-
- Influencer
- Posts: 12
- Liked: never
- Joined: Apr 12, 2016 3:19 pm
- Full Name: Tolga ÜNTÜRK
- Contact:
[MERGED] Vcenter Privilages and Permissions.
Hi All ,
I need to your helpness and your opinions. I want to give domain privilages to my veeam user without administrator privilages. At now veeam is a administartor account on my domain . But i want to restrict to veeam user because my company dont want to a administrator account.
Thanks
I need to your helpness and your opinions. I want to give domain privilages to my veeam user without administrator privilages. At now veeam is a administartor account on my domain . But i want to restrict to veeam user because my company dont want to a administrator account.
Thanks
-
- Veteran
- Posts: 1943
- Liked: 247 times
- Joined: Dec 01, 2016 3:49 pm
- Full Name: Dmitry Grinev
- Location: St.Petersburg
- Contact:
Re: Vcenter Privilages and Permissions.
Hi Tolga,
Please, review this existing thread above, also check the document with detailed description of required permissions. Thanks!
Please, review this existing thread above, also check the document with detailed description of required permissions. Thanks!
-
- Veeam ProPartner
- Posts: 208
- Liked: 28 times
- Joined: Jun 09, 2009 2:48 pm
- Full Name: Lucio Mazzi
- Location: Reggio Emilia, Italy
- Contact:
[MERGED] Permissions on Datacenter instead of vCenter
An Italian based company has a VMware 6.5 infrastructure with 6 hosts managed by a (vm) vCenter. Veeam has been backing up all the vms with admin permissions at the vCenter level.
Now this company has been acquired by a larger US company. The new management wants to import the VMware Datacenter into their US-located vCenter. The hardware will not be moved.
They are willing to give our Veeam account admin rights at the Datacenter level only, but (undestandably) not at their vCenter level.
Are full permissions at the Datacenter level enough to keep the current backup jobs working? From the docs it seems so, but the new mgmt is asking for a confirmation.
Also, will the MoRefIDs change moving the DC to a different vCenter, thus triggering full backups on all vms?
Thanks.
Now this company has been acquired by a larger US company. The new management wants to import the VMware Datacenter into their US-located vCenter. The hardware will not be moved.
They are willing to give our Veeam account admin rights at the Datacenter level only, but (undestandably) not at their vCenter level.
Are full permissions at the Datacenter level enough to keep the current backup jobs working? From the docs it seems so, but the new mgmt is asking for a confirmation.
Also, will the MoRefIDs change moving the DC to a different vCenter, thus triggering full backups on all vms?
Thanks.
-
- VP, Product Management
- Posts: 7081
- Liked: 1511 times
- Joined: May 04, 2011 8:36 am
- Full Name: Andreas Neufert
- Location: Germany
- Contact:
Re: Permissions on Datacenter instead of vCenter
Hi Emilia,
please find the needed permissions here: https://helpcenter.veeam.com/docs/backu ... ml?ver=100
When you add the ESXi hosts to another vcenter, the VMs will be treated by Veeam as new VMs. So you have to add them to the Jobs again and next run will be a new full backup.
Potentially clone all jobs and replace there the VMs. Then run new backups. Over time, you can just delete the old backups if the new Job has enough restore points.
please find the needed permissions here: https://helpcenter.veeam.com/docs/backu ... ml?ver=100
When you add the ESXi hosts to another vcenter, the VMs will be treated by Veeam as new VMs. So you have to add them to the Jobs again and next run will be a new full backup.
Potentially clone all jobs and replace there the VMs. Then run new backups. Over time, you can just delete the old backups if the new Job has enough restore points.
-
- Veeam ProPartner
- Posts: 208
- Liked: 28 times
- Joined: Jun 09, 2009 2:48 pm
- Full Name: Lucio Mazzi
- Location: Reggio Emilia, Italy
- Contact:
Re: Permissions on Datacenter instead of vCenter
Hi Andreas,
I am aware of the linked page. However, it's not clear what "Global" level means.
If all operations (backup, restore, etc.) will be performed within the same virtual datacenter (with VMware meaning), will assigning Administrator role at the virtual datacenter level to the Veeam account work?
