Monitoring and reporting for Veeam Data Platform
Post Reply
massimiliano.rizzi
Service Provider
Posts: 223
Liked: 30 times
Joined: Jan 24, 2012 7:56 am
Full Name: Massimiliano Rizzi
Contact:

Securing the Veeam ONE server at the Windows OS level using security policy settings

Post by massimiliano.rizzi »

Hello Community and good day,

I am looking for a way to increase the security of a Veeam ONE server at the Windows OS level server with relatively minimal effort and fast gains by creating separate, Veeam ONE Client-specific users without admin rights at the Windows OS level of the Veeam ONE server itself and with just enough privileges to perform their tasks using the Veeam ONE Client.

Besides disabling the Remote Desktop Service on the Veeam ONE server itself and placing it to a separate workgroup, I believe that many if not all the Veeam Backup & Replication Security & Compliance Analyzer recommendations described at https://helpcenter.veeam.com/docs/backu ... ml?ver=120 can just be applied to a machine running a Veeam ONE server as well, but of course this is out-of-scope of my request below.

The purpose of my question is confirming the User Rights Assignments among the ones below that are not needed and, because of that, can be denied at the Windows OS level for both 1) the Veeam ONE service account and 2) the Veeam ONE Client-specific users:

==================================================
Image
==================================================

Any suggestions and thoughts will be greatly appreciated.

Kind Regards,

Massimiliano
jorgedlcruz
Veeam Software
Posts: 1552
Liked: 670 times
Joined: Jul 17, 2015 6:54 pm
Full Name: Jorge de la Cruz
Contact:

Re: Securing the Veeam ONE server at the Windows OS level using security policy settings

Post by jorgedlcruz »

Hello Massimiliano,
I have passed your question to our QA department to check all of this and will reply as soon as I have some more information.

Thank you!
Jorge de la Cruz
Senior Product Manager | Veeam ONE @ Veeam Software

@jorgedlcruz
https://www.jorgedelacruz.es / https://jorgedelacruz.uk
vExpert 2014-2025 / InfluxAce / Grafana Champion
massimiliano.rizzi
Service Provider
Posts: 223
Liked: 30 times
Joined: Jan 24, 2012 7:56 am
Full Name: Massimiliano Rizzi
Contact:

Re: Securing the Veeam ONE server at the Windows OS level using security policy settings

Post by massimiliano.rizzi »

Hello Massimiliano,
I have passed your question to our QA department to check all of this and will reply as soon as I have some more information.

Thank you
Hello Jorge,

thank you very much for taking the time to reply to my question.

I am currently spending some time in our lab environment to play with the permissions. I plan on providing you with an update with my findings as well.

Thanks!

Massimiliano
RomanK
Veeam Software
Posts: 789
Liked: 205 times
Joined: Nov 01, 2016 11:26 am
Contact:

Re: Securing the Veeam ONE server at the Windows OS level using security policy settings

Post by RomanK » 1 person likes this post

Hello Massimiliano,

Our QA team finished their checks:
  • Deny access to this computer from the network cannot be applied as it causes GRPC issues
  • Deny log on as a batch job can be applied
  • Deny log on as a service cannot be applied for the Service account, while it can be applied to the Administrator/Power User/Read-only accounts
  • Deny log on locally cannot be applied, as it causes login issues
  • Deny log on through RDS can be applied
Thanks
massimiliano.rizzi
Service Provider
Posts: 223
Liked: 30 times
Joined: Jan 24, 2012 7:56 am
Full Name: Massimiliano Rizzi
Contact:

Re: Securing the Veeam ONE server at the Windows OS level using security policy settings

Post by massimiliano.rizzi »

Hello Massimiliano,

Our QA team finished their checks:
Deny access to this computer from the network cannot be applied as it causes GRPC issues
Deny log on as a batch job can be applied
Deny log on as a service cannot be applied for the Service account, while it can be applied to the Administrator/Power User/Read-only accounts
Deny log on locally cannot be applied, as it causes login issues
Deny log on through RDS can be applied
Thanks
Hello Roman and Happy New Year,

thank you very much for taking the time to provide me with this information. And of course I would like to thank the QA team as well.

Kind Regards,

Massimiliano
Post Reply

Who is online

Users browsing this forum: No registered users and 5 guests