-
- Novice
- Posts: 7
- Liked: never
- Joined: Sep 07, 2016 10:04 am
- Full Name: Carlos robles
- Contact:
Prevent even admins from deleting a VM from Veeam
Hi
Is it possible to create some kind of rule within Veeam B&R to avoid deleting VMs from the console?
Even if an admin is the user at the time?
A denied permission or similar?
Is it possible to create some kind of rule within Veeam B&R to avoid deleting VMs from the console?
Even if an admin is the user at the time?
A denied permission or similar?
-
- Veeam Software
- Posts: 21138
- Liked: 2141 times
- Joined: Jul 11, 2011 10:22 am
- Full Name: Alexander Fogelson
- Contact:
Re: Prevent even admins from deleting a VM from Veeam
Carlos, could you please clarify what VM deletion are you trying to prevent? Do you mean deletion of backups from Veeam B&R UI or VMs from the jobs or something else?
-
- Novice
- Posts: 7
- Liked: never
- Joined: Sep 07, 2016 10:04 am
- Full Name: Carlos robles
- Contact:
Re: Prevent even admins from deleting a VM from Veeam
We've had a case where an admin deleted a replica VM from Veeam's replica repository but it turned out to be a production server
(seems it was a replica VM back in the days but was failed over to production)
Veeam deleted this 'replica' server with no questions, it shutdown the server first and delete it from disk next, no traces left.
We want to avoid this happening in the future so my post here, is there a way to create a rule maybe, within Veeam which stops anybody from deleting a VM?
(seems it was a replica VM back in the days but was failed over to production)
Veeam deleted this 'replica' server with no questions, it shutdown the server first and delete it from disk next, no traces left.
We want to avoid this happening in the future so my post here, is there a way to create a rule maybe, within Veeam which stops anybody from deleting a VM?
-
- Product Manager
- Posts: 6551
- Liked: 765 times
- Joined: May 19, 2015 1:46 pm
- Contact:
Re: Prevent even admins from deleting a VM from Veeam
Would it be sufficient to prompt the user to shutdown the VM manually first instead of shutting it down automatically? Even with password or a special role there is no guarantee that someone who has the privilege to delete VMs won't make the same mistake.
-
- Novice
- Posts: 7
- Liked: never
- Joined: Sep 07, 2016 10:04 am
- Full Name: Carlos robles
- Contact:
Re: Prevent even admins from deleting a VM from Veeam
A prompt would be somethign, not what i'm looking for but at least some type of step before deletion.
What I've noticed is that, for instance, although I log to the V&R server with my admin account, the actions towards the VMWare cluster are done in the background by the Veeam account it uses to connect to VMWare servers which has full permissions.
So modifying permissions in VMWare to this Veeam account would mean restricting Veeam doing its work, hence i posted this hoping there's Veeam 'permission' which could limit my admin account .... maybe a long shot?
What I've noticed is that, for instance, although I log to the V&R server with my admin account, the actions towards the VMWare cluster are done in the background by the Veeam account it uses to connect to VMWare servers which has full permissions.
So modifying permissions in VMWare to this Veeam account would mean restricting Veeam doing its work, hence i posted this hoping there's Veeam 'permission' which could limit my admin account .... maybe a long shot?
-
- Service Provider
- Posts: 295
- Liked: 46 times
- Joined: Jun 30, 2015 9:13 am
- Full Name: Stephan Lang
- Location: Austria
- Contact:
Re: Prevent even admins from deleting a VM from Veeam
am i wrong, when doing a failover and finishing all processes the vm disapears from Veeam console? as with a instantVM recovery...
maybe another thought, when this was an production vm, hopefully on a productive datastore, is there an backup?!
maybe another thought, when this was an production vm, hopefully on a productive datastore, is there an backup?!
-
- Novice
- Posts: 7
- Liked: never
- Joined: Sep 07, 2016 10:04 am
- Full Name: Carlos robles
- Contact:
Re: Prevent even admins from deleting a VM from Veeam
Thanks for your input,
Dastivi, im not going to discuss that,
I described that scenario as a possible cause for our incident but it could have been something else.
I'm looking for a solution to avoid anything similar happening again, an admin deleting a production VM from Veeam's console
Some Veeam rule set, permissions, rule applied to VM tag.... a third party tool...
