Comprehensive data protection for all workloads
Post Reply
dperabo
Influencer
Posts: 10
Liked: never
Joined: Aug 14, 2015 12:21 pm
Full Name: Daniel
Contact:

Permission in DMZ

Post by dperabo »

Hi,

our new DMZ won't allow permanet user in the administrator group for windows.
Does someone has expierence which permissions are realy needed?
(Leaste-Privileged)

We will use only full restores so we don't need credentials for the clients, but Admin-Permissions for B&R and Proxies are no option.
s_t
Influencer
Posts: 15
Liked: 8 times
Joined: Apr 06, 2015 8:14 pm
Full Name: Sebastian Talmon
Location: Germany
Contact:

Re: Permission in DMZ

Post by s_t »

If you do not need application-aware processing (mainly database/log handling), you do not need a user inside of the VMs.

Veeam fetches the VM data from the Hypervisor, and can use native snapshot functionality if the advanced VSS handling through application aware handling with admin user is not possible.

So you only need the permissions for the hypervisor. If possible, use root (ESXi) or administrator accounts (vCenter / Hyper-V), if you need granular permissions you will find them in the following document: https://www.veeam.com/veeam_backup_9_0_ ... ons_pg.pdf
--Sebastian
Post Reply

Who is online

Users browsing this forum: No registered users and 64 guests