Host-based backup of VMware vSphere VMs.
Post Reply
mjm599
Influencer
Posts: 18
Liked: 1 time
Joined: May 28, 2019 3:05 pm
Full Name: mjm599
Contact:

Veeam Infrastructure Appliance MFA and Admin Options

Post by mjm599 »

Hi All,

I have deployed the VIA 13.0.3 to be a Proxy server and during setup you must enable MFA and then have an option to enable the veeamso.

Working on behalf of the customer, i have to set this up and ensure its all fully working then hand it over to the customer when complete.

Therefore, during setup, i setup MFA to my own phone and this allowed me to proceed the next step where i then enabled the veeamso aswell.

- I am now considering the customer handover whereby my phone cant be the MFA account as i wont be around to provide codes etc.
- I am considering what setup for authentication i could reconfigure this to so its an easy handover to the customer and they can then configure as they want with or without MFA etc. Options i have thought of are:

1. Disable MFA on the veeamadmin account + Disable MFA on the veeamso account (however MFA is mandatory on veeamso account so cant disable)
2. Disable MFA on the veeamadmin account + Delete veeamso account

Is option 2 above possible so then we have no MFA enabled and just a single veeamadmin account?
tm67
Veeam Legend
Posts: 259
Liked: 94 times
Joined: Feb 21, 2023 4:44 pm
Full Name: Timo Marfurt
Location: Switzerland
Contact:

Re: Veeam Infrastructure Appliance MFA and Admin Options

Post by tm67 »

You can reset the MFA for a user in the host management interface: https://helpcenter.veeam.com/docs/vbr/u ... entication
And then your customer can add the MFA to his device or password manager.
vnikiforov
Veeam Software
Posts: 320
Liked: 91 times
Joined: Aug 17, 2022 5:03 am
Full Name: Vladimir Nikiforov
Location: Romania
Contact:

Re: Veeam Infrastructure Appliance MFA and Admin Options

Post by vnikiforov »

Hello, @mjm599

For the handover, one option is give the customer the veeamso recovery token. They sign in with Forgot password > I have a password recovery token, and the wizard has them set a new password, their own MFA and a new recovery token. Then they can move veeamadmin to their own device too, because after a password reset approved by the security officer veeamadmin has to set up MFA again at the next login.

You can also run installation in an unattended mode, where the answer file sets such values as:

Code: Select all

veeamadmin.password
veeamadmin.mfaSecretKey
veeamadmin.isMfaEnabled
veeamso.password
veeamso.mfaSecretKey
veeamso.isMfaEnabled
veeamso.recoveryToken
veeamso.isEnabled
(note if the installation performed without a veeamso account, it then can't be added back later time and also for the upcoming version either MFA on veeamadmin or veeamso account must be present for Veeam Infrastructure Appliance in Veeam Hardened Repository mode)

For those parameters before the actual installation you may generate unique values and supply that to a customer (they still can change them after the handover). In 13.1 you can also disable MFA for veeamadmin, with [F8] in the setup wizard or veeamadmin.isMfaEnabled=false in the answer file. Keep in mind that without a security officer, a lost veeamadmin password or MFA can only be recovered with Veeam LiveOS.

One more option to consider, I personally use an auth app which allows revealing the MFA secret and\or sharing it (transfer to a customer) - opensource app ente auth.
There is also a Veeam Software Appliance ISO Automation Tool by Baptiste Tellier.
---
BR,
Vladimir
Veeam Software
Post Reply

Who is online

Users browsing this forum: Google [Bot] and 18 guests