tape libraries are supported.
PBS is the natural first layer: the part of a backup as a service strategy closest to your hypervisors, giving fast local restores.
Why are more organisations choosing Proxmox and PBS?
Two reasons come up most: cost predictability after VMware's licensing changes, and the fact that Proxmox VE and PBS are designed to work together.
After Broadcom bought VMware, it ended perpetual licences, moved customers to subscription bundles and switched to per-core pricing. In April 2024, Computer Weekly reported that the European cloud association CISPE and business user groups from Belgium, France, Germany and the Netherlands had complained to the European Commission about those terms. Many IT teams and MSPs started testing Proxmox VE instead.
Once Proxmox VE is in place, PBS is the obvious backup target. The Proxmox VE Backup and Restore guide recommends running PBS on a dedicated host because of its deduplication and other features. Two features matter in daily use:
- Live-restore: a VM can start from a PBS backup while its data is still being copied back in the background, which shortens downtime for large VMs.
- File restore: you can browse a backup and download single files or folders without restoring the whole VM.
Moving off VMware? Plan backups during the migration, not after. We protect both, see VMware and Hyper-V backup and Proxmox backup.
How does PBS protect against ransomware, and where does it stop?
PBS protects existing backups from a compromised Proxmox VE host, because it never rewrites data blocks that are already stored. It doesn't protect you from an attacker who controls the PBS server itself, or from losing the site where it runs.
The ransomware section of the PBS storage documentation is refreshingly direct about this. It says a compromised client "cannot corrupt or modify existing backups". It then recommends extra measures: follow the 3-2-1 rule, create off-site copies with remote sync jobs or tape, give backup clients API tokens that can't delete anything, and prune on the PBS server rather than from the client. It also warns that verification jobs can detect tampering but that advanced ransomware might get around them, and advises regular test restores to new guests.
| Risk | PBS on its own | What you still need |
|---|---|---|
| Ransomware on a Proxmox VE host | Existing backups can't be rewritten by the client | Restricted API tokens and server-side pruning |
| Attacker with admin rights on PBS | Can prune or delete datastores | A copy under separate credentials that can't be deleted |
| Fire, flood or theft at your site | Lost if PBS sits in the same room | An off-site copy in another location |
| Silent corruption on disk | Detected by verification jobs | Regular re-verification and a second copy to restore from |
| Restore that fails under pressure | Not tested automatically | Scheduled test restores with recorded results |
That isn't unique to Proxmox. Any backup on one server, in one building, under production's admin accounts, is a single point of failure.
Do you need an offsite copy of your Proxmox backups?
Yes. Proxmox's own documentation recommends at least one off-site copy, and the 3-2-1-1-0 rule goes further: one copy should also be immutable or air-gapped, with zero errors on restore tests.
The 3-2-1-1-0 rule means three copies of your data, on two types of media, one off-site, one immutable or offline, and zero errors when you verify. A local PBS datastore covers the first copy and fast restores. The other copies are where most Proxmox setups fall short.
| Option | How it works | Watch out for |
|---|---|---|
| Second PBS at another site | A sync job pulls or pushes snapshots to a remote PBS; only new data is sent | You run and secure two servers; shared admin accounts weaken the separation |
| Tape | PBS writes to a tape library and tapes go to a vault | Hardware, handling and slow restores |
| Managed offsite backup | A provider stores an immutable copy in its own data centres and checks it | Check location, jurisdiction, immutability and restore support |
If you use a second PBS, configure the sync job so snapshots that disappear on the source aren't removed on the target. Proxmox points out that this stops an attacker's deletions on the primary from spreading to your copy.
How do you check that your Proxmox backups actually restore?
Run verification jobs for integrity, and do real test restores for recoverability. A verification job tells you the stored data matches its checksums. Only a restore tells you the VM boots and the application works.
The PBS maintenance documentation recommends re-verifying all backups at least monthly, even if they passed before, because disks degrade over time. A workable routine looks like this:
- Schedule a verification job for new snapshots, plus a monthly job that re-verifies everything.
- Each month, restore one VM to a new guest ID on an isolated network, never over the original.