I am aware of the linked page. However, it's not clear what "Global" level means.
If all operations (backup, restore, etc.) will be performed within the same virtual datacenter (with VMware meaning), will assigning Administrator role at the virtual datacenter level to the Veeam account work?
-
- VP, Product Management
- Posts: 7081
- Liked: 1511 times
- Joined: May 04, 2011 8:36 am
- Full Name: Andreas Neufert
- Location: Germany
- Contact:
Re: Permissions on Datacenter instead of vCenter
Yes.
When you open the vCenter Permission Management you will find the needed rights that you can give a specific role/user. One of the categories is called "Global".
So you do not need an admin account. Just an account with the needed permissions listed in the documentation link above.
When you open the vCenter Permission Management you will find the needed rights that you can give a specific role/user. One of the categories is called "Global".
So you do not need an admin account. Just an account with the needed permissions listed in the documentation link above.
-
- Veeam ProPartner
- Posts: 208
- Liked: 28 times
- Joined: Jun 09, 2009 2:48 pm
- Full Name: Lucio Mazzi
- Location: Reggio Emilia, Italy
- Contact:
Re: Permissions on Datacenter instead of vCenter
Well, just to confirm I got this straight:
I understand that full Administrator rights are not needed, but let's keep it simple and let's assume we are granted a full Administrator role.
This role, however, will not be granted to root (=vCenter) level, but to a lower level: virtual DATACENTER level, where said virtual datacenter will contain all the inventory objects that are relevant to us.
Is this OK?
I understand that full Administrator rights are not needed, but let's keep it simple and let's assume we are granted a full Administrator role.
This role, however, will not be granted to root (=vCenter) level, but to a lower level: virtual DATACENTER level, where said virtual datacenter will contain all the inventory objects that are relevant to us.
Is this OK?
-
- VP, Product Management
- Posts: 7081
- Liked: 1511 times
- Joined: May 04, 2011 8:36 am
- Full Name: Andreas Neufert
- Location: Germany
- Contact:
Re: Permissions on Datacenter instead of vCenter
Jup as long as we can get the needed permissions.
-
- Veeam ProPartner
- Posts: 208
- Liked: 28 times
- Joined: Jun 09, 2009 2:48 pm
- Full Name: Lucio Mazzi
- Location: Reggio Emilia, Italy
- Contact:
Re: vCenter Server Granular Permissions (v9)
A feedback note about this --- maybe useful for answering future doubts.
We were granted Administrator role not at root level but at Datacenter level of the VMware structure. The Datacenter contains the cluster with all the hosts, datastores, vms and networks of our pertinence.
Everything seems to work fine except for one thing: the permissions on tag categories can only be granted at root level. I could create and assing tags, but a tag must belong to a tag category. Since in our case no categories have been defined, I am unable to create tags.
Our backup jobs used to rely on tags to pick different vms for different jobs. I had to switch to folders instead.
We were granted Administrator role not at root level but at Datacenter level of the VMware structure. The Datacenter contains the cluster with all the hosts, datastores, vms and networks of our pertinence.
Everything seems to work fine except for one thing: the permissions on tag categories can only be granted at root level. I could create and assing tags, but a tag must belong to a tag category. Since in our case no categories have been defined, I am unable to create tags.
Our backup jobs used to rely on tags to pick different vms for different jobs. I had to switch to folders instead.
-
- VP, Product Management
- Posts: 27377
- Liked: 2800 times
- Joined: Mar 30, 2009 9:13 am
- Full Name: Vitaliy Safarov
- Contact:
Re: vCenter Server Granular Permissions (v9)
Lucio, I will pass this feedback to our TW team. Thanks!
-
- VP, Product Management
- Posts: 27377
- Liked: 2800 times
- Joined: Mar 30, 2009 9:13 am
- Full Name: Vitaliy Safarov
- Contact:
Re: vCenter Server Granular Permissions (v9)
The document has been updated with the corresponding note about tag categories. Thanks again!
Who is online
Users browsing this forum: No registered users and 51 guests