-
- Service Provider
- Posts: 7
- Liked: never
- Joined: Mar 07, 2023 6:02 am
- Full Name: Lee Murphy
- Contact:
[V13] veeamadmin MFA setup
Hi,
I was wondering for the Software Appliance if there was a potential to move the MFA setting for the veeamadmin user from the initial set up to the first login. I understand the desire to mandate it but it would make just as much sense to require a user to set it up via the Web UI on the First Login after the webui is online and doing it in the console is kind of clunky in my opinion
I was wondering for the Software Appliance if there was a potential to move the MFA setting for the veeamadmin user from the initial set up to the first login. I understand the desire to mandate it but it would make just as much sense to require a user to set it up via the Web UI on the First Login after the webui is online and doing it in the console is kind of clunky in my opinion
-
- Product Manager
- Posts: 14870
- Liked: 1800 times
- Joined: Feb 04, 2013 2:07 pm
- Full Name: Dmitry Popov
- Location: Prague
- Contact:
Re: [V13] veeamadmin MFA setup
Hello Lee,
We want to ensure that MFA for the host admin is enabled before we turn on web services and open the necessary ports, as this significantly reduces security risks. Thank you for your feedback!
We want to ensure that MFA for the host admin is enabled before we turn on web services and open the necessary ports, as this significantly reduces security risks. Thank you for your feedback!
-
- Chief Product Officer
- Posts: 32580
- Liked: 7882 times
- Joined: Jan 01, 2006 1:01 am
- Location: Baar, Switzerland
- Contact:
Re: [V13] veeamadmin MFA setup
@Dima P. there's nothing to protect on a net new install though? So I think it's a good idea to move MFA configuration to the first login.
Remember that the initial Veeam Infrastructure Appliance connection is completely passwordless for the same reason: it's empty.
Remember that the initial Veeam Infrastructure Appliance connection is completely passwordless for the same reason: it's empty.
-
- Influencer
- Posts: 10
- Liked: 1 time
- Joined: Sep 01, 2025 12:20 pm
- Full Name: Carlos Eduardo Esteves
- Location: Brazil
- Contact:
Re: [V13] veeamadmin MFA setup
I agree with suggestion: To make it to work in the installation from Web console in the VMware was very bad
-
- Product Manager
- Posts: 14870
- Liked: 1800 times
- Joined: Feb 04, 2013 2:07 pm
- Full Name: Dmitry Popov
- Location: Prague
- Contact:
Re: [V13] veeamadmin MFA setup
We will discuss the possibility of moving MFA initialization into the web UI. Thank you for sharing your thoughts!
-
- Veeam Legend
- Posts: 391
- Liked: 63 times
- Joined: Jun 30, 2015 9:13 am
- Full Name: Stephan Lang
- Location: Austria
- Contact:
Re: [V13] veeamadmin MFA setup
would add another vote for this!
I believe there is currently a bug in the MFA setup process.
I've tested it several times and noticed a few issues. First, the the font used to display the secret key for manual OTP setup is very hard to read. Characters like 1 and l, or O and 0, are nearly indistinguishable, which makes it easy to enter the wrong key. After several retries, I found that canceling and restarting the setup eventually displays a version of the key with more readable characters — but this workaround is far from ideal.
Even when I manage to enter the code correctly (I'm quite sure I did, despite the font issues), there's another problem: when I scan the QR code instead of entering the key manually, the generated OTP is different. I repeated this test multiple times. When entering the key manually in different tools, I consistently get the same OTP, and it works. However, scanning the QR code seems to generate a different secret, even though the setup dialog doesn’t show a new one.
Additionally, if I cancel the MFA setup and reopen it (without confirming the code), the secret key appears to be regenerated. I assume this is expected behavior and generally fine. However, the same issue persists: the QR code and the manually entered key still produce different OTPs..
maybe someone else Could please check if the secret used for the QR code is being regenerated or mismatched during the setup process?
not sure if i can or should open a support case on this? there aren't any logs of this... edit: i've create a case too now: Case #07827104
I believe there is currently a bug in the MFA setup process.
I've tested it several times and noticed a few issues. First, the the font used to display the secret key for manual OTP setup is very hard to read. Characters like 1 and l, or O and 0, are nearly indistinguishable, which makes it easy to enter the wrong key. After several retries, I found that canceling and restarting the setup eventually displays a version of the key with more readable characters — but this workaround is far from ideal.
Even when I manage to enter the code correctly (I'm quite sure I did, despite the font issues), there's another problem: when I scan the QR code instead of entering the key manually, the generated OTP is different. I repeated this test multiple times. When entering the key manually in different tools, I consistently get the same OTP, and it works. However, scanning the QR code seems to generate a different secret, even though the setup dialog doesn’t show a new one.
