Comprehensive data protection for all workloads
Post Reply
mjm599
Influencer
Posts: 19
Liked: 1 time
Joined: May 28, 2019 3:05 pm
Full Name: mjm599
Contact:

Veeam Infrastructure Appliance MFA and Admin Options

Post by mjm599 »

Hi All,

I have deployed the VIA 13.0.3 to be a Proxy server and during setup you must enable MFA and then have an option to enable the veeamso.

Working on behalf of the customer, i have to set this up and ensure its all fully working then hand it over to the customer when complete.

Therefore, during setup, i setup MFA to my own phone and this allowed me to proceed the next step where i then enabled the veeamso aswell.

- I am now considering the customer handover whereby my phone cant be the MFA account as i wont be around to provide codes etc.
- I am considering what setup for authentication i could reconfigure this to so its an easy handover to the customer and they can then configure as they want with or without MFA etc. Options i have thought of are:

1. Disable MFA on the veeamadmin account + Disable MFA on the veeamso account (however MFA is mandatory on veeamso account so cant disable)
2. Disable MFA on the veeamadmin account + Delete veeamso account

Is option 2 above possible so then we have no MFA enabled and just a single veeamadmin account?
tm67
Veeam Legend
Posts: 259
Liked: 94 times
Joined: Feb 21, 2023 4:44 pm
Full Name: Timo Marfurt
Location: Switzerland
Contact:

Re: Veeam Infrastructure Appliance MFA and Admin Options

Post by tm67 »

You can reset the MFA for a user in the host management interface: https://helpcenter.veeam.com/docs/vbr/u ... entication
And then your customer can add the MFA to his device or password manager.
vnikiforov
Veeam Software
Posts: 320
Liked: 92 times
Joined: Aug 17, 2022 5:03 am
Full Name: Vladimir Nikiforov
Location: Romania
Contact:

Re: Veeam Infrastructure Appliance MFA and Admin Options

Post by vnikiforov » 1 person likes this post

Hello, @mjm599

For the handover, one option is give the customer the veeamso recovery token. They sign in with Forgot password > I have a password recovery token, and the wizard has them set a new password, their own MFA and a new recovery token. Then they can move veeamadmin to their own device too, because after a password reset approved by the security officer veeamadmin has to set up MFA again at the next login.

You can also run installation in an unattended mode, where the answer file sets such values as:

Code: Select all

veeamadmin.password
veeamadmin.mfaSecretKey
veeamadmin.isMfaEnabled
veeamso.password
veeamso.mfaSecretKey
veeamso.isMfaEnabled
veeamso.recoveryToken
veeamso.isEnabled
(note if the installation performed without a veeamso account, it then can't be added back later time and also for the upcoming version either MFA on veeamadmin or veeamso account must be present for Veeam Infrastructure Appliance in Veeam Hardened Repository mode)

For those parameters before the actual installation you may generate unique values and supply that to a customer (they still can change them after the handover). In 13.1 you can also disable MFA for veeamadmin, with [F8] in the setup wizard or veeamadmin.isMfaEnabled=false in the answer file. Keep in mind that without a security officer, a lost veeamadmin password or MFA can only be recovered with Veeam LiveOS.

One more option to consider, I personally use an auth app which allows revealing the MFA secret and\or sharing it (transfer to a customer) - opensource app ente auth.
There is also a Veeam Software Appliance ISO Automation Tool by Baptiste Tellier.
---
BR,
Vladimir
Veeam Software
Mildur
Product Manager
Posts: 12330
Liked: 3556 times
Joined: May 13, 2017 4:51 pm
Full Name: Fabian K.
Location: Switzerland
Contact:

Re: Veeam Infrastructure Appliance MFA and Admin Options

Post by Mildur »

Topic moved, since it's not related to vSphere only.

Best,
Fabian
Product Management Analyst @ Veeam Software
mjm599
Influencer
Posts: 19
Liked: 1 time
Joined: May 28, 2019 3:05 pm
Full Name: mjm599
Contact:

Re: Veeam Infrastructure Appliance MFA and Admin Options

Post by mjm599 »

@vnikiforov, thanks for the reply and detail.

With the current setup, we have a windows 13.0 VBR Server, then 4 x VIA Proxy Servers. So for the 4 x VIA Servers these have the veeamadmin and veeamso accounts setup, this means 8 x MFA setups. As each account has its own MFA setup in authenticator.

So the 8 accounts is quite a lot and on top of that, the customer needs to access it most of the time with me accessing sometimes aswell. So the constraint of having the 8 x MFA accounts setup on one of the customers phones is going to mean i cannot access without customer contact to get codes etc.

My plan for now, is to:

1. Delete veeamso account on the 4 x VIA Proxy Servers
2. Disable MFA on the veeamadmin account (Customer then has the option to re-enable MFA on this account in the future if they ever wanted to)
3. Create a recovery/back door account on the 4 x VIA Proxy servers with strong password so if veeamadmin password lost, we can get into the proxy servers.

Do you see any issue with the above apart from it being less secure?

Thanks,
Post Reply

Who is online

Users browsing this forum: ravatheodor and 91 guests