-
- Enthusiast
- Posts: 25
- Liked: 1 time
- Joined: Nov 19, 2015 10:00 am
- Contact:
gMSA & App aware processing permissions on AD's
We're in the final stages of killing off our old/classic service account (user + no password expiry) that we implimented from day1 when purchasing veeam. 10-12years old! I'm aiming to move all our service accounts to gMSA's where possible.
For Veeam, we're at the final 2 servers now - AD's.
Since there is no local 'administrators' group, whats the recommended practice to add the gMSA to the "local administrators" group that's required for the app-aware processing function of backup jobs? While i understand there are other aspects to gMSA setup that would stop unauthorised use, adding to the 'domain admins' group just feels the wrong way to go about it.
For Veeam, we're at the final 2 servers now - AD's.
Since there is no local 'administrators' group, whats the recommended practice to add the gMSA to the "local administrators" group that's required for the app-aware processing function of backup jobs? While i understand there are other aspects to gMSA setup that would stop unauthorised use, adding to the 'domain admins' group just feels the wrong way to go about it.
-
- Product Manager
- Posts: 10870
- Liked: 2967 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: gMSA & App aware processing permissions on AD's
Hi veehexx
Domain admin permissions are required on a Domain Controller. This is a limitation from Microsoft.
If you find another way, please let us know.
As a workaround consider to use a Veeam Agent and the "pre-installed agent - protection group" for doing backups of your Domain Controller.
Best,
Fabian
Domain admin permissions are required on a Domain Controller. This is a limitation from Microsoft.
If you find another way, please let us know.
As a workaround consider to use a Veeam Agent and the "pre-installed agent - protection group" for doing backups of your Domain Controller.
Best,
Fabian
Product Management Analyst @ Veeam Software
-
- Expert
- Posts: 113
- Liked: 40 times
- Joined: Mar 07, 2018 12:57 pm
- Contact:
-
- Product Manager
- Posts: 10870
- Liked: 2967 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: gMSA & App aware processing permissions on AD's
With this group on a domain controller, the user still has full permission over the entire active directory domain.
https://learn.microsoft.com/en-us/windo ... nistrators
Best,
Fabian
https://learn.microsoft.com/en-us/windo ... nistrators
Best,
Fabian
Product Management Analyst @ Veeam Software
Who is online
Users browsing this forum: Baidu [Spider], Bing [Bot], ChristophINV, diana.boro, flaren, Google [Bot], JosVerhallen, Paul.Loewenkamp and 61 guests