-
- Service Provider
- Posts: 4
- Liked: never
- Joined: Feb 07, 2016 3:22 pm
- Full Name: Tom Mucha
- Location: Plantsville, CT
- Contact:
Restore to Azure - MFA requirement
Hi Everyone,
Our Azure tenant is tied to our MS Partner account. As a MS Partner, all our accounts that access cloud resources must have MFA enabled, even using an app password after enforcing the MFA is allowed. Per the documentation - https://helpcenter.veeam.com/docs/backu ... ml?ver=100 - MFA must be disabled and app passwords are not supported (I even tried for the heck of it). Is there any possibility of something in the works to allow for accounts with MFA? I know with the 365 backup there is an option to use modern auth and MFA by creating an Azure Application Registration, was hoping something like this might be in the works for VBR.
I could just setup another Azure tenant/subscription, but I can't link any of my MS Partner benefits to an outside tenant.
Any thoughts? Anyone in a similar situation?
Tom
Our Azure tenant is tied to our MS Partner account. As a MS Partner, all our accounts that access cloud resources must have MFA enabled, even using an app password after enforcing the MFA is allowed. Per the documentation - https://helpcenter.veeam.com/docs/backu ... ml?ver=100 - MFA must be disabled and app passwords are not supported (I even tried for the heck of it). Is there any possibility of something in the works to allow for accounts with MFA? I know with the 365 backup there is an option to use modern auth and MFA by creating an Azure Application Registration, was hoping something like this might be in the works for VBR.
I could just setup another Azure tenant/subscription, but I can't link any of my MS Partner benefits to an outside tenant.
Any thoughts? Anyone in a similar situation?
Tom
-
- VP, Product Management
- Posts: 27377
- Liked: 2800 times
- Joined: Mar 30, 2009 9:13 am
- Full Name: Vitaliy Safarov
- Contact:
Re: Restore to Azure - MFA requirement
Hi Tom,
As far as I know, these accounts cannot be used for now, but if I find a workaround I will update this thread.
Thanks!
As far as I know, these accounts cannot be used for now, but if I find a workaround I will update this thread.
Thanks!
-
- Service Provider
- Posts: 4
- Liked: never
- Joined: Feb 07, 2016 3:22 pm
- Full Name: Tom Mucha
- Location: Plantsville, CT
- Contact:
Re: Restore to Azure - MFA requirement
Thank you for the quick followup Vitaliy! Have a wonderful day!
Tom
Tom
-
- Novice
- Posts: 7
- Liked: 3 times
- Joined: Aug 30, 2021 5:38 pm
- Full Name: Joe Clarke
- Contact:
Re: Restore to Azure - MFA requirement
This is still true with version 11 in case anyone is wondering, hit this today.
https://helpcenter.veeam.com/docs/backu ... ml?ver=110
https://helpcenter.veeam.com/docs/backu ... ml?ver=110
-
- Product Manager
- Posts: 14844
- Liked: 3086 times
- Joined: Sep 01, 2014 11:46 am
- Full Name: Hannes Kasparick
- Location: Austria
- Contact:
Re: Restore to Azure - MFA requirement
yep, it's something we are working on.
-
- Novice
- Posts: 7
- Liked: 3 times
- Joined: Aug 30, 2021 5:38 pm
- Full Name: Joe Clarke
- Contact:
Re: Restore to Azure - MFA requirement
So I was running into the error message AADSTS50076 : Due to a configuration change made by your administrator, or because you moved to a new location, you must use multi-factor authentication to access.
We had MFA disabled for the user and we even had the "Default Security" setting disabled, so it really shouldn't even be doing that. We were able to log in from the Veeam VM using Web and powershell APIs with the same creds, so this was incredibly confusing.
We resolved this by changing the conditional access policy to exclude the Veeam service account user, which isn't called out in the Veeam docs, but it is required even if the user is set to disabled.
https://docs.microsoft.com/en-us/azure/ ... -condition
My good deed is done for the day.
We had MFA disabled for the user and we even had the "Default Security" setting disabled, so it really shouldn't even be doing that. We were able to log in from the Veeam VM using Web and powershell APIs with the same creds, so this was incredibly confusing.
We resolved this by changing the conditional access policy to exclude the Veeam service account user, which isn't called out in the Veeam docs, but it is required even if the user is set to disabled.
https://docs.microsoft.com/en-us/azure/ ... -condition
My good deed is done for the day.
-
- Novice
- Posts: 7
- Liked: 3 times
- Joined: Aug 30, 2021 5:38 pm
- Full Name: Joe Clarke
- Contact:
Re: Restore to Azure - MFA requirement
BTW, the fact that customers need to disable the "default security" setting in Azure AD or make conditional access policies to make a service account for Veeam to restore VMs is kind of not great. Hopefully this gets worked on sooner rather than later.
https://docs.microsoft.com/en-us/azure/ ... y-defaults
https://docs.microsoft.com/en-us/azure/ ... y-defaults
-
- Product Manager
- Posts: 14844
- Liked: 3086 times
- Joined: Sep 01, 2014 11:46 am
- Full Name: Hannes Kasparick
- Location: Austria
- Contact:
Re: Restore to Azure - MFA requirement
Hello,
yes, V12 supports application passwords. We plan to release V12 early 2023
Best regards,
Hannes
yes, V12 supports application passwords. We plan to release V12 early 2023
Best regards,
Hannes
Who is online
Users browsing this forum: No registered users and 2 guests