Hi,
our new DMZ won't allow permanet user in the administrator group for windows.
Does someone has expierence which permissions are realy needed?
(Leaste-Privileged)
We will use only full restores so we don't need credentials for the clients, but Admin-Permissions for B&R and Proxies are no option.
-
- Influencer
- Posts: 10
- Liked: never
- Joined: Aug 14, 2015 12:21 pm
- Full Name: Daniel
- Contact:
-
- Influencer
- Posts: 15
- Liked: 8 times
- Joined: Apr 06, 2015 8:14 pm
- Full Name: Sebastian Talmon
- Location: Germany
- Contact:
Re: Permission in DMZ
If you do not need application-aware processing (mainly database/log handling), you do not need a user inside of the VMs.
Veeam fetches the VM data from the Hypervisor, and can use native snapshot functionality if the advanced VSS handling through application aware handling with admin user is not possible.
So you only need the permissions for the hypervisor. If possible, use root (ESXi) or administrator accounts (vCenter / Hyper-V), if you need granular permissions you will find them in the following document: https://www.veeam.com/veeam_backup_9_0_ ... ons_pg.pdf
Veeam fetches the VM data from the Hypervisor, and can use native snapshot functionality if the advanced VSS handling through application aware handling with admin user is not possible.
So you only need the permissions for the hypervisor. If possible, use root (ESXi) or administrator accounts (vCenter / Hyper-V), if you need granular permissions you will find them in the following document: https://www.veeam.com/veeam_backup_9_0_ ... ons_pg.pdf
--Sebastian
Who is online
Users browsing this forum: Amazon [Bot], Bing [Bot], Yapman and 1 guest