Table of contents
Overview
Acronis Cyber Protect delivers a unified cyber resilience platform that combines data protection, cybersecurity, and endpoint management in a single, integrated solution.
It’s designed for organizations that require data sovereignty and compliance, supporting both fully air-gapped deployments and environments with internet connectivity.
One integrated solution
- Data sovereignty and control: Keep management and data within your perimeter to meet strict compliance and data residency requirements.
- Broad workload protection: Safeguard legacy systems, OT infrastructures, and modern virtualized platforms — including VMware, Hyper-V, Nutanix, Proxmox, and more.
- Rapid recovery: Enable one-click restores to minimize downtime and empower end users with self-service recovery.
- Integrated security: Protect endpoints with built-in anti-malware, ransomware protection, and vulnerability and patch management.
- Operational efficiency: Reduce cost and complexity by consolidating backup, recovery, and security in one centrally managed solution.
This major release delivers enhanced performance and strengthened cyber resilience — enabling customers to maintain full control of their data across any environment.
What's new in Acronis Cyber Protect 17 Update 1
On-premises deployment
SIEM Connector
Enables customers to easily export Acronis security data into their SIEM platforms for unified visibility, and faster detection and response.
Key Benefits
- Easy setup, better compliance and broader data coverage.
- Integrated directly into protection plans and uses the Acronis agent as the data writer.
- Delivers continuous, audit-ready event trails across protection and security control.
- Exports alerts, events, activities and tasks in CEF or JSON format to a file path for ingestion by any SIEM platform.
- Simplifies configuration by eliminating the need for syslog servers.
Run as VM on Proxmox VE
Instantly mount backups of Windows or Linux machines as ready-to-use virtual machines on Proxmox VE, providing immediate access to workloads while full recovery proceeds.
Key Benefits
- Immediate access to production workloads directly from backup.
- Supports cross-platform mounting, including physical-to-Proxmox VE.
Supported Scenarios
- Instant restore of Windows or Linux machine backups as VMs on Proxmox VE.
- Finalization of the mounted VM to permanent storage.
Agentless backup of Scale Computing Hypercore versions 9.5 and 9.6
This release adds support for agentless backup of Scale Computing Hypercore versions 9.5 and 9.6.
Nutanix virtual appliance deployment from UI
You can deploy Agent for Nutanix from the Cyber Protect console, without manually creating a virtual machine in the Nutanix cluster.
Supported Scenarios
- When the deployment completes, the virtual appliance appears under Devices and the Nutanix virtual machines in the cluster become available for protection.
Cloud deployment
SIEM Connector
Enables customers to easily export Acronis security data into their SIEM platforms for unified visibility, and faster detection and response.
Key Benefits
- Easy setup, better compliance and broader data coverage.
- Integrated directly into protection plans and uses the Acronis agent as the data writer.
- Delivers continuous, audit-ready event trails across protection and security control.
- Exports alerts, events, activities and tasks in CEF or JSON format to a file path for ingestion by any SIEM platform.
- Simplifies configuration by eliminating the need for syslog servers.
Agent for Windows on ARM
The Acronis Cyber Protection agent is now available for Windows devices running on ARM processors, delivering backup, recovery, antimalware protection,remote management, vulnerability scanning, and patch deployment from a single console.
Key Benefits
- Unified protection for both x86 and ARM CPU-based Windows workloads.
- Includes backup and recovery, antimalware, and remote management via Cyber Scripting.
- Closes the vulnerability assessment gap for ARM-based Windows devices.
- Consistent patch remediation across x86/x64 and ARM endpoints.
Supported Scenarios
- Remote installation of the protection agent on ARM devices (Windows 11 and Windows Server 2025 or later).
- Disk and file backup and restore, antimalware protection, and remote management for Windows ARM workloads.
- Disk and file backup and restore via bootable media.
- Continuous data protection (CDP) for ARM workloads.
- Restore with reboot (Secure Boot must be disabled on ARM devices).
- Vulnerability scanning for OS and third-party applications on Windows ARM devices.
- Patch deployment to ARM-based Windows endpoints via existing protection plans.
Microsoft Entra ID Backup
Microsoft Entra ID (formerly Azure Active Directory) organizations can now be backed up and recovered, protecting authentication and access management data against accidental deletion or corruption.
Key Benefits
- Protection for heavily used Microsoft-based authentication and access management infrastructure.
