Discussions related to using object storage as a backup target.
Post Reply
NAP-LN
Novice
Posts: 7
Liked: never
Joined: Feb 20, 2023 2:11 am
Contact:

Veeam VBR - Account for Azure Blob

Post by NAP-LN »

Setting up a VBR server - with M365 also on the same server - and attempting to connect to Azure blob storage. Azure is still fresh to me so trying to piece together all the information as on-prem is where I have been in the past.

Based on Microsoft article found here: https://learn.microsoft.com/en-us/azure ... -directory it states:
Authorization with Azure AD provides superior security and ease of use over Shared Key authorization. Microsoft recommends using Azure AD authorization with your blob applications when possible to assure access with minimum required privileges.
Authorization with Shared Key is not recommended as it may be less secure. For optimal security, disable authorization via Shared Key for your storage account, as described in Prevent Shared Key authorization for an Azure Storage account.

Use of access keys and connection strings should be limited to initial proof of concept apps or development prototypes that don't access production or sensitive data. Otherwise, the token-based authentication classes available in the Azure SDK should always be preferred when authenticating to Azure resources.

Microsoft recommends that clients use either Azure AD or a shared access signature (SAS) to authorize access to data in Azure Storage. For more information, see Authorize operations for data access.
I read that as we should not be using shared keys outside PoC and instead use token based Azure AD authentication. I set 'Azure AD user account' as the authentication method for the container and set the roles to access it but when running the Azure blob connection wizard only shared key is an option via VBR. Am I missing something when comparing the above MS article vs the Veeam set up?
HannesK
Product Manager
Posts: 14314
Liked: 2890 times
Joined: Sep 01, 2014 11:46 am
Full Name: Hannes Kasparick
Location: Austria
Contact:

Re: Veeam VBR - Account for Azure Blob

Post by HannesK »

Hello,
access keys are the only method supported by VBR (also VB365) today.

Best regards,
Hannes
gable
Veeam Software
Posts: 101
Liked: 7 times
Joined: Jun 11, 2012 3:05 pm
Full Name: gabriele pelizzari
Contact:

Re: Veeam VBR - Account for Azure Blob

Post by gable »

Thx all for your help

G.
apolloxm
Enthusiast
Posts: 93
Liked: 1 time
Joined: Aug 27, 2021 12:29 am
Contact:

Re: Veeam VBR - Account for Azure Blob

Post by apolloxm »

HannesK wrote: Feb 21, 2023 6:08 am access keys are the only method supported by VBR (also VB365) today.
Is this still valid for Veeam V12 and Veeam V12.1?
Mildur
Product Manager
Posts: 8678
Liked: 2276 times
Joined: May 13, 2017 4:51 pm
Full Name: Fabian K.
Location: Switzerland
Contact:

Re: Veeam VBR - Account for Azure Blob

Post by Mildur »

V12.1 supports now „ Microsoft Azure Storage Accounts (Entra ID)“ as well.

https://helpcenter.veeam.com/docs/backu ... ml?ver=120

Try „Storage Blob Data Reader“ role for the account instead of „Storage Blob Data Owner“.

Best,
Fabian
Product Management Analyst @ Veeam Software
Post Reply

Who is online

Users browsing this forum: No registered users and 8 guests