Additionally, if I cancel the MFA setup and reopen it (without confirming the code), the secret key appears to be regenerated. I assume this is expected behavior and generally fine. However, the same issue persists: the QR code and the manually entered key still produce different OTPs..
maybe someone else Could please check if the secret used for the QR code is being regenerated or mismatched during the setup process?
not sure if i can or should open a support case on this? there aren't any logs of this... edit: i've create a case too now: Case #07827104
-
- Product Manager
- Posts: 15496
- Liked: 3402 times
- Joined: Sep 01, 2014 11:46 am
- Full Name: Hannes Kasparick
- Location: Austria
- Contact:
Re: [V13] veeamadmin MFA setup
there is a known bug (1081697) in that area that should be fixed with 13.0.1when I scan the QR code instead of entering the key manually, the generated OTP is different
-
- Chief Product Officer
- Posts: 32580
- Liked: 7882 times
- Joined: Jan 01, 2006 1:01 am
- Location: Baar, Switzerland
- Contact:
Re: [V13] veeamadmin MFA setup
@HannesK I thought I saw in the report that the QR code always works but there are some occasional issues with the key for manual entry. Are you saying it's the other way around? I guess this is a good candidate to document as the first known issue, although based on the number of active installs very few users seem to be running into it.
-
- Product Manager
- Posts: 15496
- Liked: 3402 times
- Joined: Sep 01, 2014 11:46 am
- Full Name: Hannes Kasparick
- Location: Austria
- Contact:
Re: [V13] veeamadmin MFA setup
yes, that's also my understanding. The QR code always works.
And if I need to guess, than Stephan is using a password manager and there he inserts the key manually and then there is a difference between an app that uses the QR code vs. the password manager
And if I need to guess, than Stephan is using a password manager and there he inserts the key manually and then there is a difference between an app that uses the QR code vs. the password manager
-
- Veeam Legend
- Posts: 391
- Liked: 63 times
- Joined: Jun 30, 2015 9:13 am
- Full Name: Stephan Lang
- Location: Austria
- Contact:
Re: [V13] veeamadmin MFA setup
For my understanding, the OTP generated should always be the same as long as the same secret key is used—and that’s exactly what happens. The QR code is simply a visual representation of the secret key.
However, I suspect that when you click “Show QR Code” during setup, a new secret key is generated. Why do I think that? As long as I manually enter the original secret key and use the OTPs generated from it, the setup accepts them.
But once I click “Show QR Code,” only the OTPs generated from the QR code are accepted—the manually entered ones from the original secret key no longer work.
Imagine the authenticator app used to scan the QR code is lost or reset. The user then needs to recover access, because the OTPs are no longer valid. This mismatch can easily lead to confusion and potentially result in a support case.
However, I suspect that when you click “Show QR Code” during setup, a new secret key is generated. Why do I think that? As long as I manually enter the original secret key and use the OTPs generated from it, the setup accepts them.
But once I click “Show QR Code,” only the OTPs generated from the QR code are accepted—the manually entered ones from the original secret key no longer work.
This might cause problems when a user tries to generate OTPs using the secret key (for example, one stored in KeePass), and the codes don’t work—because someone scanned also the QR code during setup, which generated a different OTPs.Gostev wrote: ↑Sep 18, 2025 9:02 am @HannesK I thought I saw in the report that the QR code always works but there are some occasional issues with the key for manual entry. Are you saying it's the other way around? I guess this is a good candidate to document as the first known issue, although based on the number of active installs very few users seem to be running into it.
Imagine the authenticator app used to scan the QR code is lost or reset. The user then needs to recover access, because the OTPs are no longer valid. This mismatch can easily lead to confusion and potentially result in a support case.
-
- Product Manager
- Posts: 15496
- Liked: 3402 times
- Joined: Sep 01, 2014 11:46 am
- Full Name: Hannes Kasparick
- Location: Austria
- Contact:
Re: [V13] veeamadmin MFA setup
your understanding is correct and the bug will be fixed 

-
- Chief Product Officer
- Posts: 32580
- Liked: 7882 times
- Joined: Jan 01, 2006 1:01 am
- Location: Baar, Switzerland
- Contact:
Re: [V13] veeamadmin MFA setup
Super, thank you @DaStivi for laying the issue out so clearly. This goes directly into the Top Issues posts I'm about to publish.
Who is online
Users browsing this forum: Bing [Bot], iain@visionlab.nz and 91 guests