- Granular recovery at the organization, object, record, and individual property level.
Supported Scenarios
- Backup of an Entra ID organization and comparison with live data or other backups.
- Recovery at any level: organization, object, record, or individual property.
- Download of any object, including audit and sign-in logs.
Custom User Roles
Tenant administrators can now define custom roles with specific permission sets, enabling fine-grained access control beyond the available built-in roles.
Key Benefits
- Greater flexibility to delegate tasks without granting full administrative rights.
- Custom roles are reusable and inherited by child tenants.
- Supports RBAC compliance requirements (ISO/IEC 27001, NIST Cybersecurity Framework, SOC 2, GDPR).
Supported Scenarios
- Create custom roles with a required set of permissions and assign them to users.
- Child tenant administrators can use or clone and further customize parent tenant custom roles.
AI-powered summaries of remote desktop sessions and in-session recommendations
Acronis AI automatically generates summaries of remote desktop sessions and provides real-time troubleshooting recommendations during live sessions, improving technician efficiency and service consistency.
Key Benefits
- Automatic session summaries with AI-categorized issue types and resolution status.
- Real-time, context-aware troubleshooting guidance during live sessions.
- Shareable session summaries and recordings for training, escalation, and compliance purposes.
Supported Scenarios
- Automatic generation of remote session summaries with all actions taken.
- AI-based in-session recommendations for resolving technical issues.
- Detection of anomalous user behavior during remote sessions.
Backup: Change Archive Password
Administrators can now change the password of an encrypted backup archive directly in the protection plan, without revoking and re-creating the plan.
Key Benefits
- Simplified response to compromised archive passwords.
- Supports regular password rotation as required by company policy.
Supported Scenarios
- Change the archive password for machines with an installed protection agent (physical servers, workstations, and agent-based VMs). Supported on v12 (tibx) backup format only.
Microsoft 365 onboarding wizard
The guided wizard accelerates Microsoft 365 onboarding with significantly reduced setup steps.
Key Benefits
- Minimize the onboarding process duration
- Remove setup complexity
- No training needed
Supported Scenarios
- Protect everything by default
- Protect specific workloads in the M365 organization
- Quick onboard partners to Acronis
- Backup an entire Microsoft 365 organization, or select the workloads to backup
Limitations
- Exclusions are not supported in this release.
Support for Synology Marketplace
The Acronis Cyber Protection agent for Synology can now be installed directly through the Synology Package Center, simplifying agent deployment on Synology NAS devices.
Supported Scenarios
- Agent installation via the Synology Package Center (DSM 7.x supported).
What's new in Acronis Cyber Protect 17
On-premises deployment
Agentless Backup for Nutanix AHV
Effortlessly protect Nutanix environments with agentless backup and seamless recovery — no agents, no complexity.
Key Benefits
- Native Nutanix integration, cross-platform recovery, flexible storage options.
Supported Scenarios
- Backup and recovery of Nutanix AHV VMs, migration to and from other platforms.
All editions.
Agentless Backup for Proxmox VE
Protect your Proxmox VE infrastructure with zero-touch backups and intuitive recovery — all from a single console.
Key Benefits
- No per-VM agents, centralized management, cross-platform recovery.
Supported Scenarios
- Backup of Proxmox VE VMs, recovery of physical machines as Proxmox VMs.
Licensing
All editions.
Role-Based Access Control
Empower your teams with precision access — assign roles, reduce risk, and streamline operations.
Key Benefits
- Role-based access control with precise roles (Backup Admin, Restore Operator, Security Admin) minimizes human error, reduces insider risk, and ensures compliance alignment.
Supported Scenarios
- Role-based access for backup, restore, and security operations.
Licensing
All editions.
Device Sense™ Discovery
Uncover every device in your network — even the hidden ones — and close protection gaps before they become threats.
Key Benefits
Instant discovery, identifies unmanaged endpoints, strengthens security posture.
Supported Scenarios
-
Network-wide device visibility and onboarding.
Limited to registered network segments.
Licensing
All editions.
Software and Hardware Inventory
Gain full visibility into your IT assets — track, manage, and optimize with confidence.
Key Benefits
- Real-time inventory, automated scans, simplified maintenance.
Supported Scenarios
-
Asset discovery, update planning, compliance tracking.
Requires agent installation.
Licensing
Standard and Advanced editions.
Support for New Operating Systems
Stay ahead with expanded OS support — protect the latest platforms from day one.
