-
alu
- Lurker
- Posts: 2
- Liked: never
- Joined: Mar 09, 2016 1:38 pm
- Contact:
Endpoint Backup User repositoreis best practice
Hello
My task is to back up notebooks from users with endpoint backup to a Veeam Server. Important is that the users can only see their own backup. My idea is to create for each user (~30) a repository and add the specific AD user. Is that the best way? Can the user do a recovery on their own?
Or is it better with encryption (not on users harddrive)?
Thanks
My task is to back up notebooks from users with endpoint backup to a Veeam Server. Important is that the users can only see their own backup. My idea is to create for each user (~30) a repository and add the specific AD user. Is that the best way? Can the user do a recovery on their own?
Or is it better with encryption (not on users harddrive)?
Thanks
-
Dima P.
- Product Manager
- Posts: 15033
- Liked: 1886 times
- Joined: Feb 04, 2013 2:07 pm
- Full Name: Dmitry Popov
- Location: Prague
- Contact:
Re: Endpoint Backup User repositoreis best practice
Hello alu,
That is a perfect idea, the best is, however, to set up a dedicated ‘backup’ account for every user and let only VEB job know the creds (BTW AD computer accounts can be used for setting the access to the repository). With last approach you will protect your backups in the repository from unauthorized access of malware that can be executed by regular end user account. Encryption on backup repository can help as well.
That is a perfect idea, the best is, however, to set up a dedicated ‘backup’ account for every user and let only VEB job know the creds (BTW AD computer accounts can be used for setting the access to the repository). With last approach you will protect your backups in the repository from unauthorized access of malware that can be executed by regular end user account. Encryption on backup repository can help as well.
-
poussah
- Influencer
- Posts: 11
- Liked: never
- Joined: Mar 26, 2014 4:01 pm
- Full Name: Renaud Boitouzet
- Location: Paris, France
- Contact:
Re: Endpoint Backup User repositoreis best practice
Follow up question: if the repository is authorized for all relevant AD users but the storage target (NAS) is on a separate network and thus not directly accessible to the users, could a malware damage the backup files?
-
Dima P.
- Product Manager
- Posts: 15033
- Liked: 1886 times
- Joined: Feb 04, 2013 2:07 pm
- Full Name: Dmitry Popov
- Location: Prague
- Contact:
Re: Endpoint Backup User repositoreis best practice
Renaud,
Most likely NAS remains hidden.
Most likely NAS remains hidden.
-
Vitaliy S.
- VP, Product Management
- Posts: 27879
- Liked: 2985 times
- Joined: Mar 30, 2009 9:13 am
- Full Name: Vitaliy Safarov
- Contact:
Re: Endpoint Backup User repositoreis best practice
Yes, all user sensitive data is encrypted with machine specific key using WinAPI.JChris wrote:My question is, how secure will be Mike_BK credential stored inside Veeam software? Do you guys encrypt the credentials or something like that?
Yes, seems good to me.In short, anyone would be able to create his "Backup Job for XYZ" inside /backup and put their files in there, but wouldn't be able to affect other user folders. Is that a good approach?
-
folerx
- Expert
- Posts: 115
- Liked: 8 times
- Joined: Jun 22, 2016 9:47 pm
- Full Name: Daniel Kaiser
- Contact:
Re: Endpoint Backup User repositoreis best practice
ok, but what is best practices if b&r server is not domain member? one repository, multiple?
today i receive 6x8tb hdds and need to configure test repository. 50 clients in domain.
also how to schedule backup across day? wont overload repository. 3gb incremental per day/client changes.
today i receive 6x8tb hdds and need to configure test repository. 50 clients in domain.
also how to schedule backup across day? wont overload repository. 3gb incremental per day/client changes.
-
Vitaliy S.
- VP, Product Management
- Posts: 27879
- Liked: 2985 times
- Joined: Mar 30, 2009 9:13 am
- Full Name: Vitaliy Safarov
- Contact:
Re: Endpoint Backup User repositoreis best practice
If Veeam B&R is not a member of a domain, you can still use 1 or multiple repositories, all VEB users will see only their backup files. Scheduling is a bit tricky, you need to do that for all clients individually. There is no central management for Veeam Endpoint Backup / Veeam Agent for Windows yet, however you can set a limit of concurrent tasks on the repository that would fit best to your deployment.
Who is online
Users browsing this forum: No registered users and 1 guest