Comprehensive data protection for all workloads
Post Reply
Zoatibix
Novice
Posts: 6
Liked: 1 time
Joined: Jan 29, 2018 3:19 pm
Full Name: David Morgan
Contact:

Hardening Query

Post by Zoatibix »

Hello folks

I've been going through the checklist for Veeam Hardening using the script from here https://www.veeam.com/kb4525

Great so far except for two entries.

25 - Backup services should be running under the LocalSystem Account. When I try to set that the script returns 'Does not need to be applied'

- Is this simply a case of manually moving the services over?

27 - Credentials and encryption passwords should be rotated at least annually. - I've changed Veeam's encryption passwords but does credentials include those on the target servers themselves?

Thank you.
david.domask
Veeam Software
Posts: 2590
Liked: 606 times
Joined: Jun 28, 2016 12:12 pm
Contact:

Re: Hardening Query

Post by david.domask » 1 person likes this post

Hi Zoatibix,

Correct, if these items were flagged as having challenges, they need to be manually adjusted, the script does not handle this.

Item 25 (Backup Services running under LocalSystem account) simply checks if the account for Veeam services is LocalSystem or not. If not, this requires user interaction to change as there are some arguments for using non-System accounts in very specific circumstances. (I would advise use LocalSystem)

Item 27 similarly just checks if any of the stored credentials haven't been changed in > 1 Year, and would also require you to change the password.

So please handle those elements manually.
David Domask | Product Management: Principal Analyst
Zoatibix
Novice
Posts: 6
Liked: 1 time
Joined: Jan 29, 2018 3:19 pm
Full Name: David Morgan
Contact:

Re: Hardening Query

Post by Zoatibix » 1 person likes this post

Hello David.

Thanks for the confirmation. I'll get those sorted out.
Post Reply

Who is online

Users browsing this forum: Bing [Bot], frisco and 281 guests