Key Benefits
- Compatibility with modern IT and OT environments, extended protection.
Supported Scenarios
- Backup and recovery for Windows Server 2022/2025 Essentials, Ubuntu 24.10, Fedora 39–41, Oracle Linux 9.5, CloudLinux 9.5, AlmaLinux 9.5, Rocky Linux 9.4, 9.5, Red Hat 9.5.
Licensing
All editions.
Cloud deployment
Support for macOS 26 Tahoe
This release adds complete cyber protection for macOS 26 Tahoe workloads.
Key Benefits
- Ensures readiness for the latest macOS release.
Supported Scenarios
- Backup and protection of macOS 26 Tahoe systems.
Licensing
All editions.
Detection and Response: Automated Uninstallation Protection for Acronis Agent
Now active protection blocks automatically any attempt to uninstall the protection agent as prevention to ransomware attacks. Administrators can allow the uninstallation and updates of agents during a configurable maintenance period. This feature replaces the password protection functionality in self protection.
Key Benefits
- Strengthens endpoint security.
- Prevents unauthorized agent removal.
Supported Scenarios
- Agent uninstallation and updates are blocked by default.
- An administrator can configure a maintenance period (1 hour to 7 days).
Licensing
Advanced edition.
Installation notes
Upgrading the Cyber Protection agent
The Cyber Protection agent can be updated directly to Acronis Cyber Protect 17 from any version of Acronis Cyber Protect 15 or 16.
Updating the Management server (MMS)
The Acronis Management Server can be updated directly to Acronis Cyber Protect 17 from any version of Acronis Cyber Protect 16. If you are using Acronis Cyber Protect 15 management server, you must upgrade it to 16 first, and then upgrade to 17.
Updating the Acronis Storage Node
Acronis Storage Node version 17 requires agents version 17. It does not work with older agents, such as v16, v15, and v12.5. Do not install the storage node component if you still have older agents running on protected workloads.
Important
-
Updating from older builds requires an active subscription license or support maintenance agreement. Verify that you have a valid subscription license or support maintenance agreement before you initiate an upgrade.
- If you are using BitLocker on protected workloads, suspend or disable BitLocker before updating the Cyber Protection Agent. After the update, enable BitLocker again. If you fail to disable BitLocker before the update, the BitLocker recovery key will be required after you restart the workload. See product documentation.
- If you plan to use the immutable storage functionality, see Updating the Account Server certificate.
- If you plan to use Virtual Host/Universal licenses for protection of virtual machines by running a protection agent inside them (agent-based backup), see this knowledge base article.
Issues fixed in Acronis Cyber Protect 17 Update 1 (Build 42587)
A part of Acronis Cyber Protect 17 Update 1
Fixed in build 42587
Security
For information about security issues fixed in this release, please refer to https://security-advisory.acronis.com/updates/UPD-2606-cfba-926e.
Backup
- [ABR-422104] When multiple machines back up to the same deduplication vault on the Acronis Storage Node, backup activities may get stuck at 7%.
- [ABR-420035] Backup to Acronis Cloud may fail with the error 'The activity has failed due to a crash of the managed machine service.'
- [ABR-413028] Scheduled backups do not start as expected.
Common
- [ADP-45490] Dashboard and Reports are only available in English.
- [PLTFRM-90470] Protection plan statuses are shown incorrectly in the Status column of the Protection plans tab.
- [ABR-418163] Management servers registered for offline use may incorrectly display the notification 'This management server has been offline for XX days.'
- [ABR-414048] SMTP server settings cannot be saved in the Acronis Cyber Protect management console when the management server is installed on Windows 10 or Windows 11.
- [ABR-308314] After a daylight saving time change, the Daily recap email shows an incorrect time in the email body.
- [ABR-306960] After changing the 'Send at' time for the daily recap email, multiple recap emails are sent instead of one.
- [ABR-255115] When a network card is disconnected or missing, the Cyber Protection agent fails to register on the management server.
Installation and upgrade
- [ABR-429451] After updating the Cyber Protection agent, real-time protection and scheduled scans are not available due to an incompatible or missing driver.
- [ABR-414906] Upgrading to Acronis Cyber Protect 17 fails with a PostgreSQL authentication error.
- [ABR-200522] Installation of the Cyber Protection agent on Windows XP SP3 fails with a fatal error when Avast antivirus is installed.
