Hello,
I would like to know if Veeam has foreseen in the future a 'Two person control' feature.
In other words, a 2nd backup administrator account is required to approve certain actions on the backup environment (eg deleting backup, config adjustment,…).
Thanks
-
- Enthusiast
- Posts: 32
- Liked: 2 times
- Joined: May 12, 2016 1:32 pm
- Contact:
-
- Product Manager
- Posts: 9846
- Liked: 2607 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: Two person control for certain operations
Hi brucquat
Thanks for the question.
It is not on our roadmap for one of the next versions. But thanks for the request.
Can you explain your scenario why you need such a feature?
From my opinion I see two situations where a "two person control feature" doesn't give you any benefits. Backup files can be deleted on non immutable storage without a second admin. And the configuration can be changed by an SQL administrator inside the database. In both cases, a two person control feature wouldn't help.
Instead of using a 'Two person control' feature for the backup deletion you could use immutable or air gapped backup storage.
Config adjustments can be monitored with Veeam One and in case an attacker changed something, you can restore the configuration backup to the healthy state of the config.
Thanks
Fabian
Thanks for the question.
It is not on our roadmap for one of the next versions. But thanks for the request.
Can you explain your scenario why you need such a feature?
From my opinion I see two situations where a "two person control feature" doesn't give you any benefits. Backup files can be deleted on non immutable storage without a second admin. And the configuration can be changed by an SQL administrator inside the database. In both cases, a two person control feature wouldn't help.
Instead of using a 'Two person control' feature for the backup deletion you could use immutable or air gapped backup storage.
Config adjustments can be monitored with Veeam One and in case an attacker changed something, you can restore the configuration backup to the healthy state of the config.
Thanks
Fabian
Product Management Analyst @ Veeam Software
-
- Enthusiast
- Posts: 32
- Liked: 2 times
- Joined: May 12, 2016 1:32 pm
- Contact:
Re: Two person control for certain operations
Sometimes, the question is posed in some RFPs. But I will provide your arguments which are really valuable! Many thanks.
-
- Veeam Legend
- Posts: 251
- Liked: 136 times
- Joined: Mar 28, 2019 2:01 pm
- Full Name: SP
- Contact:
Re: Two person control for certain operations
Well, i guess for us, we have physical Veeam boxes that are not network attached. Our SQL is domain joined. If somehow the Veeam server was compromised it doesn't mean the SQL server has been. Or the SAN.
I supposed someone could go delete the backups still, but then I could say it would idiot proof Veeam from ourselves from accidently deleting a job / backup at 4AM using the GUI. Or if someone left their PC on with the client up.
I could see some reasons for having it, but I also see it not being the end all be all of security.
I supposed someone could go delete the backups still, but then I could say it would idiot proof Veeam from ourselves from accidently deleting a job / backup at 4AM using the GUI. Or if someone left their PC on with the client up.
I could see some reasons for having it, but I also see it not being the end all be all of security.
-
- Product Manager
- Posts: 9846
- Liked: 2607 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: Two person control for certain operations
Thank you both for explaining.
Veeam V12 will bring an "Auto-Logoff feature". That should helpOr if someone left their PC on with the client up.
Product Management Analyst @ Veeam Software
Who is online
Users browsing this forum: Bing [Bot] and 42 guests