Hi,
We have a physical domain controller, and we use the agent to backup this server. As of today the user that runs the backup agent is part of Domain Admins, but we would like to not have the user in Domain Admin. How can we accomplish this, on regular servers we have a account that is part of Local Administrator group.
For information we have 3 domain controllers, site A = domain controller1(physical) and domain controller 2(virtual). Site B = domain controller3(physical)
How do you backup your domain controllers, may be we should just backup the domain controller that has FSMO roles ? and not all 3 ?
Thanks for reply.
/Andreas
			
			
									
						
										
						- 
				andreas2012
- Veeam ProPartner
- Posts: 114
- Liked: 5 times
- Joined: Jun 11, 2013 11:27 am
- Full Name: Andreas
- Contact:
- 
				Dima P.
- Product Manager
- Posts: 14945
- Liked: 1833 times
- Joined: Feb 04, 2013 2:07 pm
- Full Name: Dmitry Popov
- Location: Prague
- Contact:
Re: Windows Agent backup domain controller
Hello Andreas,
To perform application aware backup agent account must be a local administrator on the machine but it's not required to use domain admin. Can you create a backup service account and add it to the administrators group for the machines you are about to protect with agents? Thanks!
			
			
									
						
										
						To perform application aware backup agent account must be a local administrator on the machine but it's not required to use domain admin. Can you create a backup service account and add it to the administrators group for the machines you are about to protect with agents? Thanks!
- 
				andreas2012
- Veeam ProPartner
- Posts: 114
- Liked: 5 times
- Joined: Jun 11, 2013 11:27 am
- Full Name: Andreas
- Contact:
Re: Windows Agent backup domain controller
Hi,
Yes I know I have to add the service account to the local administrator group on each machine, but what do I do with the domain controller ? Since a domain controller does not have local administrator group, it seems like I must add it to domain admins, and then they have control over the domain.
/R
Andreas
			
			
									
						
										
						Yes I know I have to add the service account to the local administrator group on each machine, but what do I do with the domain controller ? Since a domain controller does not have local administrator group, it seems like I must add it to domain admins, and then they have control over the domain.
/R
Andreas
- 
				Dima P.
- Product Manager
- Posts: 14945
- Liked: 1833 times
- Joined: Feb 04, 2013 2:07 pm
- Full Name: Dmitry Popov
- Location: Prague
- Contact:
Re: Windows Agent backup domain controller
Andreas,
Sounds right (sorry, somehow forgot the limitation that DCs do not have local admin group). Cheers!
			
			
									
						
										
						Sounds right (sorry, somehow forgot the limitation that DCs do not have local admin group). Cheers!
Who is online
Users browsing this forum: No registered users and 2 guests