Licensing
- [ABR-426913] The Windows Server Essentials license cannot be assigned to a Windows Server 2025 domain controller.
Protection agent
- [ABR-426133] After updating the Cyber Protection agent, the log files grow excessively and consume too much disk space.
Recovery
- [ABR-418392] The Flavor selector is not visible in the VM restore wizard.
- [ABR-317576] The recovery activity progress is stuck at 15% even after the recovery has completed successfully.
Tapes management
- [ABR-411736] Always incremental application backup to tape may fail with the error: "Path 'atis:/tape?' does not exist."
- [PLTFRM-83388] The archive refresh operation may fail if the location is an Acronis Storage Node with tapes.
- [ABR-404471] File recovery from a tape archive completes with the warning 'No files recovered' even though all files were successfully restored.
- [ABR-397235] Replication from a managed location to tape takes an excessively long time to complete.
- [ABR-328759] After upgrading from Acronis Backup 12.5, the occupied space for tapes is displayed as 0 bytes.
Virtualization
- [ABR-411830] Backup of a VM on a network share with replication to tape may fail with the error: "An archive with the same name already exists."
- [ABR-425998] The "Not enough RAM" alert is triggered after updating the protection agent on a virtual appliance, and the virtual appliance might crash.
- [ABR-421218] Proxmox VM backup completes with the warning 'The selected storage does not support snapshots. To improve performance and apply changes incrementally, choose a storage that supports snapshots.'
Issues fixed in Acronis Cyber Protect 17 (Builds 42054, 41676, 41224, 41186)
A part of Acronis Cyber Protect 17 Hotfix 3
Fixed in build 42054
- [ABR-420115], [ABR-420960] The Acronis Storage Node might fail when multiple machines are backed up to the same deduplication vault simultaneously.
Installation and upgrade
- [PLTFRM-86486] Upgrading from Acronis Cyber Protect 16 (build 38093) to version 17 on a machine with an external Microsoft SQL Server database fails because the backup manager service does not start after the upgrade, and the Management Console becomes inaccessible.
Licensing
- [ABR-419813] On Windows Server Essentials 2022 and 2025, the license eligibility might be evaluated incorrectly, preventing the Windows Server Essentials license from being assigned.
Linux protection
- [PLTFRM-86006] On Linux systems with GNU C Library (glibc) earlier than version 2.28 (such as Red Hat Enterprise Linux 7), the License Manager in on-premises installation fails to start.
Networking
- [ABR-419514] After the network is disconnected and reconnected, duplicate TCP connections may be established between the management server and the protection agent.
Patch management
- [ABR-419349] When a patch management plan with the Pre-update backup option is run, the safety backup fails, and patching does not proceed.
PostgreSQL
- [ABR-418394], [ABR-418396] On a fresh installation of Acronis Cyber Protect 17, the PostgreSQL database service may consume excessive amounts of RAM. This issue has now been resolved, and memory usage is significantly reduced.
Protection
- [AMP-43711] When proxy settings include a no-proxy exclusion list, the exclusions are not respected when checking for or downloading malware protection updates. Additionally, if the proxy configuration changes while the product is running, the updated settings are not applied to update operations.
- [ADP-48279] Unnecessary internet connectivity checks are performed before downloading antivirus and antimalware definition updates in certain network configurations.
Tapes management
- [ABR-416582] After a successful backup to tape with the Eject tape after every successful backup option enabled, tape ejection fails with the error "The string resource is not found."
A part of Acronis Cyber Protect 17 Hotfix 2
Fixed in build 41676
Common
- [PLTFRM-85371] Users are unexpectedly logged out of the Management Console after clicking a tab.
Licensing
- [ABR-414643] The Essentials license is not available for Windows Server machines with less than 10 CPU cores.
Linux protection
- [ABR-413210] "Storage Node" is available as an installation option for Agent for Linux although it is not supported on Linux machines.
Protection agent
- [ABR-414357] Service log files are consuming excessive disk space on protected workloads.
Protection console
- [ABR-412327] Sending reports manually does not work as expected.
- [ABR-412817] The number of CPUs is not properly reported for Windows Server machines.
- [ADP-45842] The Overview tab does not display any data.
Recovery
- [ABR-404578] The progress of recovery tasks of entire machine backups shown in the bootable media interface does not match the status of these recovery tasks in Acronis Management Server web console.
Tapes management
- [ABR-411796] Deleting backups from tapes fails with SQL-related errors.