I'm assuming this doesn't exist as I'm not seeing any solution from anybody.
Dastivi, im not going to discuss that,
I described that scenario as a possible cause for our incident but it could have been something else.
I'm looking for a solution to avoid anything similar happening again, an admin deleting a production VM from Veeam's console
Some Veeam rule set, permissions, rule applied to VM tag.... a third party tool...
I'm assuming this doesn't exist as I'm not seeing any solution from anybody.
-
- Veeam Software
- Posts: 21138
- Liked: 2141 times
- Joined: Jul 11, 2011 10:22 am
- Full Name: Alexander Fogelson
- Contact:
Re: Prevent even admins from deleting a VM from Veeam
You're looking for restrictions on a Veeam B&R console side, but are these same admins allowed to login to vSphere client and removing production VMs from there?
-
- Novice
- Posts: 7
- Liked: never
- Joined: Sep 07, 2016 10:04 am
- Full Name: Carlos robles
- Contact:
Re: Prevent even admins from deleting a VM from Veeam
yes, they are
-
- Novice
- Posts: 7
- Liked: never
- Joined: Sep 07, 2016 10:04 am
- Full Name: Carlos robles
- Contact:
Re: Prevent even admins from deleting a VM from Veeam
Having said that, i can operate the Veeam console with my admin account but the actions in vsphere show as created by Veeam's account.
What about generating a pop up window in Veeam console indicating the server you want to delete is powered on?
at least that'd make an admin think twice, he's working on a running server not a powered off replica
can this be done?
What about generating a pop up window in Veeam console indicating the server you want to delete is powered on?
at least that'd make an admin think twice, he's working on a running server not a powered off replica
can this be done?
-
- Veeam Software
- Posts: 21138
- Liked: 2141 times
- Joined: Jul 11, 2011 10:22 am
- Full Name: Alexander Fogelson
- Contact:
Re: Prevent even admins from deleting a VM from Veeam
This is exactly the prompt Pavel has suggested above.
-
- Novice
- Posts: 7
- Liked: never
- Joined: Sep 07, 2016 10:04 am
- Full Name: Carlos robles
- Contact:
Re: Prevent even admins from deleting a VM from Veeam
And how is this done?
-
- Veeam Software
- Posts: 21138
- Liked: 2141 times
- Joined: Jul 11, 2011 10:22 am
- Full Name: Alexander Fogelson
- Contact:
Re: Prevent even admins from deleting a VM from Veeam
This was mentioned as a probable future improvement, not as currently available functionality.
-
- VeeaMVP
- Posts: 1007
- Liked: 314 times
- Joined: Jan 31, 2011 11:17 am
- Full Name: Max
- Contact:
Re: Prevent even admins from deleting a VM from Veeam
@foggy/@PTide: Did this end as a feature request?
Similar to the "Restore entire VM" dialog, deleting a Replica should check if the VM is running or if it did get changed, and prompt for permission to proceed.
Similar to the "Restore entire VM" dialog, deleting a Replica should check if the VM is running or if it did get changed, and prompt for permission to proceed.
-
- Product Manager
- Posts: 20402
- Liked: 2298 times
- Joined: Oct 26, 2012 3:28 pm
- Full Name: Vladimir Eremin
- Contact:
Re: Prevent even admins from deleting a VM from Veeam
Nope, it did not - it got too few requests and was superseded by more demanded features. Thanks!
-
- VeeaMVP
- Posts: 1007
- Liked: 314 times
- Joined: Jan 31, 2011 11:17 am
- Full Name: Max
- Contact:
Re: Prevent even admins from deleting a VM from Veeam
Then please count my post as 2 votes/requests
Apparently this doesn't happen that often, but I'm sure many customers are manually failing over Replicas; and chances are high that later on they delete their new production VMs when cleaning up the Replicas in the Veeam configuration (Delete from Disk).
Apparently this doesn't happen that often, but I'm sure many customers are manually failing over Replicas; and chances are high that later on they delete their new production VMs when cleaning up the Replicas in the Veeam configuration (Delete from Disk).
Who is online
Users browsing this forum: Bing [Bot], chris.childerhose, Google [Bot], massimiliano.rizzi and 131 guests