A few months ago we archived some SharePoint data up to AWS S3 OneZone-IA and encrypted it with a customer provided key (Veeam generated). We then created a lifecycle rule on the S3 bucket to push the data down to Glacier Deep Archive to cut storage cost. Veeam for Microsoft 365 cannot read data in buckets/locations with storage tiers below OneZone-IA. Well, a few days ago, some user decided she needed some Excel doc from the archived data.
I realize NOT encrypting the data would have avoided this mess but our company policy/compliance requirements dictate that archived data must be encrypted at rest. So, I was wondering if Veeam might be able to develop a way to pull the key from the database it's tied to so customers such as ourselves can provide some relief for users asking for data to be pulled from AWS Glacier archives.
Thanks!