A part of Acronis Cyber Protect 17 Hotfix 1
Fixed in build 41224
Installation and upgrade
- [PLTFRM-83676] The update to Acronis Cyber Protect 17 might fail at the agent registration stage if an existing backup validation plan contains credentials to VMware.
Recovey
- [ABR-411648] Sometimes image restore of Windows 11/Windows Server 2025 doesn't work if Windows Update KB5007651 is installed on the computer.
Virtualization
- [ABR-411831] After an upgrade from version 16 to version 17, backup validation plans that use network storage (a VMB archive located on a network share) may fail with the error “Access Denied”.
A part of Acronis Cyber Protect 17
This product version is based on the code base of Acronis Cyber Protect 16 Update 4. All fixed issues were present in the latest build of Acronis Cyber Protect Update 4, build 40354 (July, 2025). For more information, see the Acronis Cyber Protect 16 release notes.
Fixed in build 41186
Security
For information about the security issues fixed in this release, see https://security-advisory.acronis.com/updates/UPD-2510-e871-9553.
Backup and replication
- [ABR-404530] Backup and replication tasks fail due to issues with the service_process.exe.
- [ABR-401838] Deleting backups from managed storage vaults fails with the error "Unknown archive:"
- [ABR-376101] The replication of SQL backups created by the Always full scheme does not work as expected.
Bootable media
- [ABR-385716] Incorrect characters appear in the UI of the media builder wizard in Japanese language.
Common
- [ABR-204436] Unable to recover OneDrive files from disk backups.
- [ABR-246800] Retention rules are not properly processed in replication plans.
- [ABR-313181] The following error might occur when opening the Details page of a protected workload: "The path 'C:\ProgramData\Acronis\AMS\AccessVault\profiles\...\meta' does not exist."
- [ABR-345007] Recovering backups from one NAS to another fails with errors indicating incorrect credentials.
- [ABR-346613] Attempt to create a dynamic group by using the 'ou' criterion and 'IN' operator fails with the error "1:1 Invalid operation 'in' for 'ou' field."
- [PLTFRM-78034] Registration tokens expire prematurely after a single use due to incorrect parsing of the UNIX timestamp format in the database.
Installation
- [ABR-265753] Backups fail with the error "couldn't get upstream token, failed to get upstream token provider" after an agent update.
- [ABR-178648] The MMS service might not operate as expected if the agent update operation was interrupted.
- [ABR-399457] On rare occasions, agent updates might fail with the error "DIFXAPP: UninstallDriverPackages failed with error 0x2.
Linux protection
- [ABR-341164] Recovery operations on Linux might fail due to missing drivers for the RAID controller.
Protection console
- [ABR-402780] Executing a protection plan via "Run now" button may produce incremental backups instead of full ones, if the plan was created selecting "Always full" scheduling schema, while there was "simple UI" mode enabled in the web console interface.
- [ABR-208735] The deleting of archives under an expired trial account on Acronis cloud fails with the error "Failed to execute the command. Deleting recovery points. Invalid operation on read-only object."
- [ABR-298851] The reported usage of the virtual host license for VMware ESXi clusters is incorrect.
- [ABR-411040] The status in backup plans is indicated as failed even though backups complete successfully.
- [ABR-337561] The virtual host license doesn't allow backing up all KVM hosts and KVM guests
- [ABR-335382] The status of the protection plan is OK even though there are errors in some backups.
- [ABR-372609] The status of the protection plan indicates errors while backup operation are running with no issues.
Storage operations
- [ABR-314132] The error "Lease request conflicts with another lease" appears when several backups are deleted consecutively.
- [ABR-225424] Entire machine recovery hangs at around 88% in management console even though recovery completed successfully. The following error appear: "error 0x142711: The system has rebooted without cleanly shutting down first."
- [ABR-297729] Recovery points are being loaded very slowly.
Tapes management
- [ABR-254513] "The "No backups" message appears when trying to restore backups from tape after an agent update.
Known issues
This section describes known issues and provides solutions where possible.
Common
- [ABR-334079] Activities for deleted agents are not cancelled properly.
Recovey
- [ABR-411444] Restoring a forensic encrypted image backup from a network share may fail.
Tapes management
- [ABR-385806] Recovery from full backups on tapes is not possible if the caches for their corresponding incremental backups are missing due to partial archive corruption.
- Workaround: Perform tapes re-scan.