Can someone explain me what is the difference in term of security between domain join backup and SAML integration ?
I mean, the first idea to not be domain joined is to avoid an attacker to access backup if domain account with some privilege is stolen or if backup server is compromise to get access to AD domain right ?
So, If SAML account is compromised, the user has automatically access to backup server right ? And then he can probably retrieve credentials stored in the VSA / VBR server.
I never join backup server into the domain and I would like to understand why SAML integration is better ... (For sure Entra ID account have more security than AD account with conditionnal access / PIM / MFA but I would like to know the Veeam position on it