- Check that it boots, that services start and that recent data is there.
- Time the restore and compare it with how long the business can be without that system.
- Use file restore to pull back a single file, so the team knows the steps.
- Record the result as evidence for auditors.
We go deeper into test levels and metrics in how to verify your backup works.
What should you look for in a managed Proxmox backup?
Look for a copy separate from your Proxmox estate in every sense: another location, other credentials, storage that can't be altered, and daily checks.
- Location and law: where is the data stored, and which jurisdiction applies? Our Proxmox backups stay in our own Tier III data centres in the Netherlands and Germany, under EU law and independent of US hyperscalers.
- Immutability and air gap: we keep immutable backups with Object Lock plus an air-gapped copy, following the 3-2-1-1-0 rule.
- Checks and monitoring: every backup job is checked automatically, backups are scanned for malware and the platform is monitored 24/7.
- Access control: admin actions require MFA, and data is AES-256 encrypted in transit to our data centres.
- Restore help: granular restores, and personal support in Dutch, German or English when you need a VM back.
For organisations under NIS2, this is also a governance point. Article 21(2)(c) of the NIS2 Directive lists "business continuity, such as backup management and disaster recovery, and crisis management" among the required measures. See what Article 21 asks for. MSPs managing Proxmox for several clients can use our multi-tenant console; see our partner programme.
What to do next
Keep PBS. It's a sound first layer: fast local backups, deduplication, client-side encryption and quick restores. What it can't be is your only copy, because one server on one site under one set of admin accounts can be lost in one incident.
Check three things this week: can your backup clients delete snapshots, does a copy exist outside your building, and when did you last restore a VM to a new guest? Our backup as a service overview explains how that fits a wider strategy.
Want to see a Proxmox restore from an EU data centre? Book a free 15-minute demo and talk to an engineer in Dutch, German or English.
This article is information, not legal advice.
Frequently asked questions
Is Proxmox Backup Server free?
Yes. Proxmox Backup Server is free and open-source software, licensed under the GNU AGPL v3. You can download, install and use it without a licence fee. You still pay for the hardware or storage it runs on, the time to manage it, and any off-site copy you add, so the total cost depends on how you run it.
Does Proxmox Backup Server protect against ransomware?
Partly. PBS never rewrites existing data blocks, so ransomware on a Proxmox VE host can't alter backups that are already stored. An attacker who gains admin access to the PBS server itself can still delete them. Proxmox recommends restricted API tokens, server-side pruning, the 3-2-1 rule and an off-site copy to close that gap.
What does a Proxmox verification job check?
A verification job reads stored backup chunks and checks them against their SHA-256 checksums, so it detects corruption or tampering in the datastore. It doesn't prove that a VM will boot or that an application works after restore. Proxmox recommends re-verifying all backups at least monthly and combining that with regular test restores to new guests.
Can I restore a single file from a Proxmox backup?
Yes. In Proxmox VE, the File Restore option lets you browse the contents of a backup stored on Proxmox Backup Server and download individual files or folders. Folders are packed into a zip archive on the fly. You don't need to restore the whole VM or container, which makes small recoveries much quicker.
How do I create an offsite copy of Proxmox backups?
There are three common routes. You can run a second Proxmox Backup Server at another site and use sync jobs to copy snapshots, write backups to tape and store the tapes off-site, or use a managed backup service that keeps an immutable copy in its own data centres. Whichever you choose, keep its credentials separate from production.
Sources
- Proxmox Backup Server documentation: IntroductionProxmox Server Solutions, 2026
- Proxmox Backup Server documentation: Backup storage (ransomware protection and recovery)Proxmox Server Solutions, 2026
- Proxmox Backup Server documentation: Maintenance tasksProxmox Server Solutions, 2026
- Proxmox Backup Server documentation: Managing remotes and syncProxmox Server Solutions, 2026
- Proxmox VE: Backup and RestoreProxmox VE wiki, 2026
- VMware: Broadcom faces EU complaint over unfair licensingComputer Weekly, 2024
- Directive (EU) 2022/2555 (NIS2 Directive)EUR-Lex, Publications Office of the European Union, 2022


