REST API knowledge exchange
Post Reply
fabbar
Novice
Posts: 9
Liked: 5 times
Joined: Jan 02, 2024 10:42 am
Contact:

granular permission/roles and access via API key

Post by fabbar » 1 person likes this post

Hi All,
I would like to ask if console permission will be more granular in future. I think that Administrator, Viewer and Operator roles (I'm actually going by memory) are not so feasible by now.

I'm exploring API integration and I think it would be useful if a user can perform some "not-readonly" activities without being a full administrator.
In our environment all VBR admins people are MFA enabled and I would not like to enable a full administrator service user .

In addition, will be available API key login in the future?

thanks,
f
Mildur
Product Manager
Posts: 10291
Liked: 2747 times
Joined: May 13, 2017 4:51 pm
Full Name: Fabian K.
Location: Switzerland
Contact:

Re: granular permission/roles and access via API key

Post by Mildur »

Hello Fabbar

Better RBAC roles is something we may look into for a future version. But no ETA today.
Can you share examples what you are looking for?
In addition, will be available API key login in the future?
I moved your topic to the RestAPI forum.
No news today. We count your request as +1.

Best,
Fabian
Product Management Analyst @ Veeam Software
fabbar
Novice
Posts: 9
Liked: 5 times
Joined: Jan 02, 2024 10:42 am
Contact:

Re: granular permission/roles and access via API key

Post by fabbar »

Can you share examples what you are looking for?
automatic password rotation.
bye
fabbar
Novice
Posts: 9
Liked: 5 times
Joined: Jan 02, 2024 10:42 am
Contact:

Re: granular permission/roles and access via API key

Post by fabbar » 1 person likes this post

Mildur wrote: Feb 19, 2024 9:35 am Can you share examples what you are looking for?
In addition I would hope that communication/authentication for Veeam products will be available w/certificates or API keys or one time password (such as hardened repo).
We have set up our VBR environments with MFA and only personal administrator accounts for backup management (and company is happy for this) but for Veeam One integration it seems we must have a service user for Veeam One Agent that is a Local Admin.
MFA helps you with sysadmin (human person) credential compromise but if you are forced to use local admins and their password management attachers are kicked out from door but can re-enter through the windows.
Post Reply

Who is online

Users browsing this forum: No registered users and 18 guests