Comprehensive data protection for all workloads
Post Reply
david.brunner
Enthusiast
Posts: 27
Liked: 1 time
Joined: Jan 07, 2021 10:00 am
Full Name: David Brunner
Contact:

B&R Windows Domain Admin Credentials BP?

Post by david.brunner »

Dear forum,

I hope it is not a stupid question. It is written about somewhere but with all the info overload I can´t find the proper answer.

It is best practice to keep the B&R Server out of domain, secured by firewall, have an immutable storage... so attackers from internal network have a harder time getting TO the Backup area

But the other way around? For example for backup an AD Domain Server VM, you need to provide "Domain Admin" credentials to the B&R server so it can fully process it. for example written here: https://helpcenter.veeam.com/docs/backu ... =120#rptcb

especially:
To process a Domain Controller server, make sure that you are using an account that is a member of the DOMAIN\Administrators group.
Meaning, there is no better practice (BP) to resolve it by lesser permissions? What if attackers infiltrate the Veeam B&R server ( beats me - in any unimaginable way... doesn´t matter..) then they get hold of full Domain Admin privileges


Is this still how it is supposed to be?
With a dedicated User with "Domain admin" rights, which only serves as a "service account", complex password and is never used to logon, of course.

Or would it be better to create (if not existing) an RODC for this purpose and have Veeam only access this one with RODC account permissions?

Sorry for stupid questions, but I try to think about holes in the system right now / kind of Audit.

Thanks!
David
Mildur
Product Manager
Posts: 8735
Liked: 2294 times
Joined: May 13, 2017 4:51 pm
Full Name: Fabian K.
Location: Switzerland
Contact:

Re: B&R Windows Domain Admin Credentials BP?

Post by Mildur » 1 person likes this post

Hi David

Starting in V12, you can use gMSA to backup the Domain Controller:
https://helpcenter.veeam.com/docs/backu ... ml?ver=120

You can also use Veeam Agent and the preinstalled Agent protection group:
https://helpcenter.veeam.com/docs/backu ... ml?ver=120

With Preinstalled Agents, you don't provide an account for the backup of the domain controller backup. The installation of the Agent needs to be done manually by your or by another automation application.

Best,
Fabian
Product Management Analyst @ Veeam Software
david.brunner
Enthusiast
Posts: 27
Liked: 1 time
Joined: Jan 07, 2021 10:00 am
Full Name: David Brunner
Contact:

Re: B&R Windows Domain Admin Credentials BP?

Post by david.brunner »

Thanks!
Sorry, information overload.

RTFM is often a good answer but mainly impossible in daily work...

I try with gMSA first. Seems the fastest approach to change.

best regards,
David
Post Reply

Who is online

Users browsing this forum: No registered users and 113 guests