VIX Guest interaction - permissions?

VMware specific discussions

VIX Guest interaction - permissions?

Veeam Logoby mma » Thu Jan 12, 2017 8:43 am

Hello Veeam

Our physical Veeam B&R Server (which is also proxy and guest interaction proxy) is in an private VLAN. Guest interaction over RPC is not possible, so we have to use VIX.
As we need to have UAC enabled, we have to use domain\administrator for the guest interaction. Not a big problem, but we have to harden our domain admin accounts.
Guest interaction proxies are no solution as we have dozens of guest VM VLANs. Additionally any communication between backup VLAN and guest VLANs is a no go.

There is a nice little guide from Microsoft “Securing Built-In Administrator Accounts on Active Directory”
https://technet.microsoft.com/en-us/win ... 2147217396

We set the following options for domain\administrator:
    Account is sensitive and cannot be delegated

    GPO "Security - domain\administrator hardening"
    Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies

    Deny log on through Remote Desktop Services
    Deny log on as a service
    Deny log on as a batch job
    Deny access to this computer from the network

The result is a secure administrator account, but no more guest interaction….
Is there a list of minimum permissions for VIX guest interaction?

Thanks
Marcel
mma
Service Provider
 
Posts: 58
Liked: 10 times
Joined: Thu Dec 22, 2011 9:12 am
Location: Lucerne, Switzerland
Full Name: Marcel

Re: VIX Guest interaction - permissions?

Veeam Logoby foggy » Thu Jan 12, 2017 10:54 am

Hi Marcel, I don't think we have such a granular permissions list. Have you tried backing up using such somewhat restricted administrator account or just curious whether it should work?
foggy
Veeam Software
 
Posts: 14742
Liked: 1080 times
Joined: Mon Jul 11, 2011 10:22 am
Full Name: Alexander Fogelson

Re: VIX Guest interaction - permissions?

Veeam Logoby mma » Thu Jan 12, 2017 3:18 pm

Hi foggy

Guest interaction is no longer possible with those setting.
Will do some try and error and let you know.

Regards
Marcel
mma
Service Provider
 
Posts: 58
Liked: 10 times
Joined: Thu Dec 22, 2011 9:12 am
Location: Lucerne, Switzerland
Full Name: Marcel

Re: VIX Guest interaction - permissions?

Veeam Logoby foggy » Thu Jan 12, 2017 3:19 pm

Thanks, will appreciate sharing your findings.
foggy
Veeam Software
 
Posts: 14742
Liked: 1080 times
Joined: Mon Jul 11, 2011 10:22 am
Full Name: Alexander Fogelson

Re: VIX Guest interaction - permissions?

Veeam Logoby mma » Fri Jan 13, 2017 7:36 am 1 person likes this post

So, the show stopper is the "Deny access to this computer from the network" option.
The other settings have no influence on guest interaction.

Regards
Marcel
mma
Service Provider
 
Posts: 58
Liked: 10 times
Joined: Thu Dec 22, 2011 9:12 am
Location: Lucerne, Switzerland
Full Name: Marcel


Return to VMware vSphere



Who is online

Users browsing this forum: No registered users and 7 guests