-
pirx
- Veteran
- Posts: 665
- Liked: 99 times
- Joined: Dec 20, 2015 6:24 pm
- Contact:
[v13] veeamadmin account and personal MFA account
I just noticed aomething as I added the veeamadmin account to my authenticator app during deployment. I added the password to our interval vault but what about MFA? I know that it's best practice to have dedicated named users for working day to day with appliance. But having the MFA accounts for veeamadmin etc just in one persons authenticator app doesn't feel right. I've to admin, I did not run into such a situation before, maybe there is already a simple solution.
-
Gostev
- Chief Product Officer
- Posts: 32973
- Liked: 8091 times
- Joined: Jan 01, 2006 1:01 am
- Location: Baar, Switzerland
- Contact:
Re: [v13] veeamadmin account and personal MFA account
Yes, this is not a problem indeed because you can just enter the TOTP seed value into multiple authenticator apps for redundancy. And also store this seed in your internal vault so you can use it in future in even more authenticator apps 
-
pirx
- Veteran
- Posts: 665
- Liked: 99 times
- Joined: Dec 20, 2015 6:24 pm
- Contact:
Re: [v13] veeamadmin account and personal MFA account
I somehow expected this... as I have no access to Windows v13 console, where can I find TOTP seed after deployment? I checked VBR Web GUI and Host Management user. MFA reset needed?
-
Gostev
- Chief Product Officer
- Posts: 32973
- Liked: 8091 times
- Joined: Jan 01, 2006 1:01 am
- Location: Baar, Switzerland
- Contact:
Re: [v13] veeamadmin account and personal MFA account
Correct, it would be a vulnerability if it was possible to easily look up the TOTP seed value .
-
pirx
- Veteran
- Posts: 665
- Liked: 99 times
- Joined: Dec 20, 2015 6:24 pm
- Contact:
Re: [v13] veeamadmin account and personal MFA account
Maybe a hint during deployment would be good to catch simple people like me 
-
DaStivi
- Veeam Legend
- Posts: 442
- Liked: 83 times
- Joined: Jun 30, 2015 9:13 am
- Full Name: Stephan Lang
- Location: Austria
- Contact:
Re: [v13] veeamadmin account and personal MFA account
if you use KeePass for example, you can also add TOTP/MFA there... with a MFA Plugin you can just input the Seed there and generate TOTP Code...
of course you could even store the Seed itself as a secure note in side some credential safe... as gostev explained allready.
one additional note: the TOTP Code (seed) is different for the Console and Management Host Login! so you would have to have the same account with different MFA's saved! (its the same user and password, but different MFA-Seed, resulting in different TOTP codes!!)
of course you could even store the Seed itself as a secure note in side some credential safe... as gostev explained allready.
one additional note: the TOTP Code (seed) is different for the Console and Management Host Login! so you would have to have the same account with different MFA's saved! (its the same user and password, but different MFA-Seed, resulting in different TOTP codes!!)
Who is online
Users browsing this forum: No registered users and 45 guests