Comprehensive data protection for all workloads
Post Reply
ratkinsonuk
Expert
Posts: 111
Liked: 16 times
Joined: Dec 10, 2018 10:59 am
Full Name: Robert Atkinson
Contact:

Veeam Console Access Groups

Post by ratkinsonuk »

A strange thing just happened! I logged onto our Veeam application server using an account that isn't explicitly defined in the Veeam console roles, but the account was able to connect and manage the B&R environment.

Is there an explicit rule in Veeam that allows Admin level access using the GUI from the B&R application server? I can't think of any other way this account would gain access.

Thanks, Rob.
MarkBoothmaa
Veeam Legend
Posts: 198
Liked: 55 times
Joined: Mar 22, 2017 11:10 am
Full Name: Mark Boothman
Location: Darlington, United Kingdom
Contact:

Re: Veeam Console Access Groups

Post by MarkBoothmaa » 1 person likes this post

https://helpcenter.veeam.com/docs/backu ... ml?ver=110
Built-in administrator accounts (Domain\Administrator and Machine\Administrator) always have full access to Veeam Backup & Replication, even if you exclude them from all Veeam Backup & Replication roles. If you delete the Administrators group from the Veeam Backup & Replication roles, the users who are added to this group will still have access to Veeam Backup & Replication.
ratkinsonuk
Expert
Posts: 111
Liked: 16 times
Joined: Dec 10, 2018 10:59 am
Full Name: Robert Atkinson
Contact:

Re: Veeam Console Access Groups

Post by ratkinsonuk »

Thanks for the help Mark - something I'd never come across before.

I really do wish Veeam would change their stance on console security. I agree if a hacker has managed to log onto the application server, then he/she is probably far enough in to get around console security. But there are many other scenarios where administrators need to lock down Veeam B&R without denying admin access to the server. It's exactly the same problem with Veeam AWS and Veeam 365.

Cheers, Rob.
Post Reply

Who is online

Users browsing this forum: Bing [Bot] and 73 guests