Comprehensive data protection for all workloads
Post Reply
matsusan
Enthusiast
Posts: 28
Liked: 4 times
Joined: Feb 26, 2026 8:55 pm
Full Name: ryoma matsuyama
Contact:

Configuration Restore using a Veeam admin user without OS logon permissions

Post by matsusan »

[Background and Environment]
To strictly adhere to the principle of least privilege, we separate the Windows OS logon account from the Veeam administrator account
on our Veeam Backup & Replication (VBR) server.
This ensures our backup data remains protected even if one of these accounts is compromised.
Our specific environment setup is as follows:
- OS Logon User: <OS_ADMIN_USER> (used only for Windows OS access)
- Veeam Admin User: <VEEAM_ADMIN_USER> (assigned the Veeam Administrator role, but has no Windows interactive logon or RDP permissions)

[Our Goal]
We'd like to perform a Veeam Configuration Restore.
Since we are logged into the Windows OS as <OS_ADMIN_USER>, we'd like to specify the credentials of <VEEAM_ADMIN_USER> in the restore wizard to authenticate with the PostgreSQL database.

[The Issue]
In the "Target Database" step of the Configuration Restore wizard,
we select "Native authentication using the following credentials" and enter the <VEEAM_ADMIN_USER> credentials.
However, we cannot complete the restore due to database authentication errors.
(such as "Unable to authenticate because native authentication is disabled on the database server" or "Role ... does not exist")

[Questions]
1. Is it possible to perform a Configuration Restore using a Veeam administrator account that does not have Windows OS logon permissions?
2. If yes, what is the recommended PostgreSQL (pg_hba.conf / pg_ident.conf) and restore wizard configuration to support this scenario?

Thanks,
Ryoma
Post Reply

Who is online

Users browsing this forum: Google [Bot] and 110 guests